| Message ID | 1601232360-14096-1-git-send-email-selva.nair@gmail.com |
|---|---|
| State | Accepted |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director9.mail.ord1d.rsapps.net ([172.30.191.6]) by backend30.mail.ord1d.rsapps.net with LMTP id YIi2FTjecF9sCgAAIUCqbw (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Sun, 27 Sep 2020 14:47:20 -0400 Received: from proxy19.mail.ord1d.rsapps.net ([172.30.191.6]) by director9.mail.ord1d.rsapps.net with LMTP id GP1mFTjecF+gRgAAalYnBA (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Sun, 27 Sep 2020 14:47:20 -0400 Received: from smtp7.gate.ord1d ([172.30.191.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy19.mail.ord1d.rsapps.net with LMTPS id yGTNFDjecF8kKQAAyH2SIw (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Sun, 27 Sep 2020 14:47:20 -0400 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp7.gate.ord1d.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dkim=fail (signature verification failed) header.d=gmail.com; dmarc=fail (p=none; dis=none) header.from=gmail.com X-Suspicious-Flag: YES X-Classification-ID: df1eb536-00f1-11eb-9ab7-525400d0c497-1-1 Received: from [216.105.38.7] ([216.105.38.7:60280] helo=lists.sourceforge.net) by smtp7.gate.ord1d.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id 93/45-25125-73ED07F5; Sun, 27 Sep 2020 14:47:20 -0400 Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.90_1) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1kMbgf-000282-I4; Sun, 27 Sep 2020 18:46:17 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) (envelope-from <selva.nair@gmail.com>) id 1kMbgd-00027s-Ge for openvpn-devel@lists.sourceforge.net; Sun, 27 Sep 2020 18:46:15 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Message-Id:Date:Subject:Cc:To:From:Sender:Reply-To: MIME-Version:Content-Type:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=Pqpyo173DyLGKfoH5dDUY6ZH7mtzWQepMhZneazmzKU=; b=QvmVfq/nE/p2FYHoLkg3CC36Wu C7uKq6C6ymbnSdpK5OOMoyLt0Vl1UBMosUp8gMuNulMqOikzCUr5HzYRhPXfDhSQLAw90rG5Mkow2 udkX1rJaNycjW+hHZF+jn+D4KZi4TKXiqROjQIdUuryaZrTCISOwx46H6LMSpXsGndsg=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Message-Id:Date:Subject:Cc:To:From:Sender:Reply-To:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=Pqpyo173DyLGKfoH5dDUY6ZH7mtzWQepMhZneazmzKU=; b=J+Hu6mf+bKBXg6wlpys2G65cjg V9IUgW0TIta+tMJLkbTN85JeLKE2EzkXCU0jHsRhvb5MyNNYDLYOB7a6omm6s1kp1VNVfXoihm1rc odFnxzWWzQI3fxr74xUVYgu3eQwcRlU9SjKf/F8CcoIWAPys+14aLi+SLJomg7IB1CQc=; Received: from mail-qk1-f193.google.com ([209.85.222.193]) by sfi-mx-3.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.92.2) id 1kMbgY-007xjp-UK for openvpn-devel@lists.sourceforge.net; Sun, 27 Sep 2020 18:46:15 +0000 Received: by mail-qk1-f193.google.com with SMTP id w16so8140855qkj.7 for <openvpn-devel@lists.sourceforge.net>; Sun, 27 Sep 2020 11:46:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id; bh=Pqpyo173DyLGKfoH5dDUY6ZH7mtzWQepMhZneazmzKU=; b=JYhsnSJ2MWxq2I5NHEVq1apEGVj6oBmCmnNybBPuiRttPwnYL/EnTKXdLDzX0Fbxpo /suVr2H8GLxJLXOb0UjNpe8lwHnzo9dS73MgD0Lumc+NglkqY+6d5VKaoUErEX43mPaV PuHggPKIDu6YDHN0Lsg1KjkJg3HxcwBsZSQGIWHyeXImehb78s6xDt1LoC/DUNzVBKaH zmtCGIoF/pSPHscF90K6BZMysu6+pkoQ/Xlac/+OA3QPYZTIguNxThJyvzPHGWtDmzW3 JOFaiWRv5kZAVTXyQJhv/B5Q0jLLq2q3J/6mb5fLuzm35GdW5fhG522v+jaEEzWczf56 YcXA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=Pqpyo173DyLGKfoH5dDUY6ZH7mtzWQepMhZneazmzKU=; b=N7IH5IcJMK1SAdoDKfToTs9MTkdjz6TeO/tL/fZJtKERgByvvEbLLCevdBGfftlY1S bdQLPWo0TWNb1FwIzJns9AwuXl+x6rj1jsHDAoJv2qeMC3dCKdvbLQdo6GSO5E25zSZn A18d73AVd383oiL9a+XMGHON8/+QeyCcO52bGvYNB4TjkVuWeAyyWYOzbPrmFAFE6Z9c SERvyxtTOOdLXWYh3fn3r2M6yCHjk9kIdlkKvev+iwj+0NYRSfKenVdMeHIrIOJfpye3 ZIZdvN96w0pfleDqDsFNo4NrAyyoPCJc4nDHK0OGyoVqnQy/0eY0k99cld1izxm959Qh i8Ug== X-Gm-Message-State: AOAM530eW2jAyhZIPkpC9/jUofzYh1aRKFO8C7fHwUJzCE6AHLRAgeed VhtyHI8iuugimgUfZSJPyuIbcIq1ljw= X-Google-Smtp-Source: ABdhPJwtS0OHMZQSrMP3l/2khseG2CmRwWpiFu4Vkf8fQfCrd1mTr6RPeLB5JvnZYxn3NkCDPGJKHg== X-Received: by 2002:a05:620a:78f:: with SMTP id 15mr8688161qka.340.1601232364839; Sun, 27 Sep 2020 11:46:04 -0700 (PDT) Received: from saturn.home.sansel.ca (CPE40167ea0e1c2-CM788df74daaa0.cpe.net.cable.rogers.com. [99.228.34.11]) by smtp.gmail.com with ESMTPSA id g203sm6874190qkb.51.2020.09.27.11.46.03 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sun, 27 Sep 2020 11:46:04 -0700 (PDT) From: selva.nair@gmail.com To: openvpn-devel@lists.sourceforge.net Date: Sun, 27 Sep 2020 14:46:00 -0400 Message-Id: <1601232360-14096-1-git-send-email-selva.nair@gmail.com> X-Mailer: git-send-email 2.1.4 X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (selva.nair[at]gmail.com) -0.5 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [209.85.222.193 listed in wl.mailspike.net] -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [209.85.222.193 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1kMbgY-007xjp-UK Subject: [Openvpn-devel] [PATCH] Improve documentation of --username-as-common-name X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
[Openvpn-devel] Improve documentation of --username-as-common-name
|
|
Commit Message
Selva Nair
Sept. 27, 2020, 8:46 a.m. UTC
From: Selva Nair <selva.nair@gmail.com> Trac #1079 Signed-off-by: Selva Nair <selva.nair@gmail.com> --- doc/man-sections/server-options.rst | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-)
Comments
On 27/09/2020 20:46, selva.nair@gmail.com wrote: > From: Selva Nair <selva.nair@gmail.com> > > Trac #1079 > > Signed-off-by: Selva Nair <selva.nair@gmail.com> > --- > doc/man-sections/server-options.rst | 12 +++++++++--- > 1 file changed, 9 insertions(+), 3 deletions(-) > > diff --git a/doc/man-sections/server-options.rst b/doc/man-sections/server-options.rst > index c0b22a5..4b649b1 100644 > --- a/doc/man-sections/server-options.rst > +++ b/doc/man-sections/server-options.rst > @@ -668,9 +668,15 @@ fast hardware. SSL/TLS authentication must be used in this mode. > ``--max-routes-per-client`` > > --username-as-common-name > - For ``--auth-user-pass-verify`` authentication, use the authenticated > - username as the common name, rather than the common name from the client > - cert. > + Use the authenticated username as the common-name, rather than the > + common-name from the client certificate. Requires that some form of > + auth-user-pass verification is in effect. As the replacement happens after > + auth-user-pass verification, the verification script or plugin will still The two occurrences of "auth-user-pass" should be: ``--auth-user-pass`` (with "double-backwards-single-quotes" in both ends) > + receive the common-name from the certificate. > + > + The common_name environment variable passed to scripts and plugins invoked > + after authentication (e.g, client-connect script) and file names parsed in > + client-config directory will match the username. I have not verified the behavior described, but I trust Selva's understanding and testing. The extension of this part is valuable and makes both the man entry and behavior clearer. The fix I've touched above can be handled at commit-time, unless Gert objects. Acked-By: David Sommerseth <davids@openvpn.net>
Thanks, documentation clarification is always welcome. I have added
formatting to --auth-user-pass as instructed (and rewrapped the
paragraph slightly to avoid overlong lines in the .rst)
Your patch has been applied to the master and release/2.5 branch.
commit 66ad8727935a371e237a5bada142c9f5f467c3f8 (master)
commit f9f5b4a307ddd59dd9eddcc869d05cc89dffbeb5 (release/2.5)
Author: Selva Nair
Date: Sun Sep 27 14:46:00 2020 -0400
Improve documentation of --username-as-common-name
Signed-off-by: Selva Nair <selva.nair@gmail.com>
Acked-by: David Sommerseth <davids@openvpn.net>
Message-Id: <1601232360-14096-1-git-send-email-selva.nair@gmail.com>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg21098.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/doc/man-sections/server-options.rst b/doc/man-sections/server-options.rst index c0b22a5..4b649b1 100644 --- a/doc/man-sections/server-options.rst +++ b/doc/man-sections/server-options.rst @@ -668,9 +668,15 @@ fast hardware. SSL/TLS authentication must be used in this mode. ``--max-routes-per-client`` --username-as-common-name - For ``--auth-user-pass-verify`` authentication, use the authenticated - username as the common name, rather than the common name from the client - cert. + Use the authenticated username as the common-name, rather than the + common-name from the client certificate. Requires that some form of + auth-user-pass verification is in effect. As the replacement happens after + auth-user-pass verification, the verification script or plugin will still + receive the common-name from the certificate. + + The common_name environment variable passed to scripts and plugins invoked + after authentication (e.g, client-connect script) and file names parsed in + client-config directory will match the username. --verify-client-cert mode Specify whether the client is required to supply a valid certificate.