Re: Limit the number of users based on the key

Gert Doering <[email protected]>
Newsgroups gmane.network.openvpn.user
Message-ID <[email protected]>
Hi,

On Tue, Jan 09, 2024 at 11:14:26AM +0000, Peter Davis wrote:
> 1- So, by using --auth-user-pass I can prevent excessive access to the server.

That depends on your definition of "excessive" and "prevent", but it
gives you more control on who can login, and when.

> 2- I want each department to have its own key, because if I want to revoke the key of one department, then there will be no problem for other departments. Is this a good idea?

What do you mean by "revoke the key of one department"?  This question does
not make much sense, since there *is no* per-department key, if you do not
have per-department servers.

OTOH, you could work with multi-level CAs (root CA signs department CA,
department CA maintains all user certs for that department) - so in that
case, you could indeed revoke the department key.  But before you even
think about going there, *read a good textbook* on X509 certificates.

gert

-- 
"If was one thing all people took for granted, was conviction that if you 
 feed honest figures into a computer, honest figures come out. Never doubted 
 it myself till I met a computer with a sense of humor."
                             Robert A. Heinlein, The Moon is a Harsh Mistress

Gert Doering - Munich, Germany                             [email protected]

_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users
signature.asc (application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE-----

iQGcBAEBAgAGBQJlnStcAAoJEB2Cnv7KVigSIdIL/Rg6epeUdaqyJrmq337Q2xSA
rvCfNKqbsNvoxez2S1aRAYX17FFXekGqNJhxy+H7YYJZuQTGLsTuJxUiEPn1EPwN
MmJZYxEW8U/YeqnGT4kOVBigG/UjQuf3acmtg7fe6FIaZyKVSN+TxnPZiPFODkxS
vah7A2BpnZEvzJHtwmMfeJHaSt+rXpYk4xzgEnExdr9BHkCEhPq7Qzj3bGrLUpKj
YeegB8Q5YsJbDI5h56petcNiGi1POmALDQJ9amNhzBOHL0kXZHdSB8mVfkSaJTsD
XBIgBnGdFdAKuGd+8Iu4IYYggNnlqRazT6TYjjHDFYC0nO1aqBpTEj4fXLw/6dMU
NY1zACCizABdfxtob637QhfxD1wlAcYJK+/YK4Z5V6RQfTqiQoEwYSgENDQlQxwV
JZ6jG6OuWXkWBATJGqnLk91opckNgf/FGP/NQDhVb4yxDInt1IUpuB7rs8v5UoMw
3zRS9mM352fE67j9BY5cS8zvTxyIG3Su3IKgrWCtHw==
=NpbJ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.