On Fri, Jun 18, 2004 at 11:17:23AM -0600, Darren Spruell wrote:

> OK, I see that in the README_SSL. I find that confusing, it seems like 
> the identity of the user can be determined from the certificate?

nessusd uses the username to determine where to look for the user's dname
file (which holds the subject name for the user's certificate).

> directory and placed these lines in the client's .nessusrc:
> 
>  ca_file = /usr/com/nessus/CA/cacert.pem
>  cert_file = ~/.nessus-certs/cert_darren.pem
>  key_file = ~/.nessus-certs/key_darren.peM

nessus does not expand tildes like a shell does. Replace them with
the full pathname to your cert and private key files.

If that doesn't fix the problem, run the following command and let 
me know what *errors* you get:

    nessus -qP localhost 1241 darren bogus

Adjust as necessary by, for example, replacing localhost with the
nessusd's hostname. 

NB: when you're using certificate-based authentication and your private
key is not protected with a pass phrase, the client will accept any
non-null password (eg, "bogus"). 

George
-- 
[EMAIL PROTECTED]

Attachment: pgpS79asnj0AP.pgp
Description: PGP signature

_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to