Re: Limit the number of users based on the key

Gert Doering <[email protected]>
Newsgroups gmane.network.openvpn.user
Message-ID <[email protected]>
Hi,

On Tue, Jan 09, 2024 at 10:06:33AM +0000, Peter Davis wrote:
> I'd like to use something like a MAC address filtering mechanism, but that would require scripting and I don't know how to do that. I want no one to be able to connect to the OpenVPN server without permission.

If a user has no key, they have no permission.  If you give them a key,
you have given them permission.

If you want stronger auth, add --auth-user-pass and (for example) an LDAP
backend, so users need to have a key *and* know a password.

> 2- What's the solution? Should I generate one server key and multiple client keys? Isn't it better if each department has its own server key?

Do you have one server per department, or one server for all?

It makes sense to have one server key *per server*, but whether or not
that is "per department" depends on what you are trying to achieve.

gert
-- 
"If was one thing all people took for granted, was conviction that if you 
 feed honest figures into a computer, honest figures come out. Never doubted 
 it myself till I met a computer with a sense of humor."
                             Robert A. Heinlein, The Moon is a Harsh Mistress

Gert Doering - Munich, Germany                             [email protected]

_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users
signature.asc (application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE-----

iQGcBAEBAgAGBQJlnRyxAAoJEB2Cnv7KVigSwncL/i6TudXFyVbGMZQ6blv5OB34
yHQ/PsZGCAE7D3u+rjxNTiPjzl4uYO6fFNTMgX5pgxV3+iqpowwlijXgiBQpw+v1
xkYc0b9RNTw9/0SitsLQ+H3/QDX0/2U5sdryduxNVrNtxUN73v0B/G/5dKZvrdPE
UPteVpZ9hYM7F3ZTQp0EW3w0ZttUfSrso5LlvCPmHUItkYSy5TiqxJCxdi0t3k+D
EBRowvo1Y+GAzzqXicpBueCD9MzmsXmCJ+2MblvOM2Vp8qixVHOUzh4jWdInphmF
MiHg2m8hkF/06scTgXSq3qx0xsrTE++/132MOKvysq/a8IXfYQTvoiL+0o+wbDcK
Kp6+anY4mSam0T8+5VXzvWth9LqS/NiLqVDVwywXC+2KqJHaRMu4aLaAJM0bPQq9
dBqNEw5IANViIbloU+R+Rp6jVVMzdE+c9G1AJlFzalg2lU3aWrlksAYJ3o8+s088
W3RbR0j/EZMKAdf22lqx6zXXH/X7XOErerYaSPQ8qQ==
=3LQa
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.