Re: [Openvpn-devel] [PATCH] Support fingerprint authentication

2018-05-28 Thread Jan Just Keijser
Hi all, On 25/05/18 22:56, Simon Rozman wrote: JJK, I think you are misreading this proposal. No hash is being sent as a part of the handshake -- its still client and server certificates that are exchanged and checked during handshake. The hash is exchanged by a separate channel (say snail

Re: [Openvpn-devel] [PATCH] Support fingerprint authentication

2018-05-28 Thread Arne Schwabe
> > 2. instead of storing a certificate on each side, wouldn't it be nice to > be able to store the public key only of the certificate, or perhaps even > a hash of the public key of the certificate? > To me, storing either the certificate itself is not a problem (I recall > Jason Donenfeld