[Openvpn-users] bridging, shared certs question

  • From: Frank Sweetser <fes@xxxxxxxxxxxxxxxxxxxxx>
  • Date: Mon, 31 Jan 2005 21:23:49 -0500

I have a couple of questions:

1) We're considering deploying openvpn with a single client cert shared among
the users, with username and password authentication.  Given that each user has
access to the private key used by other users, does this mean that each user
would be able to decrypt the traffic from other users tunnels?

2) In TAP mode, the openvpn process has to effectivly act as a software bridge.
What does it do with ethernet broadcasts - discard them, or flood them to all
connected clients?

