On 05/04/2015 10:01 PM, Etienne Dechamps wrote:
> On 4 May 2015 at 20:53, Anne-Gwenn Kettunen <[email protected]> wrote:
>> We started to take a look about that, and apparently, it seems that the IP
>> in the public key is taken into account when a client connects to a gateway.
>> Spoofing at that level doesn't seem easy, because the IP address seems to be
>> part of the authentication process.
> 
> I'm having trouble understanding what you mean by "gateway",
> "authentication process" and "IP address" especially when you say it's
> part of the "public key" (it's not).
> 
> Can you clarify? I am pretty sure tinc doesn't use IP addresses in any
> of its security mechanisms, except when StrictSubnets is enabled.
> 

I tested with two node "miou" and "apeliote"
they have a connectTo. and public key from "Neptune".

"Neptune" node have their public key also. (and all node can play together)

/etc/tinc/tinclan/host/miou contain a subnet with IP and public key from "miou"
/etc/tinc/tinclan/host/apeliote contain a subnet with IP and public key from 
"apeliote"

If IP from miou is changed with IP from apeliote, "miou" can not connect to 
"Neptune"
even miou have apeliote's IP.

ok, this is not the best spoofing tentative :p

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
tinc mailing list
[email protected]
http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc

Reply via email to