Re: [Openvpn-users] New OpenVPN 2.3.6 Windows installers released

2015-03-06 Thread Simon Deziel
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi Samuli, Since the download link are pointing to swupdate.openvpn.org and this server has a valid SSL certificate, would it be possible to publish HTTPS links? Thanks in advance. Best regards, Simon Deziel On 03/05/2015 08:01 AM, Samuli Seppänen

Re: [Openvpn-users] New OpenVPN 2.3.6 Windows installers released - FREAK

2015-03-06 Thread Steffan Karger
Hi, On Fri, Mar 6, 2015 at 12:32 PM, wrote: > Can somebody please explain this: > > Adding !EXP to the server side tls-cipher is enough to mitigate attacks. The > suggested tls-cipher string is DEFAULT:!EXP:!LOW:!PSK:!SRP:!kRSA. This > disallows export ciphers, weak ciphers (e.g. DES), and RSA k

Re: [Openvpn-users] New OpenVPN 2.3.6 Windows installers released - FREAK

2015-03-06 Thread debbie10t
- Original Message - From: "Steffan Karger" To: "Debbie Tent" ; Sent: Friday, March 06, 2015 3:23 PM Subject: Re: [Openvpn-users] New OpenVPN 2.3.6 Windows installers released - FREAK > Hi, > > On Fri, Mar 6, 2015 at 12:32 PM, wrote: >> Can somebody please explain this: >> >> Addi

Re: [Openvpn-users] Unexplainable "bad source address from client" after reconnect (bug?) - Still happening

2015-03-06 Thread Gert Doering
Hi, On Fri, Mar 06, 2015 at 02:04:36PM +0100, David Schweikert wrote: > On Fri, Feb 06, 2015 at 15:24:19 +0100, David Schweikert wrote: > > Feb 5 11:10:12 v-gate openvpn[20629]: h25848/101.92.13.121:5551 MULTI_sva: > > pool returned IPv4=192.168.0.92, IPv6=(Not enabled) > > ... > > Feb 5 11:49:

Re: [Openvpn-users] Unexplainable "bad source address from client" after reconnect (bug?) - Still happening

2015-03-06 Thread David Schweikert
On Fri, Feb 06, 2015 at 15:24:19 +0100, David Schweikert wrote: > Feb 5 11:10:12 v-gate openvpn[20629]: h25848/101.92.13.121:5551 MULTI_sva: > pool returned IPv4=192.168.0.92, IPv6=(Not enabled) > ... > Feb 5 11:49:08 v-gate openvpn[20629]: h25848/101.92.13.121:5551 MULTI: bad > source address

Re: [Openvpn-users] New OpenVPN 2.3.6 Windows installers released

2015-03-06 Thread Pavel Bychikhin
Hello, I've checked my TCP server with SSL FREAK Check (https://tools.keycdn.com/freak) and it said my address is not vulnerable to the SSL FREAK attacks. Is it enough or I have to update OpenVPN anyway? Best regards, Pavel On 05.03.2015 15:01, Samuli Seppänen wrote: Hi all, New Windows ins

Re: [Openvpn-users] New OpenVPN 2.3.6 Windows installers released - FREAK

2015-03-06 Thread debbie10t
Hi Can somebody please explain this: Adding !EXP to the server side tls-cipher is enough to mitigate attacks. The suggested tls-cipher string is DEFAULT:!EXP:!LOW:!PSK:!SRP:!kRSA. This disallows export ciphers, weak ciphers (e.g. DES), and RSA key exchange (note: not RSA authentication), but