Re: 2FA question
Gert Doering <[email protected]>
| Newsgroups | gmane.network.openvpn.user |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On Mon, Nov 20, 2023 at 10:08:46AM +1300, Richard Hector wrote:
> I've been experimenting with 2FA - with IPFire as the server, but I don't
> think that's relevant to my question.
>
> My understanding is that OpenVPN renegotiates keys every few minutes. It
> appears that when this happens, I also need to enter a new token.
60 minutes, but generally, yes.
> If that's
> true, it makes using 2FA rather impractical, or at least irritating.
>
> Have I understood this correctly? Or am I missing something?
--auth-gen-token <timer args>
on the server side.
This will make the server generate an openvpn-internal auth-token
(= password replacement) that the client will send on the next key
renegotiation. For the configured lifetime, this will make the server
happy, and not ask for 2FA.
When the configured token lifetime expires, the client will ask the
user again.
Using this with our 2FA clients since the early 2.5.x times with good
success - early clients had confusion in some combinations with
--auth-nocache, but I think we found and fixed everything for 2.5.0
(and now we're at 2.6.8).
gert
--
"If was one thing all people took for granted, was conviction that if you
feed honest figures into a computer, honest figures come out. Never doubted
it myself till I met a computer with a sense of humor."
Robert A. Heinlein, The Moon is a Harsh Mistress
Gert Doering - Munich, Germany [email protected]
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users
signature.asc
(application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE----- iQGcBAEBAgAGBQJlWn8qAAoJEB2Cnv7KVigSXHUL/jNHzSevaNBZmRrITSDf0Rrr ZfcELPtbkBOwemZR9+DVy50cpxJXZI1FVsAdaLxurF8KXgVz1v5G30i90b4305aV olK7gpM/8RiVf/hgW+EDwOwRsdCQqk83cmyNdxzJLaSyYKoaUMYHyrgKbx3C6+Ds swfKRmSDu1mOu1V297r7/jnuoW6SOluLmHQRcVvGXPvSQ7T95F3bi0+U07D453zl JF7GLNjvzeUNGOSF66pm8v53kDIZojHwYEuDDh4STTnO2OihEMf7muljld6/r7S4 j6mpex59gtNSVhCbOpDG9eymt38hIRa2HlN5i/wGLPMG1lv2SNOjgc0sXimGWP/B gFqdzvuADq1UrNj+aeKoPK1Am70mCAY8O6Flc+2ombWMUQIYmbjHQc9iPEekNwiV ybDDHuHX700XkH8G2VefymKviHrZwhZnxGDJnC/n0LHP1ch+bCRwn8vRzs7oFsrs 3xvrFgQk9YGecoZvfOeQncYgWtyyiQ9Keeu6fdpu9A== =Ga/I -----END PGP SIGNATURE-----