Setting up a OpenVPN server: Difference between revisions

From Alpine Linux
m (Reverted edits by 80.227.1.100 (Talk); changed back to last version by WikiSysop)
(→‎Setup Alpine: changed a link)
Line 5: Line 5:
= Setup Alpine =
= Setup Alpine =
== Initial Setup ==
== Initial Setup ==
Follow [http://www.alpinelinux.org/mediawiki/index.php/Installing_Alpine instructions] on how to setup Alpine
Follow [http://wiki.alpinelinux.org/w/index.php?title=Installing_Alpine] on how to setup Alpine


== Install programs ==
== Install programs ==
Line 13: Line 13:
(''The number is the start-order. Choose between 1-99'')
(''The number is the start-order. Choose between 1-99'')
  rc_add -vks 95 openvpn
  rc_add -vks 95 openvpn


= Configure OpenVPN-server =
= Configure OpenVPN-server =

Revision as of 15:36, 30 December 2008

This article will describe how to set up a OpenVPN server with the Alpine distro.

Documentation based on alpine-1.6

Setup Alpine

Initial Setup

Follow [1] on how to setup Alpine

Install programs

Install openvpn

apk_add openvpn

Prepare autostart of OpenVPN
(The number is the start-order. Choose between 1-99)

rc_add -vks 95 openvpn

Configure OpenVPN-server

(Instructions is based on openvpn.net/howto.html#server)

Test your configuration

Test configuration and certificates

 openvpn --config /etc/openvpn/openvpn.conf


Configure OpenVPN-client

(Instructions is based on openvpn.net/howto.html#client)


Manage Certificates

(Instructions is based on openvpn.net/howto.html#pki)

Initial setup for administrating certificates

The following instructions assume that you want to save your configs, certcs and keys in /etc/openvpn/keys.
Start by moving to the /usr/share/openvpn/easy-rsa folder to execute commands

cd /usr/share/openvpn/easy-rsa

If not already done then create a folder where you will save your certificates and
save a copy of your /usr/share/openvpn/easy-rsa/vars for later use.
(All files in /usr/share/openvpn/easy-rsa is overwritten when the computer is restarted)

mkdir /etc/openvpn/keys
cp ./vars /etc/openvpn/keys

If not already done then edit /etc/openvpn/keys/vars
(This file is used for defining paths and other standard settings)

vim /etc/openvpn/keys/vars
* Change KEY_DIR= from "$EASY_RSA/keys" to "/etc/openvpn/keys"
* Change KEY_SIZE, CA_EXPIRE, KEY_EXPIRE, KEY_COUNTRY, KEY_PROVINCE, KEY_CITY, KEY_ORG, KEY_EMAIL to match your system.

source the vars to set properties

source /etc/openvpn/keys/vars

Set up a 'Certificate Authority' (CA)

Clean up the keys folder.

./clean-all

Generate Diffie Hellman parameters

./build-dh

Now lets make the CA certificates and keys

./build-ca

Set up a 'OpenVPN Server'

Create server certificates

./build-key-server {commonname}

Set up a 'OpenVPN Client'

Create client certificates

./build-key {commonname}

Revoke a certificate

To revoke a certificate...

./revoke-full {commonname}

The revoke-full script will generate a CRL (certificate revocation list) file called crl.pem in the keys subdirectory.
The file should be copied to a directory where the OpenVPN server can access it, then CRL verification should be enabled in the server configuration:
crl-verify crl.pem


Save settings

Don't forget to save all your settings

lbu ci floppy