Re: Limit the number of users based on the key
Gert Doering <[email protected]>
| Newsgroups | gmane.network.openvpn.user |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On Tue, Jan 09, 2024 at 10:06:33AM +0000, Peter Davis wrote:
> I'd like to use something like a MAC address filtering mechanism, but that would require scripting and I don't know how to do that. I want no one to be able to connect to the OpenVPN server without permission.
If a user has no key, they have no permission. If you give them a key,
you have given them permission.
If you want stronger auth, add --auth-user-pass and (for example) an LDAP
backend, so users need to have a key *and* know a password.
> 2- What's the solution? Should I generate one server key and multiple client keys? Isn't it better if each department has its own server key?
Do you have one server per department, or one server for all?
It makes sense to have one server key *per server*, but whether or not
that is "per department" depends on what you are trying to achieve.
gert
--
"If was one thing all people took for granted, was conviction that if you
feed honest figures into a computer, honest figures come out. Never doubted
it myself till I met a computer with a sense of humor."
Robert A. Heinlein, The Moon is a Harsh Mistress
Gert Doering - Munich, Germany [email protected]
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users
signature.asc
(application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE----- iQGcBAEBAgAGBQJlnRyxAAoJEB2Cnv7KVigSwncL/i6TudXFyVbGMZQ6blv5OB34 yHQ/PsZGCAE7D3u+rjxNTiPjzl4uYO6fFNTMgX5pgxV3+iqpowwlijXgiBQpw+v1 xkYc0b9RNTw9/0SitsLQ+H3/QDX0/2U5sdryduxNVrNtxUN73v0B/G/5dKZvrdPE UPteVpZ9hYM7F3ZTQp0EW3w0ZttUfSrso5LlvCPmHUItkYSy5TiqxJCxdi0t3k+D EBRowvo1Y+GAzzqXicpBueCD9MzmsXmCJ+2MblvOM2Vp8qixVHOUzh4jWdInphmF MiHg2m8hkF/06scTgXSq3qx0xsrTE++/132MOKvysq/a8IXfYQTvoiL+0o+wbDcK Kp6+anY4mSam0T8+5VXzvWth9LqS/NiLqVDVwywXC+2KqJHaRMu4aLaAJM0bPQq9 dBqNEw5IANViIbloU+R+Rp6jVVMzdE+c9G1AJlFzalg2lU3aWrlksAYJ3o8+s088 W3RbR0j/EZMKAdf22lqx6zXXH/X7XOErerYaSPQ8qQ== =3LQa -----END PGP SIGNATURE-----