Re: [Openvpn-users] "--askpass file" is evil!

  • Subject: Re: [Openvpn-users] "--askpass file" is evil!
  • From: Leonard Isham <leonard.isham@xxxxxxxxx>
  • Date: Fri, 3 Dec 2004 10:02:34 -0500

On Fri, 3 Dec 2004 09:33:04 -0500 (EST), awilliam@xxxxxxxxxxxxx
<awilliam@xxxxxxxxxxxxx> wrote:
> Sure, but at that point who cares about the certs.  If you've gotten far
> enough to get the certs,  you could already have walked off with the data
> all this mishmash is meant to protect.

That depends on the location of the box with the cert.  Was it in a
secured DMZ or just sitting in the LAN.... There are other factors as

Leonard Isham, CISSP 
Ostendo non ostento.

