Okay, I'm replying to myself with another request for help. It looks like, if I'm reading the source correctly, you can't use any SSL features over a unix domain socket. Perhaps this should be documented in README_SSL?
Further the force public key auth option appears to have no effect. I'm basing this on the fact that a test user, with no cert, was able to login fine without a password. This shold also be fix/documented. Finally, as far as I can tell there is no way to use public key authentication. Is this correct? or is there some trick which I haven't found in the list archives or README_SSL? This is only an issuse because I'm going to be running automated scans, and I don't want to expose the password on the command line. Is there some way to set the user password in the config file at least? thanks, On Wed, Mar 13, 2002 at 03:30:40PM -0800, Devin Kowatch wrote: > Hi, > I'm trying to setup public key authentication for a user, but can't seem > to make the client try anything other than password authentication. > > I ran nessus-mkcert-client and nessus-adduser. everything seems to be > in order there. My .nessusrc file is: > > # Nessus Client Preferences File > > trusted_ca = /scratch/slocal/com/nessus/CA/cacert.pem > cert_file = /users/u3/devink/.nessus/cert_devink.pem > key_file = /users/u3/devink/.nessus/key_devink.pem > > and 'nessus -v': > nessus (Nessus) 1.1.14 for Linux > > (C) 1998, 1999, 2000 Renaud Deraison <[EMAIL PROTECTED]> > client - server communication is done in PLAIN TEXT > > > Which brings up my next question, does the last line mean that OpenSSL > was not activated? Looking at the make logs, it seems like it found it > and linked it in ok. The only special option I used in building it was > to enable the unix-domain socket (and disable TCP connections) for > nessusd. > > Any ideas? > > Thanks, > -- > Devin Kowatch > [EMAIL PROTECTED] -- Devin Kowatch [EMAIL PROTECTED]
