George Theall wrote:
Is it possible to use client certificate authentication with the X11 client?


Certainly.


I see it complaining unless it is fed a user name and password.


The client does need both but certificate-based authentication will
work if set up properly.

OK, I see that in the README_SSL. I find that confusing, it seems like the identity of the user can be determined from the certificate?



What error messages do you see? How have you created the certs? Have you read nessus-core/README_SSL?

I used nessus-mkcert-client on the server. It wrote the key/cert into a directory under /tmp. I copied this to a path on the client user's home directory and placed these lines in the client's .nessusrc:


 ca_file = /usr/com/nessus/CA/cacert.pem
 cert_file = ~/.nessus-certs/cert_darren.pem
 key_file = ~/.nessus-certs/key_darren.peM
 ssl_version = TLSv1

The server has the following in its nessusd.conf:

 cert_file=/usr/com/nessus/CA/servercert.pem
 key_file=/var/lib/nessus/CA/serverkey.pem
 ca_file=/usr/com/nessus/CA/cacert.pem
 force_pubkey_auth = yes
 ssl_version = TLSv1

So when I launch my client and try to connect to the server, I give it the username that is the same as the DN for the cert, and a dummy password. My error comes up in a window and says "SSL error". The only thing logged in nessusd.messages is:

 [Fri Jun 18 11:15:27 2004][21269] connection from 10.3.30.75

Server and client version, 2.0.10a from Gentoo Linux's Portage tree.

--
Darren Spruell
Sento I.S. Department
[EMAIL PROTECTED]
_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to