Nathaniel Harward | 1 Sep 2003 10:54
Picon
Favicon

[newbie] question about the contents of the "tls-auth" file

I am setting up OpenVPN for the first time and want to use the TLS
authentication over the static key method.  From what I've read using the
"tls-auth" option seems to be a pretty good idea when doing this.  However, I'm
unable to find any mention of what the tls-auth file should actually contain
and how large it should be: is this a particular key? random data? a text file
with a password...?  In the docs it's referred to as a "shared secret", when I
hear "shared secret" in a file context I think of random data that only the
participants know about, but in and of itself has no real meaning.

I unfortunately can't remember where I read about how this works (the contents
of the tls-auth file are sent verbatim across the wire without header or
checksum info followed immediately by the real TLS authentication?), but if I
understand it correctly it sounds like this file should be some random data and
probably need not be more than 1k or so, if even that (depending on how
paranoid you feel, of course).

Can anybody advise on this?  If this was already posted somewhere else I
apologize, I did several searches through this list and on Google and was
unable to find an answer to this question.  Any help is appreciated.

Thank you,
Nat Harward
nharward at yahoo dot com

__________________________________
Do you Yahoo!?
Yahoo! SiteBuilder - Free, easy-to-use web site design software
http://sitebuilder.yahoo.com

-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf

Gmane