3 ms·
Well, TLS-auth should be used _on top_ of a PKI. It is a HMAC key that an attacker would need to know before he'd even be able to initiate a TLS handshake. Th
by mrsaint 12y ago
Well, TLS-auth should be used _on top_ of a PKI. It is a HMAC key that an attacker would need to know before he'd even be able to initiate a TLS handshake.
Thus, if you have used it in your OpenVPN setup, and if you know that the few users who have access to your VPN wouldn't have heartbleed-attacked you, then yes, you could assume that your private key has been safe from heartbleed despite an exploitable OpenSSL library.