|
|
Ben Scott wrote:
On 2/3/06, Alon Bar-Lev <alon.barlev@xxxxxxxxx> wrote:Why do you mix username and certificate? If you give a different certificate for each user it should be sufficient.
Using private key encrypted with password is stronger than supplying the password to a server, without protecting the private key. I can extent this a little and say that a password to access a private key on a smartcard is the best approach. Presenting shared secret information to the server weak! But it is more simple to understand (intuitive), so people select this approach to be on the safe side (psychological). There may also be administrative benefits by authenticating the user name against a server-side system. For example, accounting (tracking who uses the VPN when) or group membership access control. Again, I disagree. By authenticating the user based on his certificate you loose no information! From the certificate server side knows which user is on the other side... Based on this information all account mechanism works. But at the end... All a matter of choice. Best Regards, Alon Bar-Lev
Warning: require_once(../../../archive_common.php) [function.require-once]: failed to open stream: No such file or directory in /home/openvpn/domains/openvpn.net/public_html/archive/openvpn-users/2006-02/msg00048.html on line 211 Fatal error: require_once() [function.require]: Failed opening required '../../../archive_common.php' (include_path='/usr/local/lib/php') in /home/openvpn/domains/openvpn.net/public_html/archive/openvpn-users/2006-02/msg00048.html on line 211 |