Re: Transfer from one server to another, compress and digest

Gert Doering <[email protected]>
Newsgroups gmane.network.openvpn.user
Message-ID <[email protected]>
Hi,

On Wed, Jan 03, 2024 at 04:04:02PM +0000, Peter Davis via Openvpn-users wrote:
> I have two questions:
> 1- Is it possible to transfer server and client keys from one server to another or must the keys be generated on each server?

Ideally, you wouldn't create the keys "on the server" anyway - in a 
secure world, the CA key never leaves a *secure* machine for key generation,
and you'd create server key(s) and client keys on this machine, copying
to the target machines as are needed.

In practice, it does not really matter how your copy your keys around - the
other end of the connection will have no insight on "what is the real
identity of the machine?", all it cares about is "is this a certificate
signed by a CA that I trust" (plus possible constraints if so configured,
like "the server must present a certificate with a CN 'alice'", but this
is client config specific).


> 2- I connected to an OpenVPN server with the OpenVPN Connect app on Android, I saw the following two lines in the logs:
> 
> compress: NONE
> digest: NONE
> 
> What do these mean and are they considered a security problem?

You omitted the part that said something about "cipher: AES-256-GCM", I'd
wager a guess...

So, compress: NONE is good, digest: NONE is good *only* if an AEAD cipher
is used (like AES-GCM) that does not need a separate digest pass.

gert

-- 
"If was one thing all people took for granted, was conviction that if you 
 feed honest figures into a computer, honest figures come out. Never doubted 
 it myself till I met a computer with a sense of humor."
                             Robert A. Heinlein, The Moon is a Harsh Mistress

Gert Doering - Munich, Germany                             [email protected]

_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users
signature.asc (application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE-----

iQGcBAEBAgAGBQJllYn7AAoJEB2Cnv7KVigSDC8L/1N+8tmqpyRS+kwp1dITQcTV
OI9AAXxScf+y1ATIc/D0XgRqk7HPYzJqBZP2ZuhzWWDHR1q6Qt55Z0UwYEOszvOB
1Z9H+Um7Axn9SRAzFyGKfoYn8r3gBldYtjLfbhJ0/bROofa7HWax46fS/Z3y3yms
7nv1v1d6FvwvpXr6Fk2bk3tYA9HCDfvCdfY8FE1rP/tCFkt8WRlbY3xTIw2v/8s/
Xvw3H7UdR5nicwTwutfNRdfuOmXcqmbOw3cCn1yPe5ZruhkqTFY1haQGku7dcigl
Q8N69PpoisK1DhCqGBq06kiWb+6SBmUKOYlk6VMP/6nbTrTN4yDevIW0N/O2y+b/
eZSoz1XacMfcqe5RLCLnsq7IxV760sN7kxSh22VLsAJXyoI5RBGinTGcVHaamd+D
/QDnxHRjmluDwZxMXOnUuO/r4EUwAIAlpsw3jVWvMq1PPHpt95q1Gi/HqV0HWbCV
M4NBvOC+KwtRgjaky7i57mYHpDppRam5MqWXpRWwMw==
=zDNh
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.