Admin Server#

Librem Server v2
  • 1U Server

  • PureOS (Not Windows) offering 100% Auditable Code and no Third Party traffic

  • Cryptographic Tamper Detection via PureBoot and Librem Key

  • Admin Interface for Ecosystem Deployment

Post Quantum Cryptography (PQC)#

Purism implemented the latest NIST approved PQC throughout the ecosystem. Purism’s unique implementation generates keys on the end devices and the secret never leaves that device. A public certificate is propagated through the ecosystem offering the latest and greatest in secure communication between parties via end-to-end-encrypted quantum-safe cryptography.

Administration Interface#

To set up a new user and device, an administrator creates a user, then authorizes the device by generating a secret key and public certificate. After setup, a user can then use the device for quantum-safe communications with other users.

PQC administration interface diagram

The administration interface can be accessed through a web browser. The administrator can administer users and public certificates through this interface.

Register a new user#

An administrator registers a new user to enable use of communications services. The administrator can also grant administrator rights, so that a user can register further users.

  1. First, access the web interface, then select System > Users and Groups:

    Administration interface: Users and Groups
  2. Select Create User:

    Administration interface: Create user
  3. Choose a user name and password for the new user. You can also check Access to all services and settings (admin) to allow that user to create additional users and administer the server.

    Administration interface: Create user

Configure a communication device#

An administrator sets up a communications device to grant it access to communications services.

This process installs the CA certificate from the server, then generates a secret key and certificate for this device. The device is then authorized by the administrator signing its certificate. The secret key is generated on-device and never transmitted. It always remains on the device.

  1. Open the PQC Communications Client Setup application

Open **PQC Communications Client Setup**
  1. Select Open Site Configuration File

Open the client setup application on device
  1. Insert the USB flash drive containing the JSON configuration file from the server. Tap the “sidebar” button to see locations.

Open the client setup application on device
  1. Select the flash drive.

Name the device and create secret key
  1. Select the site JSON file.

Open the client setup application on device
  1. Enter your password (for the local phone user, (default 123456) to install the server’s root certificate.

Open the client setup application on device
  1. The setup application now shows that a site is selected. Type in the common name you selected below “Client Common Name”, then select Create Secret Key.

Name the device and create secret key
  1. Wait for the secret key creation to complete, then select OK.

Open the client setup application on device
  1. Select Authorize to authorize your client certificate.

Open the client setup application on device
  1. Enter the administrator password for the server, then select OK.

Name the device and create secret key
  1. Wait for authorization to complete, then select OK.

Open the client setup application on device
  1. Select Install to install web applications.

Open the client setup application on device
  1. Wait for installation to complete, then select OK. (If you get an SSL handshake error, you forgot to temporarily allow non-PQC key exchange on the server.)

Name the device and create secret key
  1. Select Exit to exit the setup application.

Open the client setup application on device
  1. Open the Talk app, and log in with the credentials you were provided.

Open the client setup application on device

To change your password, open the PQC+ Settings app, then log in and change your password.

Use a communication device#

The administrator then gives the device and credentials to the user. To use the device, the user authenticates with the device certificate, then logs in with the credentials. Authenticating with the device certificate is automatic when using the installed web apps. The Talk application launches automatically when the phone starts up.

  1. To verify the connection utilizes the server CA certificate, open the server’s admin interface from a web browser on the device. This requests certificate authentication.

    Note

    This will only work on the Librem 5 at 100% screen scale. The certificate prompt does not fit at any higher scale and cannot scroll.

    Accepting the certificate
  2. Check “Remember this decision” and tap “OK”, then log in with your credentials.