3 ms·
Not necessarily. What about exploiting VPN clients? IPSec is a disaster, one aspect of which is having a client daemon listening on an open port for isakmp/ike
by ankp 17y ago
Not necessarily. What about exploiting VPN clients?
IPSec is a disaster, one aspect of which is having a client daemon listening on an open port for isakmp/ike key exchange.
There's also the configuration to consider. Using PSK or aggressive mode for VPNs can be considered bad but are you really going to deploy a full RADIUS solution just to access a web server?
Provisionally "yes", but I'd actually use OpenVPN, wired into our existing directory infrastructure.
Compare this to using public key based auth on SSH, I know which one I'd rather have for a web server.
Why do you consider it a net win to reduce the entry barrier to only one exploit, one bad user password, or one misconfigured host?