Critical security flaw: Missing crl-verify openvpn option

Bug #1618286 reported by Nicholas Stommel
This bug report is a duplicate of:  Bug #1566032: crl-verify is not an option. Edit Remove
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
network-manager-openvpn (Ubuntu)
New
Undecided
Unassigned

Bug Description

Many VPN providers will give a Certificate Revocation List crl.pem file in their OpenVPN packages. The CRL list is becoming increasingly important after the Heartbleed bug was exposed, leaving many servers vulnerable to attack by unauthorized certificates. Is there any way to manually pass the option 'crl-verify crl.pem' to openvpn by editing a file somewhere?
I'm having a difficult time understanding how the network-manager-openvpn client actually works, and what arguments it can actually receive, given that it doesn't 'truly' import .ovpn configuration files. I also have little clue where the configurations are written in the file system as there are no manual pages and no debugging/terminal output for the network-manager-openvpn client. I can't even find the godforsaken binaries after installing the package. It would be much better if one could literally just pass it a .ovpn file, but seeing as that's not possible, I must request that the crl-verify option is added in the near future so that my system is not vulnerable to attacks using unauthorized certificates.

Tags: crl openvpn
information type: Private Security → Public Security
information type: Public Security → Public
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.