Hi,

On Fri, Dec 16, 2016 at 04:48:16PM +0100, Sebastian Rubenstein wrote:
> It seems to me that using the --tls-auth key file is not good for security at 
> all as an expert had earlier replied that anyone who has the --tls-auth key 
> file could inject malicious packets. What viable alternatives would you 
> propose please?

Not exactly.  *If* there were a TLS vulnerability in OpenVPN, tls-auth
would not protect against other users of the same VPN service - but would
protect against everyone else and their evil twins.

TLS vulnerabilities aside, knowing someone else's tls-auth key will
not allow you to inject arbitrary packets - they still need to pass the
actual TLS layer.

[..]
> There is no way for a customer like me to get hold of my VPN provider's 
> server and intermediate certificates to check if the cipher strength is at 
> least 2048 bits, correct?

They need to be known to the client to verify who you are connecting to - so
look for the "ca" bit in your client config.

gert

-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             [email protected]
fax: +49-89-35655025                        [email protected]

Attachment: signature.asc
Description: PGP signature

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most 
engaging tech sites, SlashDot.org! http://sdm.link/slashdot
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to