This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
networking:openvpn_howto [2014/10/13 17:15] ww |
networking:openvpn_howto [2022/03/16 09:39] (current) |
||
|---|---|---|---|
| Line 3: | Line 3: | ||
| ===== 1. Generování klíčů (Linux) ===== | ===== 1. Generování klíčů (Linux) ===== | ||
| - | ==== 1.1. Příprava ===== | + | ==== 1.1. PKI - příprava ===== |
| - | - Zkopírovat nástroje z adresáře '' | + | - Stáhnout Easy-RSA ([[https://github.com/OpenVPN/easy-rsa/releases|odkaz]]). |
| - | - Upravit | + | - Zkopírovat |
| + | - Volitelně eliptické křivky: | ||
| + | - '' | ||
| + | - '' | ||
| - | # . ./vars | + | # ./easyrsa init-pki |
| - | # ./clean-all | + | # ./easyrsa build-ca nopass |
| - | # ./build-ca | + | # ./easyrsa build-server-full < |
| + | # ./easyrsa | ||
| + | # ./easyrsa gen-dh | ||
| - | ==== 1.2. Klíč serveru | + | ==== 1.2. PKI - umístění souborů |
| - | | + | |
| + | - '' | ||
| + | - '' | ||
| + | | ||
| + | - '' | ||
| + | - klient: | ||
| + | - '' | ||
| + | - '' | ||
| + | | ||
| - | ==== 1.3. Klíče klientů | + | ==== 1.3. TLS auth ==== |
| - | | + | |
| - | # ./build-key client2 | + | |
| - | # ... | + | |
| - | + | ||
| - | Přidání dalších klientů | + | |
| - | | + | ===== 2. Nastavení serveru (Linux) ===== |
| - | # . ./vars | + | |
| - | # ./build-key newclient | + | server 172.17.255.0 255.255.255.0 |
| + | port 1194 | ||
| + | proto udp | ||
| + | |||
| + | topology subnet | ||
| + | |||
| + | dev tun | ||
| + | |||
| + | user nobody | ||
| + | group nogroup | ||
| + | |||
| + | persist-key | ||
| + | persist-tun | ||
| + | |||
| + | remote-cert-tls client | ||
| + | cipher AES-256-GCM | ||
| + | |||
| + | | ||
| + | #push "route 192.168.X.0 255.255.255.0 172.17.Y.Z" | ||
| + | | ||
| + | # ifconfig-pool-persist ipp.txt | ||
| + | |||
| + | keepalive 10 120 | ||
| + | |||
| + | log /var/ | ||
| + | verb 3 | ||
| + | mute 10 | ||
| + | |||
| + | ca | ||
| + | cert | ||
| + | key [inline] | ||
| + | dh | ||
| + | tls-auth [inline] | ||
| + | | ||
| + | |||
| + | < | ||
| + | -----BEGIN CERTIFICATE----- | ||
| + | ... | ||
| + | -----END CERTIFICATE----- | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | -----BEGIN PRIVATE KEY----- | ||
| + | ... | ||
| + | -----END PRIVATE KEY----- | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | -----BEGIN CERTIFICATE----- | ||
| + | ... | ||
| + | -----END CERTIFICATE----- | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | -----BEGIN DH PARAMETERS----- | ||
| + | ... | ||
| + | -----END DH PARAMETERS----- | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | -----BEGIN OpenVPN Static key V1----- | ||
| + | ... | ||
| + | -----END OpenVPN Static key V1----- | ||
| + | </ | ||
| | | ||
| - | ==== 1.4. Diffie-Hellman ==== | ||
| - | # ./build-dh | ||
| - | ==== 1.5. Umístění souborů ==== | + | ===== 3. Nastavení klientů (Windows) ===== |
| - | - ca.crt -> všem (CA - certifikát) | + | |
| - | - ca.key -> server (CA - privátní klíč) | + | |
| - | - dh{n}.pem -> server | + | |
| - | - server.crt, server.key -> server (certifikát, | + | |
| - | - clientX.crt, | + | |
| - | ===== 2. Nastavení serveru (Linux) ===== | + | client |
| + | |||
| + | dev tun | ||
| + | dev-node tap0 <-- název síťového připojení musí být " | ||
| + | |||
| + | < | ||
| + | remote < | ||
| + | </ | ||
| + | nobind | ||
| + | |||
| + | resolv-retry infinite | ||
| + | persist-key | ||
| + | persist-tun | ||
| + | auth-nocache | ||
| + | |||
| + | remote-cert-tls server | ||
| + | cipher AES-256-GCM | ||
| + | |||
| + | log "..\\log\\< | ||
| + | verb 3 | ||
| + | mute 10 | ||
| + | |||
| + | ca | ||
| + | cert | ||
| + | key [inline] | ||
| + | tls-auth [inline] | ||
| + | key-direction 1 | ||
| + | |||
| + | < | ||
| + | -----BEGIN CERTIFICATE----- | ||
| + | ... | ||
| + | -----END CERTIFICATE----- | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | -----BEGIN PRIVATE KEY----- | ||
| + | ... | ||
| + | -----END PRIVATE KEY----- | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | -----BEGIN CERTIFICATE----- | ||
| + | ... | ||
| + | -----END CERTIFICATE----- | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | -----BEGIN OpenVPN Static key V1----- | ||
| + | ... | ||
| + | -----END OpenVPN Static key V1----- | ||
| + | </ | ||
| + | ===== 4. Výpis zneplatněných certifikátů ===== | ||
| + | grep " | ||
| + | ===== 5. Zneplatnění certifikátu ===== | ||
| + | ./easyrsa revoke < | ||
| + | EASYRSA_CRL_DAYS=3650 ./easyrsa gen-crl | ||
| - | # port 1194 | + | + přidat do konfiguráku serveru: |
| - | | + | |
| - | # dev tun | + | |
| - | # | + | |
| - | # ca / | + | |
| - | # cert / | + | |
| - | # key / | + | |
| - | # dh / | + | |
| - | # | + | |
| - | # server 10.0.1.0 255.255.255.0 | + | |
| - | # ifconfig-pool-persist ipp.txt | + | |
| - | # client-to-client | + | |
| - | # keepalive 10 120 | + | |
| - | # comp-lzo | + | |
| - | # persist-key | + | |
| - | # persist-tun | + | |
| - | # status openvpn-status.log | + | |
| - | # verb 3 | + | |
| - | + | ||
| - | ===== 3. Nastavení klientů (Windows) ===== | + | |
| - | # client | + | Po zneplatnění je potřeba restartovat OpenVPN |
| - | # | + | |
| - | # dev tun | + | |
| - | # dev-node tap0 <-- název síťového připojení musí být " | + | |
| - | # proto udp | + | |
| - | # | + | |
| - | # remote {server-hostname} 1194 | + | |
| - | # | + | |
| - | # resolv-retry infinite | + | |
| - | # nobind | + | |
| - | # persist-key | + | |
| - | # persist-tun | + | |
| - | # | + | |
| - | # ca "C:\\Program Files\\OpenVPN\\keys\\{název-vpn}\\ca.crt" | + | |
| - | | + | |
| - | # key " | + | |
| - | # | + | |
| - | # ns-cert-type server | + | |
| - | # comp-lzo | + | |
| - | # verb 3 | + | |
| - | # | + | |
| - | # log " | + | |