Blame

c4f02d Samuli Seppänen 2025-01-29 08:37:37 1
# OpenVPN Cryptographic Layer
2
3
This document provides a technical overview of the cryptographic layer of OpenVPN, assuming a prior understanding of modern cryptographic concepts. For more details on security aspects related to OpenVPN, refer to [this FAQ item](wiki/295-are-there-any-known-security-vulnerabilities-with-openvpn).
4
5
## Authentication Modes in OpenVPN
6
7
OpenVPN supports two modes of authentication:
8
- **Static Key**: Utilizes a pre-shared static key.
9
- **TLS**: Employs SSL/TLS along with certificates for authentication and key exchange.
10
11
### Static Key Mode
12
In this mode, a pre-shared key is created and distributed between the OpenVPN peers before establishing the tunnel. The static key comprises four independent keys:
13
- HMAC send
14
- HMAC receive
15
- Encrypt
16
- Decrypt
17
18
By default, the same HMAC key and encryption/decryption key are used by both hosts in static key mode. However, the `--secret` directive with the direction parameter allows utilizing all four keys independently.
19
20
### TLS Mode
21
An SSL session with bidirectional authentication is initiated, requiring each connection side to present a valid certificate. Upon successful SSL/TLS authentication, key materials for encryption/decryption and HMAC are randomly generated using OpenSSL's `RAND_bytes` function and exchanged over the SSL/TLS connection. Each connection side contributes random material, ensuring unique keys for send HMAC, receive HMAC, packet encryption, and packet decryption. Depending on the `--key-method` used (1 or 2), keys are derived either directly from the `RAND_bytes` function or using the TLS PRF function. Starting from OpenVPN 1.5.0, `--key-method 2` is available and will become the default in OpenVPN 2.0.
22
23
SSL/TLS rekeying includes a `transition-window` parameter allowing key overlap during renegotiations, avoiding latency issues.
24
25
To operate over a reliable transport, OpenVPN adds a reliable transport layer atop UDP, as shown in the diagram below.
26
27
### Tunnel Operation
28
Once each peer has its keys, tunnel forwarding begins. The packet structure is as follows:
29
30
```
31
HMAC(explicit IV, encrypted envelope)
32
Explicit IV
33
Encrypted Envelope
34
```
35
36
The plaintext inside the encrypted envelope is structured as:
37
38
```
39
64-bit sequence number
40
Payload data (e.g., IP packet or Ethernet frame)
41
```
42
43
The HMAC and explicit IV are not included within the encrypted envelope.
44
45
The per-packet IV is randomized using a nonce-based PRNG, initially seeded by the OpenSSL `RAND_bytes` function.
46
47
OpenSSL's EVP interface provides HMAC, encryption, and decryption functions, allowing selection of any cipher, key size, and HMAC digest. BlowFish and SHA1 are the default cipher and message digest, respectively. The EVP interface also handles PKCS#5 padding.
48
49
An important security feature in OpenVPN is the `--tls-auth` directive, which uses a pre-shared passphrase or static key to generate an HMAC key for authenticating packets in the TLS handshake sequence, enhancing protection against buffer overflows in OpenSSL's TLS implementation.
50
51
OpenVPN multiplexes the SSL/TLS session for authentication and key exchange with the encrypted tunnel data stream, ensuring SSL/TLS sees a reliable transport layer, while the IP packet forwarder sees an unreliable one. This independence between the reliability and authentication layers is crucial for efficient and secure data transmission.
52
53
## OpenVPN Protocol
54
55
The OpenVPN protocol defines a series of packet types and operations essential for establishing and maintaining a secure VPN tunnel. This includes various message types like `P_CONTROL`, `P_ACK`, and `P_DATA`, each serving specific roles in the communication process. The protocol ensures data integrity, replay protection, and seamless transition during key renegotiations, leveraging HMAC signatures and TLS sessions authenticated and initialized as described.
56
57
[Protocol details and packet formats are extensively documented in the source code, specifically in `ssl.h` within the OpenVPN repository.]