[plug] VOIP suggestions please

Steve Baker steve at iinet.net.au
Sun Apr 9 14:24:08 WST 2006


Brad Campbell wrote:

> W.Kenworthy wrote:
>
>> its generating and redoing the keys in a more logical and supportable
>> manner that is bugging me!  Hopefully, this will be a once only - well
>> until they expire!
>
> I gotta admit the key administration is a headache..
> I just used the latest scripts delivered with openvpn and they kinda 
> managed what I needed, but it will be a pain when I start going 
> multi-server distributed across the place.. I'm going to have to do 
> some serious testing/planning before I try and deploy that.

Why don't you use X.509 certificates instead?  I'm using them with Open 
S/WAN and it is extremely simple to set up.  It was a minor hassle to 
get the certs created in the first place, but once they are created it 
is very simple to use them and really easy to add new nodes to the VPN.

sb



More information about the plug mailing list