The OpenSSL versions included in the official OpenVPN Windows installers before 2.3.6-I002/I602 are vulnerable to FREAK. All users of the official OpenVPN Windows installers are strongly advised to upgrade their OpenVPN installations or take additional steps (see below) to counter the threat. OpenVPN users on UNIX systems usually receive an updated OpenSSL version through their package management system and do not need to update OpenVPN.
Thankfully, the vulnerability's impact on OpenVPN is relatively minor:
- If activated, OpenVPN's
tls-authfeature blocks this attack. - Adding
!EXPto the server-sidetls-cipheris sufficient to prevent attacks. The recommendedtls-cipherstring isDEFAULT:!EXP:!LOW:!PSK:!SRP:!kRSA. This configuration excludes export ciphers, weak ciphers (like DES), and RSA key exchange (note: not RSA authentication), while allowing any future, stronger cipher suites. - Clients who want to completely avoid this attack on clients before 2.3.6-I002/I603 can add
!kRSAto theirtls-cipherstring. - An attacker needs to be in a man-in-the-middle position.
- An attacker must invest time and money per OpenVPN instance (restart) to attack a connection, making this mainly relevant for targeted attacks.
- OpenVPN consistently offers PFS with its own key exchange mechanism, making it impossible to decrypt sessions before a successful factorization of the temporary export key, even if those connections previously used an RSA_EXPORT cipher.
