Fwd: Re: Secure and convenient protocol

"Gregoire leroy" <[email protected]>
Newsgroups gmane.network.poptop
Message-ID <[email protected]>

            	
            	----- Original Message -----
            	From: "Gregoire leroy" [email protected]
            	To: "James Cameron" [email protected]
            	Sent: Thu 21/04/11 10:18
            	Subject: Fwd: Re: [Poptop-server] Secure and convenient protocol

<hi>>  I'm curious though what the purpose of
> the VPN is, since that would assist with solution choice.  I can imagine
> several purposes, and I'm not sure which you might have.

The purpose of VPN is to crypt communications, to make harmless MITM attacks. As
I can't struggle against MITM attack, the only solution is to crypt communications.

> 
> > My first choice was MSCHAPV2, because it's well
> supported by most
> OS, but it seems unsecure.
> 
> It was considered secure once, but times have changed.  I consider it
> unsecure now.
> 
> > So, is there a secure protocol, well supported by
> most OS, with which
> we don't need to touch to the client computer ?
> (with password, for
> example)
> 
> I don't believe so, but I only really know about OpenVPN and PPTP.
> Others may know.
> 
> Basing a security system on only a password (and not also a token)
> leads to a weak system, in the same way as building a house upon the sand
> near a river.  A system that hashes passwords (MSCHAPV2) cannot be made
> more secure by a longer or more complex password; a brute force attack
> takes the same resources.

I guess I must find a way to use EAP-TLS in a simple way for the client, to avoid
useless support

Thanks,
Regards,





------------------------------------------------------------------------------
Benefiting from Server Virtualization: Beyond Initial Workload 
Consolidation -- Increasing the use of server virtualization is a top
priority.Virtualization can reduce costs, simplify management, and improve 
application availability and disaster protection. Learn more about boosting 
the value of server virtualization. http://p.sf.net/sfu/vmware-sfdev2dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.