Personal computing discussed

Moderators: Steel, notfred

 
cheesyking
Minister of Gerbil Affairs
Topic Author
Posts: 2686
Joined: Sun Jan 25, 2004 7:52 am
Location: That London (or so I'm told)
Contact:

ipsec vpn with x509 authentication

Wed Mar 07, 2018 10:37 am

I'm trying to understand exactly how this works.

If you are only trusting certificates from a private CA that's only issuing certs for a specific vpn then I assume it doesn't make much difference what the certificate says (ie the CN), it's from the trusted CA so that's enough to authenticate the connection.

If you're using a public CA though anyone can get a cert from them so your VPN has to be checking something else in the cert (like the CN). How does this work if you're not using FQDNs when setting up the VPN? I think I read somewhere the IP can be put in the SAN field on the cert but I've gotten my self pretty confused and I'm really hoping someone tell me how this is generally dealt with.

Thanks
Fernando!
Your mother ate my dog!
 
cheesyking
Minister of Gerbil Affairs
Topic Author
Posts: 2686
Joined: Sun Jan 25, 2004 7:52 am
Location: That London (or so I'm told)
Contact:

Re: ipsec vpn with x509 authentication

Mon Mar 19, 2018 9:20 am

ha, well it turns out I was right to be confused. What happened was that I'd been given a VPN provisioning form that was missing sections for fqdns that would appear in the certs. There's no magic that I was missing out on, just an incomplete form :roll:
Fernando!

Your mother ate my dog!
 
chuckula
Gold subscriber
Gerbil Jedi
Posts: 1862
Joined: Wed Jan 23, 2008 9:18 pm
Location: Probably where I don't belong.

Re: ipsec vpn with x509 authentication

Mon Mar 19, 2018 9:29 am

cheesyking wrote:
I'm trying to understand exactly how this works.



So is everybody else! The X509 system is pretty hideously complicated. I use OpenVPN, which is also SSL based but does not try to be a full-bore X509 implementation.
4770K @ 4.7 GHz; 32GB DDR3-2133; GTX-1080 sold and back to hipster IGP!; 512GB 840 Pro (2x); Fractal Define XL-R2; NZXT Kraken-X60
--Many thanks to the TR Forum for advice in getting it built.
 
cheesyking
Minister of Gerbil Affairs
Topic Author
Posts: 2686
Joined: Sun Jan 25, 2004 7:52 am
Location: That London (or so I'm told)
Contact:

Re: ipsec vpn with x509 authentication

Mon Mar 19, 2018 10:02 am

Good to know it's not just me then. I'd love to do openvpn instead but everything I do is mandated by the other end.

I really don't understand why you'd use a public CA for a connection between two parties like this. Seems like it just introduces a host of new potential security vulnerabilities that wouldn't be there otherwise, it's not like public CAs have a very good record on security anyway.
Fernando!

Your mother ate my dog!

Who is online

Users browsing this forum: No registered users and 1 guest