OpenVPN certificate question

OpenVPN certificate question

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
OpenVPN certificate question David Goodenough 05-03-2006
Posted by David Goodenough on May 3, 2006, 11:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
The situation I have is one of omplete control of both the server and
the one client that will connect to it. It's what I know as a
"road-warrior" seup: I have my notbook connected to my LAN while I'm
at home, I'd like to be able to connect to the LAN when I'm out on the
road. Both systems are running Windows XP SP2, if it makes a
difference.

I drilled exactly one hole in my firewall: port 1999, and I've got
openvpn set up so that laptop connects to server using tcp port 1999.
That's all working just fine. 1999 was selected somewhat arbitrarily,
and can easilt be changed if there's a good reason to do so.

My limited understanding is that I can guarantee (*) the integrity of
my connection if both ends verify that the certificate presented by
the other end is signed by the same CA as generated the ca.crt. What
does it take to ensure that OpenVPN will reject a connection with an
inappropriate certificate, i.e. one that does not bear the signatuure
of my CA. Or is there a better test?

(*) guarantee extends as far as can reasonably be expected. The NSA
can probably break in if they really wanted to, but some skript kiddie
two blocks from my house is pretty much out of luck.

Thanks in advance for any help.

Similar ThreadsPosted
An ode to OpenVPN, and a question September 17, 2005, 10:06 pm
Certificate issue with a webservice August 15, 2007, 12:33 am
Need help enrolling a certificate, Cisco VPN Client July 19, 2005, 7:41 pm
Simple netmask question, could some one please answer this question for me. October 11, 2007, 10:22 pm
OpenVPN October 22, 2005, 8:54 pm
openvpn & pptp February 7, 2005, 5:56 pm
Problems with OpenVPN March 4, 2005, 6:31 pm
OpenVPN DNS problem March 27, 2005, 2:17 pm
openvpn and routing February 6, 2006, 12:50 pm
openvpn windows xp client August 25, 2005, 6:45 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map