You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Setting your tunnel to never renegotiate is a security problem for long-running tunnels, and OpenVPN added the auth-gen-token config parameter specifically for cases like OTP authentication. In short, after authentication OpenVPN will generate a token to be used for renegotiation in place of re-sending the username and password.
Please add a mention of auth-gen-token for OpenVPN >= 2.4 in the README.
The text was updated successfully, but these errors were encountered:
wrossmann
changed the title
'reneg-sec 0` is not a good idea, and is not necessary in OpenVPN >= 2.4
'reneg-sec 0' is not a good idea, and is not necessary in OpenVPN >= 2.4
Mar 19, 2021
Thanks Wade,
Would you like to raise a PR to add that?
I don’t want to take credit for other people’s contributions.
Alternatively, I could make that change myself.
Setting your tunnel to never renegotiate is a security problem for long-running tunnels, and OpenVPN added the
auth-gen-token
config parameter specifically for cases like OTP authentication. In short, after authentication OpenVPN will generate a token to be used for renegotiation in place of re-sending the username and password.Please add a mention of
auth-gen-token
for OpenVPN >= 2.4 in the README.The text was updated successfully, but these errors were encountered: