Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Development and Code Review
(Moderator:
fabian
) »
PKCS-11 compile option for OpenVPN
« previous
next »
Print
Pages: [
1
]
Author
Topic: PKCS-11 compile option for OpenVPN (Read 2650 times)
bob@afrinet.eu
Newbie
Posts: 26
Karma: 1
Lively cybersec aficionado
PKCS-11 compile option for OpenVPN
«
on:
October 05, 2018, 05:10:22 pm »
I wanted to know why compile options used in OPNsense (and pfSense®) didn't include pkcs11 ?
What is the reason ?
And what would you recommend for stronger authentication method / physical (like smart card ok USB dongle) ?
The optic is a large scale VPN where we would need to push dynamic routes && get strong authentication (firewall to firewall).
Actual OpenVPN compile options are as follow :
root@FW1:~ # openvpn --version
OpenVPN 2.4.6 amd64-portbld-freebsd11.1 [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [AEAD] built on Sep 17 2018
library versions: OpenSSL 1.0.2p 14 Aug 2018, LZO 2.10
Originally developed by James Yonan
Copyright (C) 2002-2018 OpenVPN Inc <sales@openvpn.net>
Compile time defines: enable_async_push=no enable_comp_stub=no enable_crypto=yes enable_crypto_ofb_cfb=yes enable_debug=yes enable_def_auth=yes enable_dlopen=unknown enable_dlopen_self=unknown enable_dlopen_self_static=unknown enable_fast_install=needless enable_fragment=yes enable_iproute2=no enable_libtool_lock=yes enable_lz4=yes enable_lzo=yes enable_management=yes enable_multihome=yes enable_pam_dlopen=no enable_pedantic=no enable_pf=yes enable_pkcs11=no enable_plugin_auth_pam=yes enable_plugin_down_root=yes enable_plugins=yes enable_port_share=yes enable_selinux=no enable_server=yes enable_shared=yes enable_shared_with_static_runtimes=no enable_silent_rules=no enable_small=no enable_static=yes enable_strict=yes enable_strict_options=no enable_systemd=no enable_werror=no enable_win32_dll=yes enable_x509_alt_username=no with_aix_soname=aix with_crypto_library=openssl with_gnu_ld=yes with_mem_check=no with_sysroot=no
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Development and Code Review
(Moderator:
fabian
) »
PKCS-11 compile option for OpenVPN