Re: [Openvpn-devel] [RFC] - Enable 2FA to be used with renegotiations

2016-09-16 Thread David Sommerseth
On 25/08/16 15:45, David Sommerseth wrote: > > Hi, > [...snip...] > > What the patch-set does is: > > - Add --auth-gen-token, and when used the following steps happens > > - After a successful normal user/password authentication, it will > generate a random token for this tunnel and keep a

Re: [Openvpn-devel] [RFC] - Enable 2FA to be used with renegotiations

2016-08-25 Thread David Sommerseth
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 25/08/16 18:53, Selva Nair wrote: > As for caching, either the token will have to be cached unless > management is in use in which case the UI/GUI can remember the > token and supply it during reneg. Right, but I think we both agree that caching

Re: [Openvpn-devel] [RFC] - Enable 2FA to be used with renegotiations

2016-08-25 Thread David Sommerseth
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 25/08/16 18:53, Selva Nair wrote: > As for caching, either the token will have to be cached unless > management is in use in which case the UI/GUI can remember the > token and supply it during reneg. Right, but I think we both agree that caching

Re: [Openvpn-devel] [RFC] - Enable 2FA to be used with renegotiations

2016-08-25 Thread David Sommerseth
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 25/08/16 16:32, Selva Nair wrote: > > On Thu, Aug 25, 2016 at 10:15 AM, David Sommerseth > > wrote: > > On 25/08/16 15:58, David Woodhouse wrote: >> On Thu,

Re: [Openvpn-devel] [RFC] - Enable 2FA to be used with renegotiations

2016-08-25 Thread David Woodhouse
On Thu, 2016-08-25 at 15:45 +0200, David Sommerseth wrote: > > > I've been working a bit on a new patch-set which enables third-party > user/password authentication mechanisms using two factor > authentications [2FA] (such as OTP) and not needing to disable the > renegotiation features of

Re: [Openvpn-devel] [RFC] - Enable 2FA to be used with renegotiations

2016-08-25 Thread David Woodhouse
On Thu, 2016-08-25 at 15:45 +0200, David Sommerseth wrote: > > > I've been working a bit on a new patch-set which enables third-party > user/password authentication mechanisms using two factor > authentications [2FA] (such as OTP) and not needing to disable the > renegotiation features of

[Openvpn-devel] [RFC] - Enable 2FA to be used with renegotiations

2016-08-25 Thread David Sommerseth
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I've been working a bit on a new patch-set which enables third-party user/password authentication mechanisms using two factor authentications [2FA] (such as OTP) and not needing to disable the renegotiation features of OpenVPN. Currently, if a

[Openvpn-devel] [RFC] - Enable 2FA to be used with renegotiations

2016-08-25 Thread David Sommerseth
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I've been working a bit on a new patch-set which enables third-party user/password authentication mechanisms using two factor authentications [2FA] (such as OTP) and not needing to disable the renegotiation features of OpenVPN. Currently, if a