Re: Secure and convenient protocol

James Cameron <[email protected]>
Newsgroups gmane.network.poptop
Organization Netrek Vanilla Server Dictator
Message-ID <[email protected]>
On Wed, Apr 20, 2011 at 09:31:18PM +0200, Gregoire leroy wrote:
> I manage the network of a student residence, so I don't have any
> control on the client.

I can understand your pain.  I'm curious though what the purpose of the
VPN is, since that would assist with solution choice.  I can imagine
several purposes, and I'm not sure which you might have.

> My first choice was MSCHAPV2, because it's well supported by most
> OS, but it seems unsecure.

It was considered secure once, but times have changed.  I consider it
unsecure now.

> So, is there a secure protocol, well supported by most OS, with which
> we don't need to touch to the client computer ? (with password, for
> example)

I don't believe so, but I only really know about OpenVPN and PPTP.
Others may know.

Basing a security system on only a password (and not also a token) leads
to a weak system, in the same way as building a house upon the sand near
a river.  A system that hashes passwords (MSCHAPV2) cannot be made more
secure by a longer or more complex password; a brute force attack takes
the same resources.

-- 
James Cameron
http://quozl.linux.org.au/

------------------------------------------------------------------------------
Benefiting from Server Virtualization: Beyond Initial Workload 
Consolidation -- Increasing the use of server virtualization is a top
priority.Virtualization can reduce costs, simplify management, and improve 
application availability and disaster protection. Learn more about boosting 
the value of server virtualization. http://p.sf.net/sfu/vmware-sfdev2dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.