{"id":3227,"date":"2017-03-13T22:35:06","date_gmt":"2017-03-13T22:35:06","guid":{"rendered":"http:\/\/blog.mageia.org\/en\/?p=3227"},"modified":"2017-03-15T13:57:33","modified_gmt":"2017-03-15T13:57:33","slug":"alcasar-interview-richard-rey","status":"publish","type":"post","link":"https:\/\/blog.mageia.org\/en\/2017\/03\/13\/alcasar-interview-richard-rey\/","title":{"rendered":"ALCASAR, an open source Network Access Controller based on Mageia"},"content":{"rendered":"<p><em><a href=\"http:\/\/www.alcasar.net\/en\" rel=\"attachment wp-att-3204\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"3204\" data-permalink=\"https:\/\/blog.mageia.org\/en\/?attachment_id=3204\" data-orig-file=\"https:\/\/blog.mageia.org\/en\/wp-content\/uploads\/2017\/03\/Alcasar-logo.png\" data-orig-size=\"534,532\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Alcasar-logo\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.mageia.org\/en\/wp-content\/uploads\/2017\/03\/Alcasar-logo.png\" data-large-file=\"https:\/\/blog.mageia.org\/en\/wp-content\/uploads\/2017\/03\/Alcasar-logo.png\" class=\"wp-image-3204 alignright\" src=\"http:\/\/blog.mageia.org\/en\/wp-content\/uploads\/2017\/03\/Alcasar-logo.png\" width=\"170\" height=\"169\" \/><\/a><\/em><\/p>\n<p id=\"magicdomid3\"><em><span class=\"\">&#8220;<a href=\"http:\/\/www.alcasar.net\/en\">ALCASAR<\/a> is a free Internet Access Controller for private or public consultation networks. It authenticates and protects users&#8217; access regardless their connection type, or equipment (PC, smartphone, game console, TV sets, etc.).&#8221;<\/span><\/em><\/p>\n<p id=\"magicdomid4\"><span class=\"\">I met <\/span><span class=\"author-a-7z79zz90zx6az122zz69zsz122zz86zfz70zgz75zq\">the <\/span><span class=\"\"><a href=\"http:\/\/www.alcasar.net\/en\">ALCASAR<\/a> guys in 2012, during a French event and I discovered they were using Mageia in a professional project. Then the time ran quickly and finally here we are. Richard Rey agreed <\/span><span class=\"author-a-7z79zz90zx6az122zz69zsz122zz86zfz70zgz75zq\">to<\/span><span class=\"\"> answer our questions about ALCASAR and Mageia.<\/span><\/p>\n<h3 id=\"magicdomid5\"><span class=\"b\">&#8211; Can you introduce yourself? What is your <\/span><span class=\"author-a-7z79zz90zx6az122zz69zsz122zz86zfz70zgz75zq b\">technical <\/span><span class=\"b\">background and why did you start contributing to ALCASAR project?<\/span><\/h3>\n<p id=\"magicdomid8\"><span class=\"\"><strong>RR:<\/strong> Richard REY (AKA: Rexy). I am the Deputy Director of the computer security research laboratory (C + V) \u00b0 at <a href=\"https:\/\/www.esiea.fr\/\">ESIEA<\/a><\/span><span class=\"\">, a &#8220;school of digital technology engineers&#8221;. This school, which is an non-profit association (following to the French &#8220;law 1901&#8221;), is certified CTI (Commission of the Titles of Engineers). It is located on three campuses (Paris, Ivry and Laval).<\/span><\/p>\n<p id=\"magicdomid10\"><span class=\"\">I left the French army four years ago after a 27-year career in the fields of digital telecommunications, electronic warfare and computer fighting.<\/span><\/p>\n<p id=\"magicdomid12\"><span class=\"\">The genesis of the ALCASAR project: While I was an RSSI in a major Command, I was confronted with the installation of a technical tool on a large number of geographical sites. It had to meet the requirements of the Act for the Confidence in the Digital Economy (LCEN). This law requires that all connections made by Internet users must be <\/span><span class=\"author-a-z84z871uz65zb3l7z88zz68zz69zz70znn\">logged<\/span><span class=\"\"> for one year. The objective on my side was clear: protect the responsible of Internet networks (those who pay the subscription) from judicial inquiries related to the indelicacy of some connected users (incitement to racial hatred, procuring, child pornography, Scams, extortion, apology for terrorism, etc.).<\/span><\/p>\n<p id=\"magicdomid14\"><span class=\"\">After several unsuccessful searches (incomplete products, too complex or &#8220;out of budget&#8221;), I decided to create a team and we designed ALCASAR (Free Application for Secure Access Control and Authenticated to the Network).<\/span><\/p>\n<p><span class=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"3205\" data-permalink=\"https:\/\/blog.mageia.org\/en\/?attachment_id=3205\" data-orig-file=\"https:\/\/blog.mageia.org\/en\/wp-content\/uploads\/2017\/03\/alcasar_screen.png\" data-orig-size=\"822,411\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"alcasar_screen\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.mageia.org\/en\/wp-content\/uploads\/2017\/03\/alcasar_screen.png\" data-large-file=\"https:\/\/blog.mageia.org\/en\/wp-content\/uploads\/2017\/03\/alcasar_screen.png\" class=\"size-full wp-image-3205 aligncenter\" src=\"http:\/\/blog.mageia.org\/en\/wp-content\/uploads\/2017\/03\/alcasar_screen.png\" alt=\"\" width=\"822\" height=\"411\" \/><\/span><\/p>\n<h3 id=\"magicdomid16\"><span class=\"b\">&#8211; Can you describe the ALCASAR project, its community and its features?<\/span><\/h3>\n<p id=\"magicdomid18\"><span class=\"\"><strong>RR:<\/strong> From the beginning of the project, we have enforced quite strong technical and ethical constraints: all the traces of connection of all the protocols must be stored for one year (LCEN). They must be available only to the competent authorities (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Commission_nationale_de_l'informatique_et_des_libert%C3%A9s\">CNIL<\/a>). Any digital trace must integrate the notion of volume, duration and must make it possible to find a &#8220;human&#8221; user (a human is not an IP address &#8230;).<\/span><\/p>\n<p id=\"magicdomid20\"><span class=\"\">The heart of the project was developed around four main building blocks: the Radius <em>freeradius<\/em> server, the NAC (Network Access Controller) <em>coova-chilli<\/em>, the RDBMS <em>mariadb<\/em> and the firewall <em>netfilter<\/em>.<\/span><\/p>\n<p id=\"magicdomid22\"><span class=\"\">After adding <em>apache<\/em> and <em>PHP<\/em> to propose a user-friendly Web administration interface, the project got known outside the military sphere.<\/span><\/p>\n<p id=\"magicdomid24\"><span class=\"\">New features were requested (domain name and URL filtering, &#8220;blacklist&#8221; and &#8220;whitelist&#8221; filtering, protocol filtering, user \/ user-specific filtering, blacklist\/whitelist import and customization, connection time management, SMS identification, MAC address authentication, internationalization of interfaces, etc.).<\/span><\/p>\n<p id=\"magicdomid26\"><span class=\"\">Faithful to our military roots, the community is organized in a very pyramidal way. Only three or four contributors can interact directly with our SVN. The others propose their contributions to those four &#8220;privileged&#8221; users. About twenty people of all nationalities are currently registered on the project (a dozen are active).<\/span><\/p>\n<h3 id=\"magicdomid28\"><span class=\"b\">&#8211; On your home page, it says that Mageia is part of your software ecosystem. Why this choice?<\/span><\/h3>\n<p id=\"magicdomid31\"><span class=\"\"><strong>RR:<\/strong> At the beginning of the project, I used the Mandrake Linux distribution. That was all that I was looking for both on professional and personal sides. I especially appreciated the rigorous security updates (no nasty surprises) and the &#8220;Made In France&#8221; side. We remained loyal and naturally evolved ALCASAR on Mandriva Linux and then on Mageia. The next version 3.1 of ALCASAR will be installed on Mageia 5.1. We will naturally continue this cycle with Mageia 6.<\/span><\/p>\n<h3 id=\"magicdomid33\"><span class=\"b\">&#8211; Do you have an idea of today&#8217;s ALCASAR users?<\/span><\/h3>\n<p id=\"magicdomid36\"><span class=\"\"><strong>RR:<\/strong> In terms of volume: no. In terms of use, we know that French and foreign ministries are using it. Some companies have deployed it and have sometimes included it in their security policy. We also know that ESN install and administer it on behalf of their clients. We have a lot of returns from hoteliers, providers, associates, camp managers, holiday clubs &#8230;<\/span><\/p>\n<h3 id=\"magicdomid38\"><span class=\"b\">&#8211; What are the relationships between ALCASAR and Mageia? Do you contribute to Mageia? How <\/span><span class=\"author-a-7z79zz90zx6az122zz69zsz122zz86zfz70zgz75zq b\">can <\/span><span class=\"b\">Mageia help you?<\/span><\/h3>\n<p id=\"magicdomid41\"><span class=\"\"><strong>RR:<\/strong> ALCASAR only runs on Mageia and there is no question for now to change that. This allows us to devote ourselves to the evolutions of functionality rather than waste our time adapting it for other distributions.<\/span><\/p>\n<p id=\"magicdomid43\"><span class=\"\">We contribute quite little (too little to my liking) to Mageia. We report the bugs that have an impact on the twenty software packages that we do include in ALCASAR. We package some software that we are, in my opinion, the only ones to use (HAVP, Netflow core probe, coova-chilli).<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;ALCASAR is a free Internet Access Controller for private or public consultation networks. It authenticates and protects users&#8217; access regardless their connection type, or equipment (PC, smartphone, game console, TV sets, etc.).&#8221; I met the ALCASAR guys in 2012, during &hellip; <a href=\"https:\/\/blog.mageia.org\/en\/2017\/03\/13\/alcasar-interview-richard-rey\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":true,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[170,47,124,118],"tags":[],"class_list":["post-3227","post","type-post","status-publish","format-standard","hentry","category-collaboration","category-community","category-mageia-2","category-users"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p159kA-Q3","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/posts\/3227","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/comments?post=3227"}],"version-history":[{"count":13,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/posts\/3227\/revisions"}],"predecessor-version":[{"id":3241,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/posts\/3227\/revisions\/3241"}],"wp:attachment":[{"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/media?parent=3227"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/categories?post=3227"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mageia.org\/en\/wp-json\/wp\/v2\/tags?post=3227"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}