Project

General

Profile

Actions

Task #4231

closed

Task #4227: Activate a VPN service to grant complete access to the servers network from outside

Better authentication system for the openvpn server

Added by Andrea Dell'Amico almost 10 years ago. Updated over 9 years ago.

Status:
Closed
Priority:
Normal
Assignee:
_InfraScience Systems Engineer
Category:
System Application
Target version:
Start date:
Jun 11, 2016
Due date:
% Done:

100%

Estimated time:
Infrastructure:
Development, Pre-Production, Production

Description

We are using the pam module with local users, right now.

A more secure and manageable system should use a 2FA authentication:

  • local certificates (the personal INFN ones are OK
  • username authentication via LDAP (a special group is needed to not open access to everyone)

Related issues

Related to D4Science Infrastructure - Task #4229: Configure OpenVPN on gw.d4science.orgClosed_InfraScience Systems EngineerJun 11, 2016

Actions
Actions #1

Updated by Andrea Dell'Amico almost 10 years ago

  • Related to Task #4229: Configure OpenVPN on gw.d4science.org added
Actions #2

Updated by Andrea Dell'Amico almost 10 years ago

Different routes for different users could also be used, so that we can access the console servers without exposing them to all the people.

Actions #3

Updated by Andrea Dell'Amico over 9 years ago

  • Status changed from New to In Progress

Update: the openldap-auth-ldap package is broken, openvpn crashes when the plugin is used. Need to find another way.

Actions #4

Updated by Andrea Dell'Amico over 9 years ago

  • % Done changed from 0 to 50

We are now authenticating against the ldap server. An external perl script is doing the checks against the ldap server and the vpn_users group.

Actions #5

Updated by Andrea Dell'Amico over 9 years ago

  • Status changed from In Progress to Closed
  • % Done changed from 50 to 100

The certificates authentication is enabled too.

Actions

Also available in: Atom PDF

Add picture from clipboard (Maximum size: 8.91 MB)