Can static.key be seen if the cipher is cracked?

This forum is for admins who are looking to build or expand their OpenVPN setup.

Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech

Forum rules
Please use the [oconf] BB tag for openvpn Configurations. See viewtopic.php?f=30&t=21589 for an example.
Post Reply
Kolusion
OpenVPN User
Posts: 20
Joined: Tue Sep 05, 2023 9:18 am

Can static.key be seen if the cipher is cracked?

Post by Kolusion » Thu Sep 07, 2023 1:39 pm

So I setup OpenVPN for the first time using the Static Key Mini-HOWTO which uses the default cipher BF-CBC. On startup, I was warned the cipher is vulnerable to the SWEET32 attack. I have since changed the cipher to AES-256-CBC, but I am wondering if I need change my static.key to be safe.

My understanding is there is a separate process for authentication which doesn't use static.key, and instead uses something else which involves SHA or whatever, so I shouldn't have to change my static.key.

Can static.key be seen if the cipher is cracked?

Post Reply