-
-
Notifications
You must be signed in to change notification settings - Fork 20
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Verify current client X509 certificate is bound to this TLS Crypt V2 key
The client-connect script will only find the client metadata file if the serial number of the current certificate matches the name of the temporary file created by easytls-cryptv2-verify.sh Otherwise, easytls-cryptv2-client-connect.sh treats a missing temp file as a certificate mismatch and drops the client connection. i. The current X509 certificate serial number: openvpn:-tls_serial_hex_{0} ii. The TLS Crypt V2 key metadata field: verified certificate serial number. Signed-off-by: Richard Bonhomme <[email protected]>
- Loading branch information
1 parent
2966bc8
commit aa76b19
Showing
1 changed file
with
24 additions
and
21 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
aa76b19
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
#103