BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] vnc
- Subject: [Discuss] vnc
- From: richard.pieri at gmail.com (Richard Pieri)
- Date: Mon, 25 Aug 2014 12:05:55 -0400
- In-reply-to: <1068d3cc341e984e64de0b15000633ee.squirrel@mail.mohawksoft.com>
- References: <53F9F6B9.4060505@stephenadler.com> <20140824161132.GE14848@randomstring.org> <be314521ab6bebb6add54d706b042f01.squirrel@mail.mohawksoft.com> <53FA1C3B.70908@gmail.com> <cb98ac9a77c99dd9313c5b1503d30ee1.squirrel@mail.mohawksoft.com> <53FB453F.8040201@gmail.com> <1068d3cc341e984e64de0b15000633ee.squirrel@mail.mohawksoft.com>
On 8/25/2014 11:12 AM, markw at mohawksoft.com wrote: > With openvpn you can enable two-factor authentication and a lot more > security. You can do this with SSH, too. It's called "UsePAM" in OpenSSH, compiling Dropbear with PAM enabled, etc., plus appropriate PAM modules. Then there's Kerberos. Verifiable trust is fundamental to Kerberos. This makes it more secure than X.509 which relies on root certificate authorities which, by design, cannot be verified to be trustworthy. If you Kerberize your services then you can use LDAP to manage access control to those services, and you can do it as finely or as coarsely as you want. Put them all together and you have an authentication and access control system that makes OpenVPN look like a bad joke. What traditional VPN servers have over this is that they're easier to add to existing infrastructure than Kerberizing existing infrastructure. -- Rich P.
- References:
- [Discuss] vnc
- From: adler at stephenadler.com (Stephen Adler)
 
- [Discuss] vnc
- From: dsr at randomstring.org (Dan Ritter)
 
- [Discuss] vnc
- From: markw at mohawksoft.com (markw at mohawksoft.com)
 
- [Discuss] vnc
- From: richard.pieri at gmail.com (Richard Pieri)
 
- [Discuss] vnc
- From: markw at mohawksoft.com (markw at mohawksoft.com)
 
- [Discuss] vnc
- From: richard.pieri at gmail.com (Richard Pieri)
 
- [Discuss] vnc
- From: markw at mohawksoft.com (markw at mohawksoft.com)
 
 
- [Discuss] vnc
- Prev by Date: [Discuss] vnc
- Next by Date: [Discuss] Why the dislike of X.509?
- Previous by thread: [Discuss] vnc
- Next by thread: [Discuss] vnc
- Index(es):
