Re: Limit the number of users based on the key
Gert Doering <[email protected]>
| Newsgroups | gmane.network.openvpn.user |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On Tue, Jan 09, 2024 at 11:33:22AM +0000, Peter Davis wrote:
> > What do you mean by "revoke the key of one department"? This question does
> > not make much sense, since there is no per-department key, if you do not
> > have per-department servers.
>
> In your company, you have 3 departments. One is the IT department,
> the other is the management department, and the last one is the
> supervision department. An employee in the supervision department
> shares a key with someone outside the company, and you want to block
> access to the server through that key. You must revoke the certificate
> of the supervision department. If each department has its own key,
> then this does not affect other departments.
Textbook, X.509, please.
*Departments* have no keys/certs. *Users* have keys/certs. So if a *user*
key is lost, you revoke that *user* key.
Why would you revoke the whole access for the department?
gert
--
"If was one thing all people took for granted, was conviction that if you
feed honest figures into a computer, honest figures come out. Never doubted
it myself till I met a computer with a sense of humor."
Robert A. Heinlein, The Moon is a Harsh Mistress
Gert Doering - Munich, Germany [email protected]
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users
signature.asc
(application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE----- iQGcBAEBAgAGBQJlnUJRAAoJEB2Cnv7KVigS9sUMAJm/oqrFnhntaKKB1LGCuUKo GHHWsgwDpcOOAxG6BDwkptKP/FV+9WCXb0Blq/3pGdn1puQGnpvPnAgig1CJu6Gx piNTF8Su1kqEf6IqWwPwoMwFJv2uMR84h+gauR+zYo/xnshbLWLuQHxhI98A2z9M GOeeqvg0a8WU+Vx0El3NhhdjCdahxX4tsqcJxZUBPyvqYxZgCfIIpCaYOxWUYbZZ TydbMInJhdqMeqTFki/kF3gm9awGsg1O2Hsi1VF18KKd4PfkwO9Wp2YbIap6sY6U H5jMZ3XWEvjeoJr2O42Cb/ozcp+AtlluPwAwdskJu5zXp+JiytlGwaS5L0PKp/9o o6GnDue/FPcsLM9NORte6vZrCPL2vaYgRJuNJVsbrKzkDJDP0qqmlKQTYL+xIk92 drnCPGY6OWGzk4Q4imxS4QXbMka9tz7edi5IisnYw0ljbp9TQfl8QcPlGisvzeU3 HFAfscb1v/3NE99LW3anDOncgmkUeSC0dG9IysMAkA== =yWDM -----END PGP SIGNATURE-----