In the OpenVPN server settings (Advanced), there are 2 authentication settings. I'd like to clarify I understand them.
This is how I interpret it:
A username-password (U/P) pair can be used as a second factor, as well as certificates, to authenticate server to client and vice versa (U/P Auth ON; U/P Auth Only OFF). (I'm not sure if vice versa is true - auth of client to server - but that's a distraction.)
On the other hand, if U/P Auth Only is set to ON, no certificates are used, only the Username-password pair in what would then be single factor Auth. And if Username-password authentication is NOT selected, then ONLY certificates will be used, on their own, in single-factor authentication.
So the strongest authentication would be U/P Auth ON with U/P Auth Only OFF, that way certificates AND usernames-password pairs are needed.
Is my understanding correct?
This is how I interpret it:
A username-password (U/P) pair can be used as a second factor, as well as certificates, to authenticate server to client and vice versa (U/P Auth ON; U/P Auth Only OFF). (I'm not sure if vice versa is true - auth of client to server - but that's a distraction.)
On the other hand, if U/P Auth Only is set to ON, no certificates are used, only the Username-password pair in what would then be single factor Auth. And if Username-password authentication is NOT selected, then ONLY certificates will be used, on their own, in single-factor authentication.
So the strongest authentication would be U/P Auth ON with U/P Auth Only OFF, that way certificates AND usernames-password pairs are needed.
Is my understanding correct?
Last edited: