Re: Linux VPN server and client



Am Wed, 28 Nov 2007 02:34:27 -0800 schrieb susikaufmann2003@xxxxxxxxxxx:

Ok, I have a smartcard according to the javacard 2.2.1 standard. The
java card encrypts and decrypts data that is send to my server (writes
it into a mysql-db). The data is encypted, but I don't want the mysql-
db to be that open. So I want to establish a VPN between the client
and the server. I want to create my own CA and the data for login to
the VPN-Server should be oncard. So the VPN-client soft reads it from
the card and uses it to login to the VPN-Server.

Ok got it, the only thing is it makes no sense get a vpn server on a card.
But use the card as client with the clientcert signed by your CA.
Another way what I think you could also do, use the mysql SSL connection
and filter on the server the src-ip's on a firewall, how about that?

cheers
.



Relevant Pages

  • Re: Citrix-like solution/many screens
    ... If it really is necessary to have A gfx card per screen so be it, ... I DON'T want a client pc...does that shed ANY light? ... You could then invent ethernet and Tcp/IP to connect the server ... These client machines cost less than character terminals, ...
    (alt.os.linux)
  • Re: Forwarding problem
    ... Our application has a messaging module which runs on the server B. ... This module has to be able to access the infrastructure (server C) ... with SSL using client authentication. ... in order to identify the card, it shall use card signature and public ...
    (microsoft.public.platformsdk.security)
  • Re: Winsock connection
    ... I've recently faced a similar problem, but only the server 'end' of it - you might find my observations helpful, even though I don't know all the answers at the client 'end'. ... If you are writing the server 'end' on a machine with multiple adapters, you can specify which ip address to use in the app, or implement multiple servers, one per adapter, either as separate apps, or as a single app. ... The device have 2 ethernet cards RTL80391 and RTL80392 and every card ...
    (microsoft.public.windowsce.embedded.vc)
  • Re: What doesnt lend itself to OO?
    ... >> proxy and instructs the server to constuct the real object. ... rather than client code. ... If 'clock' is instantiated in the server, ... > for the server interface at the OOA level. ...
    (comp.object)
  • This is going straight to the pool room
    ... or not the client has privilege to do what they're trying to do, ... The server environment is this: ... 3GL User action Routines that Tier3 will execute on your behalf during the ... Routine Name: USER_INIT ...
    (comp.os.vms)