Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 27 Sep 2000 20:07:52 +1100
From:      Sam wun <swun@eSec.com.au>
Cc:        "'freebsd-security@freebsd.org'" <freebsd-security@FreeBSD.ORG>
Subject:   What happened if the pre-share key got cacked?
Message-ID:  <39D1B8E8.B5B070FB@eSec.com.au>
References:  <00BF97DD9F3FD311AB860060084E50DD311C71@exchange.xpert.com> <20000925143807.A401@hal9000.bsdonline.org>

next in thread | previous in thread | raw e-mail | index | archive | help
I am a bit concernt about hte pre-share key that using by the IPsec couple of
client and the server machines.
What if this key got stolent somehow? what will be the consequence?
I am using IPSec in FreeBSD. The pre-share key is used by racoon. The psk.txt
is protected by 600 permission. But what if my root account got cracked?
anyone whom posesses my root account will be able to see the content of the
psk.txt file?

It may not be that importnat if the psk.txt got hacked, the hacker still hard
to penetrade in to another machine which also got IPsec setup. Because all
data transfer is protected by IPsec., thus tcpdump will fail. Am I right?

Thanks
Sam.



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?39D1B8E8.B5B070FB>