Task
TA.KEY in OpenVPN
Good day i have a working OpenVPN in ClearOS, my task now is how can put or apply TA.KEY i dont know how to start on this thanks for the helps
In VPN
Share this post:
Accepted Answer
Google is your friend. Try https://openvpn.net/community-resources/hardening-openvpn-security/. I would see if I can put the key in /etc/openvpn/ssl/ The configuration foes in /etc/clients.conf, but if you put the key into /etc/openvpn/ssl/, you'd need to specify a path to it in clients.conf.
You will have a problem distributing it, but that is up to you. Currently the user can download the .ovpn config file and all their certs from the webconfig. There is no current mechanism for them to download a ta.key or to embed it into the ovpn file so each ovpn file will have to be manually edited and the key manually distributed.
You will have a problem distributing it, but that is up to you. Currently the user can download the .ovpn config file and all their certs from the webconfig. There is no current mechanism for them to download a ta.key or to embed it into the ovpn file so each ovpn file will have to be manually edited and the key manually distributed.
Responses (1)
-
Accepted Answer
Nick Howitt wrote:
Google is your friend. Try https://openvpn.net/community-resources/hardening-openvpn-security/. I would see if I can put the key in /etc/openvpn/ssl/ The configuration foes in /etc/clients.conf, but if you put the key into /etc/openvpn/ssl/, you'd need to specify a path to it in clients.conf.
You will have a problem distributing it, but that is up to you. Currently the user can download the .ovpn config file and all their certs from the webconfig. There is no current mechanism for them to download a ta.key or to embed it into the ovpn file so each ovpn file will have to be manually edited and the key manually distributed.
Thank you sir Nick

Please login to post a reply
You will need to be logged in to be able to post a reply. Login using the form on the right or register an account if you are new here.
Register Here »