Re: [pfSense] OpenVPN Support Forum • Critical denial of service vulnerability in OpenVPN servers : Announcements

2014-12-04 Thread Vick Khera
On Tue, Dec 2, 2014 at 10:55 AM, Adrian Zaugg a...@ente.limmat.ch wrote: You also can find details here: https://community.openvpn.net/openvpn/wiki/SecurityAnnouncement-97597e732b So basically unless you give out TLS certificates to your openvpn to unknown/untrustworthy entities, your risk

Re: [pfSense] OpenVPN Non-admin users.

2014-12-04 Thread Karl Fife
Somehow I overlooked that option. Needless fussing. Enabling the OpenVPNManager by default seems like it could be a reasonable option considering that all supported versions of Windows (Vista/7/8/[10]) require users (even admins) to elevate the OpenVPN client (and/or create an elevated