{"id":1703,"date":"2020-02-17T11:14:42","date_gmt":"2020-02-17T10:14:42","guid":{"rendered":"http:\/\/clark.tipistrani.it\/?p=1703"},"modified":"2020-02-17T11:14:42","modified_gmt":"2020-02-17T10:14:42","slug":"accesso-a-samba-tramite-openvpn-su-ipad-2-2-2","status":"publish","type":"post","link":"http:\/\/clark.tipistrani.it\/?p=1703","title":{"rendered":"Configurazione  OpenVPN su Android 7.0 con tls-auth"},"content":{"rendered":"<p>Avendo cambiato il server Openvpn, rigenerato chiavi e certificati e aggiunto l&#8217;auth -tls ho dovuto riscrivere anche i client per android che come la volta precedente sono con estensione .ovpn<\/p>\n<p>Si tratta ora di creare il file .ovpn che contiene come per apple\u00a0 sia le istruzioni relative alla connessione al server Openvpn che i certificati ca.crt, android01.crt e androi01.key\u00a0 racchiusi tra tag in questo modo:<\/p>\n<p>client<br \/>\ndev tun<br \/>\nproto tcp<br \/>\nremote xxx.xxx.xxx.xxx 775<br \/>\nremote yyy.yyy.yyy.yyy 775<\/p>\n<p>resolv-retry infinite<br \/>\nnobind<br \/>\npersist-key<br \/>\npersist-tun<br \/>\nmute-replay-warnings<br \/>\nremote-cert-tls server<br \/>\ncipher AES-256-CBC<br \/>\nauth SHA256<br \/>\ncompress lz4-v2<br \/>\nverb 3<br \/>\nkey-direction 1<br \/>\n&lt;ca&gt;<br \/>\n&#8212;&#8211;BEGIN CERTIFICATE&#8212;&#8211;<br \/>\nMIIDVTCCAr6gAwIBAgIJAJIIm5Kj+g2yMA0GCSqGSIb3DQEBBQUAMHsxCzAJBgNV<br \/>\nBAYTAklUMQswCQYDVQQIEwJNSTEOMAwGA1UEBxMFTWlsYW4xEzARBgNVBAoTClpp<br \/>\nbmNvbWV0YWwxFjAUBgNVBAMTDVppbmNvbWV0YWwgQ0ExIjAgBgkqhkiG9w0BCQEW<br \/>\nE3N1cHBvcnRAZHluYW1pY2EuaXQwHhcNMTAwNDAyMTIxMTM1WhcNMjAwMzMwMTIx<br \/>\nMTM1WjB7MQswCQYDVQQGEwJJVDELMAkGA1UECBMCTUkxDjAMBgNVBAcTBU1pbGFu<br \/>\nMRMwEQYDVQQKEwpaaW5jb21ldGFsMRYwFAYDVQQDEw1aaW5jb21ldGFsIENBMSIw<br \/>\nIAYJKoZIhvcNAQkBFhNzdXBwb3J0QGR5bmFtaWNhLml0MIGfMA0GCSqGSIb3DQEB<br \/>\nAQUAA4GNADCBiQKBgQCyVVR5XjbvF9KZpzc4OuqJkiI25+kdf8cgllS1+GHcorhQ<br \/>\n&#8212;&#8211;END CERTIFICATE&#8212;&#8211;<br \/>\n&lt;\/ca&gt;<br \/>\n&lt;cert&gt;<br \/>\n&#8212;&#8211;BEGIN CERTIFICATE&#8212;&#8211;<br \/>\nMIIDtTCCAx6gAwIBAgIBFDANBgkqhkiG9w0BAQUFADB7MQswCQYDVQQGEwJJVDEL<br \/>\nMAkGA1UECBMCTUkxDjAMBgNVBAcTBU1pbGFuMRMwEQYDVQQKEwpaaW5jb21ldGFs<br \/>\nMRYwFAYDVQQDEw1aaW5jb21ldGFsIENBMSIwIAYJKoZIhvcNAQkBFhNzdXBwb3J0<br \/>\nQGR5bmFtaWNhLml0MB4XDTE1MDkyNDA2NTc0NloXDTI1MDkyMTA2NTc0NlowgZIx<br \/>\nCzAJBgNVBAYTAklUMQswCQYDVQQIEwJNSTEOMAwGA1UEBxMFTWlsYW4xEzARBgNV<br \/>\nBAoTClppbmNvbWV0YWwxHDAaBgNVBAsUE1N5c3RlbSAmIE5ldHdvcmtpbmcxDzAN<br \/>\nBgNVBAMTBmlwYWQwMTEiMCAGCSqGSIb3DQEJARYTc3VwcG9ydEBkeW5hbWljYS5p<br \/>\ncUQRn5xIhO4sraeLfRvUZgBOVkLlZOX3qj7jsx0FhJ\/R7LEJw09wJjE=<br \/>\n&#8212;&#8211;END CERTIFICATE&#8212;&#8211;<br \/>\n&lt;\/cert&gt;<br \/>\n&lt;key&gt;<br \/>\n&#8212;&#8211;BEGIN PRIVATE KEY&#8212;&#8211;<br \/>\nMIICeAIBADANBgkqhkiG9w0BAQEFAASCAmIwggJeAgEAAoGBANqSCOiPCxxsqS9U<br \/>\nytCHBuXwtNb34zpyH\/biM8zrLZml9jiLmaFiQVN\/0H5mcar4X0ii5\/gXbU8nLFlv<br \/>\nsjvldBhwz7QlBrQoimg6SOgqWSiq1owMHkXSCqI7ZmtyEXgh7taGbS0SzUyeBOsZ<br \/>\nDhQbOUJCzFbTq\/1ywYUHu9fj\/8oNAgMBAAECgYEAghxuyynj3l7c8\/0Q4sOOmrEI<br \/>\n&#8212;&#8211;END PRIVATE KEY&#8212;&#8211;<br \/>\n&lt;\/key&gt;<\/p>\n<p>&lt;tls-auth&gt;<br \/>\n&#8212;&#8211;BEGIN OpenVPN Static key V1&#8212;&#8211;<br \/>\n9fb1d5631195e587cdafc1e6c9133053<br \/>\n7aa9dafd570eaff6adf2f47a03c40755<br \/>\nd8601e321224968e24633a422d08b07e<br \/>\nd6c163f998fd0593cb5f060abc03d4a9<br \/>\nbf8f812d76423d7ba35655349d4da461<br \/>\n4d4dc6a82f886e69436ec650afca5e81<br \/>\nef731864613c231af03f4c0fd86fe3ba<br \/>\n14e155dd866eb440879dc8b62e959f5c<br \/>\n7649ac21828513ea63c08dbbe73a3542<br \/>\n769dd5c81787a19511d181595b607265<br \/>\n48a5782ae2860b5df19c0bf1a7c21119<br \/>\n6192561a16cb1778d1911f949d73a467<br \/>\na41c9f2ede078ea859d896d47552a094<br \/>\nbe52f94bb26c30d0469db1a88a8c7753<br \/>\n0e305c79d5f9f277006d3d6000fac1d1<br \/>\n&#8212;&#8211;END OpenVPN Static key V1&#8212;&#8211;<br \/>\n&lt;\/tls-auth&gt;<\/p>\n<p>e sul server nella directory ccd creo il file android01 che contiene:<\/p>\n<p>ifconfig-push 172.27.1.50 172.27.1.51<br \/>\npush &#8220;route 192.168.2.0 255.255.255.0&#8221;<br \/>\npush &#8220;dhcp-option DOMAIN myfirm.local&#8221;<br \/>\npush &#8220;dhcp-option DNS 192.168.2.224&#8221;<br \/>\npush &#8220;dhcp-option DNS 192.168.3.227&#8221;<\/p>\n<p>&nbsp;<\/p>\n<p>Un restart al server OpenVPN per fargli digerire le modifiche e di nuovo spediamo usando la mail spediamo il file android01.ovpn al tablet una volta arrivata la mail si scarica l&#8217;allegato si apre\u00a0 OpenVPN Connect e si sceglie OVPN Profile per importarlo, una volta fatto si fa scorrere il tastino che appare e dopo pochi secondi si e&#8217; bellamente connessi.<\/p>\n<div id=\"link64_adl_tabid\" style=\"display: none;\" data-url=\"http:\/\/clark.tipistrani.it\/wp-admin\/post-new.php\">Mi 31<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Avendo cambiato il server Openvpn, rigenerato chiavi e certificati e aggiunto l&#8217;auth -tls ho dovuto riscrivere anche i client per android che come la volta precedente sono con estensione .ovpn Si tratta ora di creare il file .ovpn che contiene come per apple\u00a0 sia le istruzioni relative alla connessione al server Openvpn che i certificati [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,14,6],"tags":[125,78,62,126],"class_list":["post-1703","post","type-post","status-publish","format-standard","hentry","category-linux","category-networking","category-work","tag-android","tag-openvpn","tag-tcp","tag-tun"],"_links":{"self":[{"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/posts\/1703","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1703"}],"version-history":[{"count":1,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/posts\/1703\/revisions"}],"predecessor-version":[{"id":1704,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/posts\/1703\/revisions\/1704"}],"wp:attachment":[{"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1703"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1703"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1703"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}