Skip to content

openvpn still relevant? My client mandate nightmare

VPS Hosting by blogfranck 22 replies 3.2K views
#11
blogfranck said:
15 USD per user per year

THAT'S CHEAPER THAN ONE HOUR OF YOUR TIME!!!

BUT RANDY IS ALSO RIGHT!!! PASS THE COST THROUGH!!! MARK IT UP 200%!!! "MANAGED LEGACY ACCESS SERVICE"!!!

ALTERNATIVE I FORGOT: PRITUNL HAS OPENVPN COMPATIBILITY AND AUTO-UPDATING CLIENT PACKAGES!!! CHEAPER THAN ACCESS SERVER!!!

5 #12

Thanks ronwit. 2.6.x with --enable-legacy-cipher, noted.

Does anyone know if the Windows 7 client from openvpn.net still installs on fully patched Win7? Last I heard the tap driver was getting blocked by SHA1 deprecation in driver signatures.

#13
Paul76 said:
The tap driver was getting blocked by SHA1 deprecation in driver signatures

Actually this is the REAL nightmare. Microsoft killed SHA1 driver signatures in 2021. The openvpn tap-windows6 driver newer than 9.24.x will NOT install on vanilla Windows 7 without ESU patches and cross-signed cert workarounds.

For that one client you probably need to keep using tap-windows 9.21.2 from 2017. Which has its own fun.

Actually sorry I keep posting in this thread.

instant noodles, instant deploys
#14
ronwit said:
Tap-windows 9.21.2 from 2017

Mon dieu. I did not know this. The client with Windows 7 is also the client with the 2019 tls-auth key. I suspect they have not patched since 2019.

I am going to quote them 40 hours for "security hardening assessment" and use Access Server. Let them say no.

7 #15

This is so depressing!! I thought banks were supposed to be secure!!

Is there like a regulatory body you can report this to?? In Canada we have OSFI for federal banks!!

learning on $5 VPS and prayers
#16

Regulatory body

The same regulatory body that wrote the compliance checklist that mandates openvpn in the first place

airgapped, encrypted, faraday'd, still worried
#17

I migrated my entire org to WireGuard three years ago. Zero regret. The only OpenVPN I touch is clients who insist, and I charge 2x for the privilege.

Legacy cipher support is a liability not a feature. BF-CBC should be in a museum.

#18
techmei said:
I migrated my entire org to WireGuard three years ago

WireGuard lacks the audit logging granularity that PCI-DSS and SOX demand. OpenVPN's --status and --management interface are why finance still uses it. Not because we love it. Because auditors understand it.

#19
sslgerm said:
WireGuard lacks the audit logging granularity

Wg-quick with post-up scripts to iptables LOG target, plus netflow. Auditors adapt. The ones who don't should retire.

9 #20

Following this thread because my MSP has a law firm still on Windows Server 2008 R2. Same energy. Same despair.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft