Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Kerberos with OpenVPN

1,280 views
Skip to first unread message

Prasad (普拉萨德)

unread,
Jan 12, 2010, 9:13:23 AM1/12/10
to kerb...@mit.edu
I don't know whether this is post should be here or not. But I am not
getting the documentation about setting up the Kerberos with OpenVPN.

I want to setup the OpenVPN with Kerberos 5. Is there is any documentation
which help me to setup the OpenVPN with Kerberos 5 as a
authentication mechanism.

--
Prasad S. Wani

--
Prasad S. Wani

John Jasen

unread,
Jan 12, 2010, 4:59:40 PM1/12/10
to "Prasad (普拉萨德)", kerb...@mit.edu
Prasad (普拉萨德) wrote:
> I don't know whether this is post should be here or not. But I am not
> getting the documentation about setting up the Kerberos with OpenVPN.
>
> I want to setup the OpenVPN with Kerberos 5. Is there is any documentation
> which help me to setup the OpenVPN with Kerberos 5 as a
> authentication mechanism.

Unless I'm mistaken, openvpn doesn't support kerberos directly.

I abused PAM by adding:

<snip>
plugin /usr/lib/openvpn/openvpn-auth-pam.so "sshd login USERNAME
password PASSWORD"
</snip>

into /etc/openvpn/server.conf

And configuring PAM to use kerberos, of course.

--
-- John E. Jasen (jja...@realityfailure.org)
-- "Deserve Victory." -- Terry Goodkind, Naked Empire

George Ross

unread,
Jan 13, 2010, 4:30:19 AM1/13/10
to Prasad (普拉萨德), kerb...@mit.edu
> I want to setup the OpenVPN with Kerberos 5. Is there is any documentation
> which help me to setup the OpenVPN with Kerberos 5 as a
> authentication mechanism.

We have thought about it a few times, but came to the conclusion that
Michigan's kx509 <http://www.kx509.org/> was easier.
--
Dr George D M Ross, School of Informatics, University of Edinburgh
10 Crichton Street, Edinburgh, Scotland, EH8 9AB
Mail: gd...@inf.ed.ac.uk Voice: +44 131 650 5147 Fax: +44 131 650 6899
PGP: 1024D/AD758CC5 B91E D430 1E0D 5883 EF6A 426C B676 5C2B AD75 8CC5

The University of Edinburgh is a charitable body, registered in
Scotland, with registration number SC005336.


0 new messages