<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=31&amp;t=1462" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-09-13T02:01:29+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=31&amp;t=1462</id>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2014-09-11T08:05:55+01:00</updated>
<published>2014-09-11T08:05:55+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1462&amp;p=5546#p5546</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1462&amp;p=5546#p5546"/>
<title type="html"><![CDATA[Re: [HOW TO] Redundant VPN servers w/ multifactor authentica]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1462&amp;p=5546#p5546"><![CDATA[
Thank you for this.<br /><br />You have a PM.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Thu Sep 11, 2014 8:05 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[FlorinAndrei]]></name></author>
<updated>2014-09-13T02:01:29+01:00</updated>
<published>2014-09-11T02:14:56+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1462&amp;p=5545#p5545</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1462&amp;p=5545#p5545"/>
<title type="html"><![CDATA[[HOW TO] Redundant VPN servers w/ multifactor authentication]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1462&amp;p=5545#p5545"><![CDATA[
<strong>Requirements:</strong> Ubuntu 14.04, yubikey-ksm, yubikey-val (recent versions), Yubikey token<br /><strong>Description:</strong> Pair of fully redundant OpenVPN servers with multifactor authentication, using Yubikey.<br /><br />Basically, you need to create your VPN infrastructure, you want multifactor authentication, and you want redundancy. This document shows you how.<br /><br />Note: This (v01) is a preliminary version. Feel free to review it and point out improvements, if needed. I will revise the document and update it if significant changes are needed. I'm especially interested in the interaction between the DB replication and yubikey-val (ykval-queue is disabled); I think it should work the way I did it, and my tests were successful, but comments and improvements are welcome.<br /><br />What's in the document:<br /><br />- Install two OpenVPN servers, fairly classic setup, fine-tuned for this scenario<br />- Create your own CA (certificate authority), generate certificates for servers and clients<br />- Configure OpenVPN for SSL certificate authentication<br />- Add Yubikey OTP authentication, either local (keys stored in DB), or via the Yubico public auth servers<br />- Add a PIN to the OTP (stored in a local DB)<br />- Perform master/master replication between DBs, securely<br />- Customize your Yubikey<br />- Network security - protect the VPN servers against network-based attacks<br /><br />Log:<br />- uploaded v02, containing corrections, some parts of the text are made more clear, etc. Nothing of substance.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2986">FlorinAndrei</a> — Thu Sep 11, 2014 2:14 am</p><hr />
]]></content>
</entry>
</feed>