Hi, On Fri, Dec 16, 2016 at 04:48:16PM +0100, Sebastian Rubenstein wrote: > It seems to me that using the --tls-auth key file is not good for security at > all as an expert had earlier replied that anyone who has the --tls-auth key > file could inject malicious packets. What viable alternatives would you > propose please?
Not exactly. *If* there were a TLS vulnerability in OpenVPN, tls-auth
would not protect against other users of the same VPN service - but would
protect against everyone else and their evil twins.
TLS vulnerabilities aside, knowing someone else's tls-auth key will
not allow you to inject arbitrary packets - they still need to pass the
actual TLS layer.
[..]
> There is no way for a customer like me to get hold of my VPN provider's
> server and intermediate certificates to check if the cipher strength is at
> least 2048 bits, correct?
They need to be known to the client to verify who you are connecting to - so
look for the "ca" bit in your client config.
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [email protected]
fax: +49-89-35655025 [email protected]
signature.asc
Description: PGP signature
------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot
_______________________________________________ Openvpn-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openvpn-users
