Re: SF.net SVN: logwatch:[108] scripts/services/openvpn

Orion Poplawski <[email protected]>
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <[email protected]>
On 05/24/2012 11:16 AM, [email protected] wrote:
> Revision: 108
>            http://logwatch.svn.sourceforge.net/logwatch/?rev=108&view=rev
> Author:   opoplawski
> Date:     2012-05-24 17:16:52 +0000 (Thu, 24 May 2012)
> Log Message:
> -----------
> Handle TLS: Username/Password authentication succeeded for username messages
> Handle PLUGIN_CALL messages
> Only output Cipher messages at Detail 10
>

This turned this:

--------------------- OpenVPN Begin ------------------------

  Verify
     status: OK depth: 0 DN: 
/C=US/ST=CO/L=Boulder/O=NWRA/OU=Boulder/CN=ash-ovpn/name=root/[email protected]: 
7 Time(s)
     status: OK depth: 1 DN: 
/C=US/ST=CO/L=Boulder/O=NWRA/OU=Boulder/CN=XXXXXXX.cora.nwra.com/name=root/[email protected]: 
7 Time(s)

  Connections:
     Configuration XXXXX-ovpn:
        24.51.59.46 connected 1 Time(s), Ports: 54963

  Ciphers used for Authentication:
     Data Channel:
        Decrypt:
           160 bit SHA1 used 7 Time(s)
        Encrypt:
           160 bit SHA1 used 7 Time(s)

  Ciphers used for Encryption:
     Control Channel:
        TLSv1:
           TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA used 7 Time(s)

     Data Channel:
        Decrypt:
           128 bit BF-CBC used 7 Time(s)
        Encrypt:
           128 bit BF-CBC used 7 Time(s)

  **Unmatched Entries**
     PLUGIN_CALL: POST 
/usr/lib/openvpn/plugin/lib/openvpn-auth-ldap.so/PLUGIN_AUTH_USER_PASS_VERIFY 
status=0: 7 Time(s)
     PLUGIN_CALL: POST 
/usr/lib/openvpn/plugin/lib/openvpn-auth-ldap.so/PLUGIN_CLIENT_CONNECT 
status=0: 1 Time(s)
     PLUGIN_CALL: POST 
/usr/lib/openvpn/plugin/lib/openvpn-auth-ldap.so/PLUGIN_CLIENT_DISCONNECT 
status=0: 1 Time(s)
     TLS: Username/Password authentication succeeded for username 'XXXXXX' : 7 
Time(s)

  ---------------------- OpenVPN End -------------------------

in to this for detail 0:


--------------------- OpenVPN Begin ------------------------

  Verify
     TLS: Username/Password authentication succeeded for username 'XXXXXXX' : 
7 Time(s)
     status: OK depth: 0 DN: 
/C=US/ST=CO/L=Boulder/O=NWRA/OU=Boulder/CN=ash-ovpn/name=root/[email protected]: 
7 Time(s)
     status: OK depth: 1 DN: 
/C=US/ST=CO/L=Boulder/O=NWRA/OU=Boulder/CN=XXXX.cora.nwra.com/name=root/[email protected]: 
7 Time(s)

  Connections:
     Configuration XXXXXX-ovpn:
        24.51.59.46 connected 1 Time(s), Ports: 54963

  ---------------------- OpenVPN End -------------------------

detail 5 adds:

  Plugin Call OK:
     Plugin /usr/lib/openvpn/plugin/lib/openvpn-auth-ldap.so:
        PLUGIN_AUTH_USER_PASS_VERIFY succeeded 7 Time(s)
        PLUGIN_CLIENT_CONNECT succeeded 1 Time(s)
        PLUGIN_CLIENT_DISCONNECT succeeded 1 Time(s)


detail 10 adds:

  Ciphers used for Authentication:
     Data Channel:
        Decrypt:
           160 bit SHA1 used 7 Time(s)
        Encrypt:
           160 bit SHA1 used 7 Time(s)

  Ciphers used for Encryption:
     Control Channel:
        TLSv1:
           TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA used 7 Time(s)

     Data Channel:
        Decrypt:
           128 bit BF-CBC used 7 Time(s)
        Encrypt:
           128 bit BF-CBC used 7 Time(s)

  Plugin Call OK:
     Plugin /usr/lib/openvpn/plugin/lib/openvpn-auth-ldap.so:
        PLUGIN_AUTH_USER_PASS_VERIFY succeeded 7 Time(s)
        PLUGIN_CLIENT_CONNECT succeeded 1 Time(s)
        PLUGIN_CLIENT_DISCONNECT succeeded 1 Time(s)


I'm still tempted to pare down the detail 0 output, but that is probably 
reasonable.

-- 
Orion Poplawski
Technical Manager                     303-415-9701 x222
NWRA, Boulder Office                  FAX: 303-415-9702
3380 Mitchell Lane                       [email protected]
Boulder, CO 80301                   http://www.nwra.com

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.