EFW Support

Support => VPN Support => Topic started by: kashif_max on Monday 01 June 2015, 08:35:27 pm



Title: WARNING about Man in the middle attack (mitm)
Post by: kashif_max on Monday 01 June 2015, 08:35:27 pm
Hi,
Running EFW (2.5) since a long time and working smoothly.

I almost rarely check OpenVPN server's log file but recently someone showed me this warning (OpenVPN client's log file).

Code:
WARNING: No server certificate verification method has been enabled see "openvpn.net/index.php/open-source/documentation/howto.html#mitm".

Then I checked server log file.

Code:
WARNING: file "/var/efw/openvpn/pkcs12.p12" is group or others accessible
WARNING: POTENTIALLY DANGEROUS OPTION --client-cert-not-required may accept clients which do not present a certificate

Did anyone noticed on EFW 2.5 or EFW 3.0?

Should I really care about those warnings? How can I do it to prevent them?

Thank you


Title: Re: WARNING about Man in the middle attack (mitm)
Post by: kashif_max on Monday 01 June 2015, 08:39:42 pm
Using PSK (username and password) method for OpenVPN.