14.1.2.7 OpenVPN Client (ovpnc)
266
Wrapper protocol
OpenVPN can either wrap the actual data in UDP or in TCP packets. Please select the
protocol used by the server.
Port
Here you have to enter the server's port number.
Additional constaints for server certificate
An additional verification of the server certificate's data should be performed in order
to protect SX-GATE from man-in-the-middle attacks.
certificate type "server"
If this option is selected, the connection will be established only if the server
presents a certificate which contains an nsCertType attribute with a value of
"server".
Certificates issued by SX-GATE's CA don't contain this
attribute, so don't choose this option if the server uses such
a certificate.
certificate usage "server"
If this option is selected, the connection will be established only if the server
presents a certificate which contains a keyUsage attribute with a value of
"digitalSignature" plus either "keyEncipherment" or "keyAgreement". In addition
an extendedKeyUsage attribute with the value "TLS Web Server Authentication"
must be present.
Certificates issued by SX-GATE's CA don't contain these
attributes, so don't choose this option if the server uses
such a certificate.
Certificate ID
Enter the certificate data (subject) of the server certificate. Connecting will only
be possible if the server certificate contains the same data. It is also possible to
enter only the common name (CN).
LZO compression
If the server uses the "comp-lzo" option, it must be enabled on the client, too.