2 ms·
Too bad the SSL VPN concentrator from this article didn't apply a HMAC key that an attacker would have needed to know before he'd even been able to initiate a T
by mrsaint 12y ago
Too bad the SSL VPN concentrator from this article didn't apply a HMAC key that an attacker would have needed to know before he'd even been able to initiate a TLS handshake to probe the Heartbleed vulnerability.
You can do this with OpenVPN using the --tls-auth option. See: https://community.openvpn.net/openvpn/wiki/Hardening https://community.openvpn.net/openvpn/wiki/Hardening