Is it possible to use client certificate authentication with the X11 client?
Certainly.
I see it complaining unless it is fed a user name and password.
The client does need both but certificate-based authentication will work if set up properly.
OK, I see that in the README_SSL. I find that confusing, it seems like the identity of the user can be determined from the certificate?
What error messages do you see? How have you created the certs? Have you read nessus-core/README_SSL?
I used nessus-mkcert-client on the server. It wrote the key/cert into a directory under /tmp. I copied this to a path on the client user's home directory and placed these lines in the client's .nessusrc:
ca_file = /usr/com/nessus/CA/cacert.pem cert_file = ~/.nessus-certs/cert_darren.pem key_file = ~/.nessus-certs/key_darren.peM ssl_version = TLSv1
The server has the following in its nessusd.conf:
cert_file=/usr/com/nessus/CA/servercert.pem key_file=/var/lib/nessus/CA/serverkey.pem ca_file=/usr/com/nessus/CA/cacert.pem force_pubkey_auth = yes ssl_version = TLSv1
So when I launch my client and try to connect to the server, I give it the username that is the same as the DN for the cert, and a dummy password. My error comes up in a window and says "SSL error". The only thing logged in nessusd.messages is:
[Fri Jun 18 11:15:27 2004][21269] connection from 10.3.30.75
Server and client version, 2.0.10a from Gentoo Linux's Portage tree.
-- Darren Spruell Sento I.S. Department [EMAIL PROTECTED] _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
