[Openvpn-devel] patch for 2.2.2 to include --script-dir

2012-08-23 Thread ammdispose-...@yahoo.com
Hello all, I am submitting a minor patch which includes an option to specify --script-dir. i.e. any user defined script will be run ONLY IF it is present in "script-dir". The reason I needed this is because I had a frontend to configuration file which allowed administrator to change configuratio

Re: [Openvpn-devel] patch for 2.2.2 to include --script-dir

2012-08-23 Thread Heiko Hund
Hi On Thu 23 08 2012 21:09:49 ammdispose-...@yahoo.com wrote: > So my idea was > 1) Add a new option called script-dir > 2) Frontend will not allow word "script-dir" in config file (so admin cant > change it) > 3) script-dir will be passed on command line > > This way admin can not run anything

Re: [Openvpn-devel] patch for 2.2.2 to include --script-dir

2012-08-23 Thread Amm Vpn
Hi > > From: Heiko Hund >To: openvpn-devel@lists.sourceforge.net; "ammdispose-...@yahoo.com" > >Sent: Thursday, 23 August 2012 7:15 PM >Subject: Re: [Openvpn-devel] patch for 2.2.2 to include --script-dir > >Hi > >On Thu 23 08 2012 21:09:49 ammdispose-...@yaho

Re: [Openvpn-devel] patch for 2.2.2 to include --script-dir

2012-08-23 Thread Eric Crist
On Aug 23, 2012, at 09:45:14, Amm Vpn wrote: >> Hi >> >> On Thu 23 08 2012 21:09:49 ammdispose-...@yahoo.com wrote: >>> So my idea was >>> 1) Add a new option called script-dir >>> 2) Frontend will not allow word "script-dir" in config file (so admin cant >>> change it) >>> 3) script-dir will b

Re: [Openvpn-devel] patch for 2.2.2 to include --script-dir

2012-08-23 Thread Amm Vpn
- Original Message - > From: Eric Crist > To: Amm Vpn > Cc: Heiko Hund ; "openvpn-devel@lists.sourceforge.net" > > Sent: Thursday, 23 August 2012 8:19 PM > Subject: Re: [Openvpn-devel] patch for 2.2.2 to include --script-dir   >> So best is to make OpenVPN itself secure. And run on

Re: [Openvpn-devel] patch for 2.2.2 to include --script-dir

2012-08-23 Thread Eric Crist
On Aug 23, 2012, at 10:30:51, Amm Vpn wrote: > - Original Message - >> From: Eric Crist >> To: Amm Vpn >> Cc: Heiko Hund ; >> "openvpn-devel@lists.sourceforge.net" >> Sent: Thursday, 23 August 2012 8:19 PM >> Subject: Re: [Openvpn-devel] patch for 2.2.2 to include --script-dir > >>>

Re: [Openvpn-devel] patch for 2.2.2 to include --script-dir

2012-08-23 Thread David Sommerseth
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 23/08/12 15:09, ammdispose-...@yahoo.com wrote: > Hello all, > > I am submitting a minor patch which includes an option to specify > --script-dir. > i.e. any user defined script will be run ONLY IF it is present in > "script-dir". > > The reason I

Re: [Openvpn-devel] patch for 2.2.2 to include --script-dir

2012-08-23 Thread David Sommerseth
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 23/08/12 17:30, Amm Vpn wrote: > > Currently openvpn BLINDLY runs any script which in my opinion is > too dangerous. One breach and intruder can simply erase your whole > harddisk. Agreed. > My idea of script-dir is taken from sendmail concept of

[Openvpn-devel] [PATCH] Document the inlining of files in openvpn and document key-direction

2012-08-23 Thread Arne Schwabe
This patch documents the usage of inline files in OpenVPN. Hackish ways of inline files are deliberately left out. For tls-auth and secret the key-direction option is right way of specifying the direction and not by using two tls-auth/secret lines where the first sets the direction and has a dum

Re: [Openvpn-devel] [PATCH] Document the inlining of files in openvpn and document key-direction

2012-08-23 Thread Gert Doering
Hi, On Thu, Aug 23, 2012 at 11:21:00PM +0200, Arne Schwabe wrote: > This patch documents the usage of inline files in OpenVPN. Hackish ways of > inline files are deliberately left out. For tls-auth and ACK. (This is far too useful to be left undocumented :-) ) gert -- USENET is *not* the non