Book Image

Troubleshooting OpenVPN

By : Eric F Crist
Book Image

Troubleshooting OpenVPN

By: Eric F Crist

Overview of this book

OpenVPN, the most widely used open source VPN package, allows you to create a secure network across systems, keeping your private data secure. Connectivity and other issues are a pain to deal with, especially if they are impacting your business. This book will help you resolve the issues faced by OpenVPN users and teach the techniques on how to troubleshoot it like a true expert. This book is a one stop solution for troubleshooting any issue related to OpenVPN. We will start by introducing you to troubleshooting techniques such as Packet Sniffing, Log Parsing, and OpenSSL. You will see how to overcome operating system specific errors. Later on, you will get to know about network and routing errors by exploring the concepts of IPv4 and IPv6 networking issues. You will discover how to overcome these issues to improve the performance of your OpenVPN deployment. By the end of the book, you will know the best practices, tips, and tricks to ensure the smooth running of your OpenVPN.
Table of Contents (16 chapters)

Chapter 6. Certificates and Authentication

There are many methods of authentication available within OpenVPN. At its introduction, OpenVPN supported only a simple pre-shared key but today supports X.509 certificate chains, user and password authentication, and third-party authentication plugins and scripts. Each of these can be used separately, or they can be combined to form a robust authentication and authorization framework.

Along with robustness, complexity creates potential confusion and adds difficulty in troubleshooting authentication issues, understanding how the individual components affect the connection process and where logic is applied in accepting or rejecting a client or user.

Mismanagement of your PKI can have great consequences, whether your PKI is relatively local in scope (a single organization or hobbyist's systems), or global, such as a public certificate authority (CA) providing certificates to customers. There were two cases in 2016 of trusted CAs that lost trust with...