LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-22-2020, 02:27 PM   #16
aboka
LQ Newbie
 
Registered: Jun 2020
Posts: 26

Original Poster
Rep: Reputation: Disabled

phew, hv manage to solve that issue by following a guide on webdock - allowing access to the '.wellknown' in the config. think now only left is more test and find ways to backup and restore the cert to a new server. will try tomorrow as its nearly 5 in the morning. time flies trying to fix things like this

thanks and will post back soon. cheers.

Last edited by aboka; 06-22-2020 at 03:42 PM.
 
Old 06-23-2020, 09:53 AM   #17
aboka
LQ Newbie
 
Registered: Jun 2020
Posts: 26

Original Poster
Rep: Reputation: Disabled
Ser Olmy - hi, hopefully can hv time tomorrow and try the last step - backup and restore the cert. would like to confirm the steps again with you:

1) disable everything on old server- SE, nginx, certbot

2) setup SE and backup its config from old to new

3) setup nginx and certbot the same way on new server - except generating a certificate. disable nginx and certbot

4) create the folders on the new server and upload everything inside "/etc/letsencrypt/live/vpn885951179.softether.net/" to new server

beside using SE ServerCertSet to point the SSL to the server, anything we need to 'update'? or they will just work after rebooting?

thank you,

Last edited by aboka; 06-23-2020 at 10:50 AM.
 
Old 06-23-2020, 02:10 PM   #18
Qusserel
LQ Newbie
 
Registered: Nov 2018
Posts: 3

Rep: Reputation: 0
Quote:
Originally Posted by Ser Olmy View Post
Yes, it would work. The provider I linked to explicitly supports the validation mechanism used by Let's Encrypt, but even other providers might work if you use web server authentication.

And no, a DDNS name is not a "pointer". It's a regular DNS host record, just like any other. In DNS, a "pointer" (PTR) is a specific type of record that points to a hostname from an IP address. That's not at all what we're talking about here.
What does that have to do with anything? You do realize that there's absolutely no relation between a VPS provider and a DNS name?
If you read up on the X.509 standard, any uncertainties will instantly vanish.

SoftEther uses OpenSSL. The moment they realize "hey, our code allows for invalid Subject names in certificates!" they may decide to fix it. And then your setup instantly breaks.
That's how one might set up SSL in a lab environment. On the Internet, self-signed certificates are either a serious security risk or a major nuisance, depending on how the client is configured.

Your setup falls into the latter category, which is fortunate. Now all you have to do is switch to a proper SSL certificate, and your setup should be secure and pretty much maintenance-free.
That only applies if the clients are configured to uncritically accept any self-signed certificate. https://eduzaurus.com/free-essay-samples/gun-control/ Incompetent people have been known to do this to avoid manually having to deploy the certificate, which means they've basically disabled the authentication part of SSL/TLS.

If all self-signed certificates are good, then the certificate I just made is perfectly fine, and I can just intercept their SSL handshake and impersonate the server. Inside the SSL stream, authentication is done in plain text, so now I've got your username and password. And if I just forward the traffic to the real server, I've got your data as well.

You probably should have researched this before setting up your VPN. That way you wouldn't have painted yourself into a corner like this, and you wouldn't have had to deploy the certificate manually at all. Just something to keep in mind next time you want to setup something for the first time.

Sorry if I'm sounding a bit harsh, but security-related misconfigurations can have serious implications for every user involved.
Thank you very much for your answers, very helpful.

Last edited by Qusserel; 06-28-2020 at 01:08 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSL certificate generation question - No certificate matches private key etcetera Linux - General 1 04-10-2017 01:28 PM
[SOLVED] The certificate is expired. Please ensure you have the correct certificate and your s manalisharmabe Linux - General 6 09-09-2013 12:51 PM
Best way to create a SSL/TLS certificate to connect the LDAP Client rgtruss Linux - Newbie 1 11-08-2012 08:00 AM
How to import/use CAcert SSL root certificate to use SSL with Xchat IRC client? GrapefruiTgirl Linux - Software 9 04-05-2011 09:54 AM
Apache with SSL does not load the 2nd SSL certificate janstapel Linux - Newbie 1 06-17-2010 09:32 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration