PDA

View Full Version : Does the Leopard VPN Client Encrypt the Login?




m i k e
Mar 6, 2009, 11:08 PM
I am going on vacation and will be connecting to my university's VPN in order to create a secure tunnel when using public WiFi. I just wanted to know, does the Mac OSX VPN client encrypt the actual login to the VPN? Also, in general is using the OSX VPN client as secure as using say, the Cisco client that my university makes available for download?



belvdr
Mar 6, 2009, 11:25 PM
What protocol will you be using?

In general for IPSec tunnels, the credentials are sent encrypted.

EDIT: Keep in mind PPTP is not IPSec, and is not a secure tunnel.

m i k e
Mar 6, 2009, 11:33 PM
Well I am using L2TP over IPSec. I heard from someone though, that whether or not the login credentials are encrypted depends on the VPN client. Does the OSX Leopard VPN client encrypt the login credentials? Also, if you know does the VPN client on the iPhone/iPod Touch encrypt the login credentials?

Thanks for your help.

belvdr
Mar 6, 2009, 11:36 PM
IPSec exchanges SAs then handles authentication after that, so you should be okay.

Your concern is one of the reason SecurID tokens are so nice and widely used.