Menu

#819 OpenVPN certs issues

2.1
open
nobody
vpn (1)
5
2014-09-23
2014-09-23
No

In cgi-bin/vpnca.cgi (row 270 in revision 7532) IPsec certificates are correctly unlinked before delete of CA and restart of daemon. The same does not seems to take place for openVPN certificates.

OpenVPN certificates seem to be contained in both /var/ipcop/certs/ and /var/ipcop/openvpn/certs/, and thus the ones in /var/ipcop/openvpn/certs/ are not affected from delete.

In my opinion, the sharing of /var/ipcop/certs/ between IPsec and openVPN could also lead to an overwrite issue. Imagine that two certificates with the same common name are created simultaneously (i.e., an IPsec one and an openVPN one).
But this same issue causes the overwriting of the undeleted certs if others with the same common name are created after a new CA is defined.

Discussion


Log in to post a comment.