{"id":2491,"date":"2023-12-22T09:36:09","date_gmt":"2023-12-22T08:36:09","guid":{"rendered":"http:\/\/clark.tipistrani.it\/?p=2491"},"modified":"2024-07-10T11:04:20","modified_gmt":"2024-07-10T09:04:20","slug":"openvpn-su-devuan-daedalus","status":"publish","type":"post","link":"http:\/\/clark.tipistrani.it\/?p=2491","title":{"rendered":"Openvpn su Devuan Daedalus"},"content":{"rendered":"<p>Dopo 3 anni dall&#8217;ultima volta mi sono trovato a dover configurare un altra VPN da affiancare a quella aziendale per poter accedere al mio PC da remoto e quindi da li con <a href=\"https:\/\/www.dell.com\/it-it\/dt\/solutions\/openmanage\/idrac.htm#scroll=off\">IDRAC<\/a> che secondo me \u00e8 l&#8217;invenzione del secolo per chi fa il mio lavoro, poter riaccendere la LAN da casa durante un giorno di festa poich\u00e9 la manutenzione aveva dovuto togliere tensione.<\/p>\n<p>Su Devuan 5 la versione di Openvpn \u00e8 la 2.6.3 e sono cambiate un bel po di cose rispetto alle versioni precedenti tant&#8217;\u00e8 che partito a razzo con i soliti comandi mi son visto restituire un bel root@pc0:\/etc\/openvpn# . .\/vars<br \/>\nbash: .\/vars: File o directory non esistente.<br \/>\nQuindi al solito una rapida ricerca in Internet e ho trovato il procedimento per configurare openvpn su debian 12 che \u00e8 la mamma di daedalus, e che riporto qui adattato alle mie esigenze.<br \/>\nfatto il solito simlynk a \/usr\/share\/easy-rsa\/ in \/etc\/openvpn<br \/>\ned entrato in esso<\/p>\n<p>root@pc0:\/etc\/openvpn\/easy-rsa# .\/easyrsa init-pki<br \/>\n* Notice:<\/p>\n<p>init-pki complete; you may now create a CA or requests.<\/p>\n<p>Your newly created PKI dir is:<br \/>\n* \/etc\/openvpn\/easy-rsa\/pki<\/p>\n<p>inizializza pki<\/p>\n<p>root@pc0:\/etc\/openvpn\/easy-rsa# cd pki<\/p>\n<p>root@pc0:\/etc\/openvpn\/easy-rsa\/pki#cp vars.example vars quindi editare e cambiare<\/p>\n<p>set_var EASYRSA_REQ_COUNTRY &#8220;IT&#8221;<br \/>\nset_var EASYRSA_REQ_PROVINCE &#8220;Lombardia&#8221;<br \/>\nset_var EASYRSA_REQ_CITY &#8220;Inveruno&#8221;<br \/>\nset_var EASYRSA_REQ_ORG &#8220;Myfirm S.p.A.&#8221;<br \/>\nset_var EASYRSA_REQ_EMAIL &#8220;clark@myfirm.com&#8221;<br \/>\nset_var EASYRSA_REQ_OU &#8220;Systems and Networking&#8221;<\/p>\n<p>&nbsp;<\/p>\n<p>aggiustamento dei parametri<\/p>\n<p>&nbsp;<\/p>\n<p>root@pc0:\/etc\/openvpn\/easy-rsa\/pki# cd ..<\/p>\n<p>root@pc0:\/etc\/openvpn\/easy-rsa#.\/easyrsa build-ca<br \/>\n* WARNING:<\/p>\n<p>Unsupported \u00a0characters are present in the vars file.<br \/>\nThese characters are not supported: (&#8216;) (&amp;) (`) ($) (#)<br \/>\nSourcing the vars file and building certificates will probably fail ..<\/p>\n<p>* Notice:<br \/>\nUsing Easy-RSA configuration from: \/etc\/openvpn\/easy-rsa\/pki\/vars<\/p>\n<p>* Notice:<br \/>\nUsing SSL: openssl OpenSSL 3.0.11 19 Sep 2023 (Library: OpenSSL 3.0.11 19 Sep 2023)<\/p>\n<p>Enter New CA Key Passphrase:<br \/>\nRe-Enter New CA Key Passphrase:<br \/>\nUsing configuration from \/etc\/openvpn\/easy-rsa\/pki\/967c26e0\/temp.34b5ff81<br \/>\n&#8230;&#8230;.+&#8230;&#8230;.+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*&#8230;&#8230;+&#8230;..+.+..+&#8230;+.+&#8230;+&#8230;..+.+&#8230;..+.+&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;.+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*&#8230;+..+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+.+&#8230;+..+&#8230;&#8230;&#8230;+&#8230;+&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;..<br \/>\n+.+&#8230;+&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;+&#8230;+..+&#8230;+&#8230;.+..+.+&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;&#8230;&#8230;&#8230;.+..+.+&#8230;&#8230;+&#8230;..+&#8230;+&#8230;&#8230;.+&#8230;+&#8230;..+.+&#8230;&#8230;&#8230;&#8230;..+.+&#8230;..+.+&#8230;..+.+..+&#8230;+&#8230;&#8230;.+&#8230;..+&#8230;&#8230;.+&#8230;&#8230;+&#8230;+&#8230;&#8230;&#8230;&#8230;..+&#8230;+&#8230;&#8230;.+..+&#8230;&#8230;&#8230;+&#8230;.+&#8230;..+&#8230;&#8230;&#8230;.+&#8230;&#8230;+&#8230;..+.+&#8230;..+&#8230;.+++++++++++<br \/>\n++++++++++++++++++++++++++++++++++++++++++++++++++++++<br \/>\n..+&#8230;.+&#8230;..+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*..+&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;..+&#8230;+.+&#8230;&#8230;&#8230;..+.+&#8230;+..+&#8230;&#8230;&#8230;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*&#8230;&#8230;+&#8230;+&#8230;&#8230;&#8230;+.+&#8230;&#8230;&#8230;&#8230;+..+&#8230;&#8230;.+&#8230;+..+&#8230;&#8230;&#8230;&#8230;.+&#8230;+&#8230;..+&#8230;+&#8230;..<br \/>\n&#8230;..+&#8230;&#8230;&#8230;+..+&#8230;.+&#8230;..+&#8230;&#8230;.+..+&#8230;&#8230;&#8230;.+..+.+..+&#8230;&#8230;&#8230;&#8230;+.+&#8230;..+&#8230;&#8230;&#8230;.+..+&#8230;&#8230;&#8230;.+..+.+&#8230;..+&#8230;&#8230;&#8230;&#8230;+.+&#8230;&#8230;&#8230;+&#8230;..+.+&#8230;..+&#8230;&#8230;.+..+&#8230;+&#8230;&#8230;&#8230;.+..+&#8230;&#8230;.+&#8230;..+.+&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..+.+&#8230;+&#8230;+&#8230;..+&#8230;+&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;&#8230;&#8230;+..+&#8230;&#8230;&#8230;&#8230;+&#8230;+<br \/>\n&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;.+&#8230;..+&#8230;.+&#8230;..+.+&#8230;+..+&#8230;+&#8230;+&#8230;.+&#8230;+&#8230;&#8230;..+&#8230;+&#8230;&#8230;&#8230;+&#8230;+&#8230;&#8230;&#8230;&#8230;+&#8230;+&#8230;&#8230;.+&#8230;+&#8230;..+&#8230;.+&#8230;..+.+&#8230;+&#8230;..+&#8230;&#8230;.+..+.+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;.+..+&#8230;+&#8230;&#8230;&#8230;.+..+&#8230;+.+..+&#8230;+&#8230;.+&#8230;&#8230;+..+&#8230;+&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;+&#8230;<br \/>\n&#8230;..+&#8230;&#8230;.+&#8230;+&#8230;&#8230;+&#8230;&#8230;&#8230;..+&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;+&#8230;..+&#8230;.+&#8230;&#8230;+&#8230;&#8230;..+&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.+&#8230;+&#8230;..+&#8230;&#8230;&#8230;&#8230;.+&#8230;&#8230;+&#8230;&#8230;..+&#8230;&#8230;+.+&#8230;+..+&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;+&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;.+&#8230;+..+&#8230;+&#8230;&#8230;.+&#8230;&#8230;&#8230;+&#8230;&#8230;<br \/>\n..+&#8230;+&#8230;+&#8230;.+&#8230;..+.+&#8230;&#8230;&#8230;&#8230;+&#8230;+&#8230;..+.+&#8230;&#8230;..+&#8230;&#8230;+&#8230;.+&#8230;&#8230;&#8230;&#8230;+&#8230;..+&#8230;.+&#8230;&#8230;&#8230;+&#8230;+&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;..+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.+&#8230;&#8230;..+&#8230;&#8230;.+..+.+..+&#8230;&#8230;&#8230;&#8230;+&#8230;+&#8230;.+&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;+&#8230;&#8230;+&#8230;&#8230;&#8230;+..+&#8230;&#8230;&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;&#8230;+..+&#8230;+&#8230;&#8230;&#8230;&#8230;<br \/>\n+.+&#8230;+..+&#8230;+.+&#8230;+..+&#8230;&#8230;&#8230;+&#8230;.+..+&#8230;&#8230;&#8230;&#8230;.+..+.+&#8230;&#8230;&#8230;&#8230;&#8230;..+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++<br \/>\nEnter PEM pass phrase:<br \/>\nVerifying &#8211; Enter PEM pass phrase:<br \/>\n&#8212;&#8211;<br \/>\nYou are about to be asked to enter information that will be incorporated<br \/>\ninto your certificate request.<br \/>\nWhat you are about to enter is what is called a Distinguished Name or a DN.<br \/>\nThere are quite a few fields but you can leave some blank<br \/>\nFor some fields there will be a default value,<br \/>\nIf you enter &#8216;.&#8217;, the field will be left blank.<br \/>\n&#8212;&#8211;<br \/>\nCommon Name (eg: your user, host, or server name) [Easy-RSA CA]:<\/p>\n<p>* Notice:<\/p>\n<p>CA creation complete and you may now import and sign cert requests.<br \/>\nYour new CA certificate file for publishing is at:\/etc\/openvpn\/easy-rsa\/pki\/ca.crt<\/p>\n<p>e con questo si genera il CA<\/p>\n<p>cd pki<\/p>\n<p>vim safessl-easyrsa.cnf<\/p>\n<p>cambiare default_days da 825 a 3650<\/p>\n<p>cambiare default_crl_days da 180 a 3650 #per evitare dopo 6 mesi che nessun client si colleghi piu&#8217; perche&#8217; il certificato non e&#8217; piu&#8217; valido<\/p>\n<p>Durata dei certificati<\/p>\n<p>cd ..<\/p>\n<p>root@pc0:\/etc\/openvpn\/easy-rsa#.\/easyrsa gen-dh<\/p>\n<p>* WARNING:<\/p>\n<p>Unsupported \u00a0characters are present in the vars file.<br \/>\nThese characters are not supported: (&#8216;) (&amp;) (`) ($) (#)<br \/>\nSourcing the vars file and building certificates will probably fail ..<\/p>\n<p>* Notice:<br \/>\nUsing Easy-RSA configuration from: \/etc\/openvpn\/easy-rsa\/pki\/vars<\/p>\n<p>* Notice:<br \/>\nUsing SSL: openssl OpenSSL 3.0.11 19 Sep 2023 (Library: OpenSSL 3.0.11 19 Sep 2023)<\/p>\n<p>Generating DH parameters, 2048 bit long safe prime<br \/>\n&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..<br \/>\n+&#8230;&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;.+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.<br \/>\n&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;<br \/>\n&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;<br \/>\n&#8230;..+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.<br \/>\n&#8230;&#8230;.+&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.<br \/>\n* Notice:<\/p>\n<p>DH parameters of size 2048 created at \/etc\/openvpn\/easy-rsa\/pki\/dh.pem<\/p>\n<p>e con questo si generano i parametri diffie hellman<\/p>\n<p>root@pc0:\/etc\/openvpn\/easy-rsa#.\/easyrsa build-server-full server nopass<\/p>\n<p>* Notice:<br \/>\nUsing Easy-RSA configuration from: \/etc\/openvpn\/easy-rsa\/pki\/vars<\/p>\n<p>* Notice:<br \/>\nUsing SSL: openssl OpenSSL 3.0.11 19 Sep 2023 (Library: OpenSSL 3.0.11 19 Sep 2023)<\/p>\n<p>&#8230;&#8230;..+.+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*..+&#8230;+&#8230;&#8230;.+&#8230;..+&#8230;&#8230;.+&#8230;..+&#8230;&#8230;+&#8230;+.+&#8230;&#8230;&#8230;..+&#8230;.+++++++++++++++++++++++++++++++++++++++++++++++++++++++<br \/>\n++++++++++*&#8230;&#8230;.+&#8230;&#8230;+&#8230;&#8230;.+&#8230;..+.+&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;.+..+&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;+.+..+&#8230;&#8230;.+&#8230;+&#8230;..+&#8230;.+&#8230;+..+&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;+.+&#8230;&#8230;&#8230;&#8230;+..<br \/>\n.+&#8230;&#8230;&#8230;..+&#8230;+&#8230;&#8230;+&#8230;&#8230;+.+..+&#8230;&#8230;&#8230;&#8230;.+..+&#8230;&#8230;+&#8230;&#8230;+&#8230;.+&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;..+.+..+&#8230;.+&#8230;&#8230;&#8230;+..+&#8230;&#8230;&#8230;+&#8230;+&#8230;&#8230;+&#8230;&#8230;&#8230;.+..+&#8230;&#8230;.+&#8230;&#8230;&#8230;..+&#8230;.+&#8230;&#8230;.<br \/>\n.+&#8230;+&#8230;&#8230;+.+..+&#8230;+&#8230;&#8230;&#8230;&#8230;+.+&#8230;&#8230;+&#8230;&#8230;+..+&#8230;&#8230;+&#8230;&#8230;.+..+.+&#8230;&#8230;+&#8230;&#8230;&#8230;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++<br \/>\n&#8230;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*.+.+&#8230;&#8230;&#8230;+&#8230;&#8230;+&#8230;..+&#8230;&#8230;&#8230;&#8230;+&#8230;+&#8230;&#8230;&#8230;.+&#8230;&#8230;+&#8230;..+.+..+&#8230;&#8230;&#8230;.+..+.+&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;..+&#8230;+&#8230;&#8230;&#8230;.+<br \/>\n++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*.+..+&#8230;+&#8230;&#8230;+&#8230;.+..+&#8230;.+&#8230;..+&#8230;&#8230;+.+&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+..+&#8230;&#8230;+&#8230;.+&#8230;..+&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;.+..+..<br \/>\n&#8230;&#8230;&#8230;&#8230;..+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++<br \/>\n&#8212;&#8211;<br \/>\n* Notice:<\/p>\n<p>Keypair and certificate request completed. Your files are:<br \/>\nreq: \/etc\/openvpn\/easy-rsa\/pki\/reqs\/server.req<br \/>\nkey: \/etc\/openvpn\/easy-rsa\/pki\/private\/server.key<\/p>\n<p>You are about to sign the following certificate.<br \/>\nPlease check over the details shown below for accuracy. Note that this request<br \/>\nhas not been cryptographically verified. Please be sure it came from a trusted<br \/>\nsource or that you have verified the request checksum with the sender.<\/p>\n<p>Request subject, to be signed as a server certificate for 825 days:<\/p>\n<p>subject=<br \/>\ncommonName \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0= server<\/p>\n<p>Type the word &#8216;yes&#8217; to continue, or any other input to abort.<br \/>\nConfirm request details: yes<br \/>\nUsing configuration from \/etc\/openvpn\/easy-rsa\/pki\/466eb3c1\/temp.c0865d32<br \/>\nEnter pass phrase for \/etc\/openvpn\/easy-rsa\/pki\/private\/ca.key:<br \/>\nCheck that the request matches the signature<br \/>\nSignature ok<br \/>\nThe Subject&#8217;s Distinguished Name is as follows<br \/>\ncommonName \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0:ASN.1 12:&#8217;server&#8217;<br \/>\nCertificate is to be certified until Mar 25 08:51:14 2026 GMT (825 days)<\/p>\n<p>Write out database with 1 new entries<br \/>\nDatabase updated<\/p>\n<p>* Notice:<br \/>\nCertificate created at: \/etc\/openvpn\/easy-rsa\/pki\/issued\/server.crt<\/p>\n<p>generazione certificato server il parametro nopass evita la richiesta di password<\/p>\n<p>root@pc0:\/etc\/openvpn\/easy-rsa# openvpn &#8211;genkey secret \/etc\/openvpn\/easy-rsa\/pki\/ta.key<br \/>\ngenerazione della chiave precondivisa TLS\/SSL<br \/>\nroot@pc0:\/etc\/openvpn\/easy-rsa# .\/easyrsa gen-crl<br \/>\n* Notice:<br \/>\nUsing Easy-RSA configuration from: \/etc\/openvpn\/easy-rsa\/pki\/vars<\/p>\n<p>* Notice:<br \/>\nUsing SSL: openssl OpenSSL 3.0.11 19 Sep 2023 (Library: OpenSSL 3.0.11 19 Sep 2023)<\/p>\n<p>Using configuration from \/etc\/openvpn\/easy-rsa\/pki\/c06ed74f\/temp.25f1295e<br \/>\nEnter pass phrase for \/etc\/openvpn\/easy-rsa\/pki\/private\/ca.key:<\/p>\n<p>* Notice:<\/p>\n<p>An updated CRL has been created.<br \/>\nCRL file: \/etc\/openvpn\/easy-rsa\/pki\/crl.pem<br \/>\nGenerazione del certificato di revoca<\/p>\n<p>root@pc0:\/etc\/openvpn\/easy-rsa# .\/easyrsa build-client-full picinin3 nopass<\/p>\n<p>&nbsp;<\/p>\n<p>* Notice:<br \/>\nUsing Easy-RSA configuration from: \/etc\/openvpn\/easy-rsa\/pki\/vars<\/p>\n<p>* Notice:<br \/>\nUsing SSL: openssl OpenSSL 3.0.11 19 Sep 2023 (Library: OpenSSL 3.0.11 19 Sep 2023)<\/p>\n<p>&#8230;..+..+.+..+&#8230;&#8230;.+&#8230;&#8230;..+&#8230;+.+&#8230;..+.+&#8230;..+&#8230;+&#8230;.+&#8230;..+&#8230;&#8230;.+&#8230;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*&#8230;.+&#8230;..+.+&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.<br \/>\n&#8230;&#8230;..+&#8230;&#8230;..+.+&#8230;+&#8230;&#8230;&#8230;..+&#8230;&#8230;&#8230;+&#8230;&#8230;+&#8230;&#8230;.+&#8230;&#8230;&#8230;&#8230;..+.+&#8230;..+&#8230;+&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;.+..+&#8230;&#8230;&#8230;&#8230;.+&#8230;+&#8230;..+&#8230;&#8230;&#8230;.+..+.+&#8230;&#8230;&#8230;..+&#8230;+.+..+&#8230;+.+&#8230;&#8230;&#8230;&#8230;&#8230;.<br \/>\n&#8230;.+&#8230;&#8230;+&#8230;+&#8230;&#8230;+.+..+&#8230;&#8230;.+&#8230;&#8230;&#8230;+&#8230;&#8230;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*&#8230;.+&#8230;&#8230;.+&#8230;&#8230;+..+&#8230;.+&#8230;..+&#8230;+.+&#8230;&#8230;&#8230;&#8230;+..+&#8230;&#8230;.+&#8230;..+&#8230;+&#8230;<br \/>\n+&#8230;&#8230;&#8230;.+&#8230;..+&#8230;&#8230;.+&#8230;..+.+&#8230;&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;.+&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;+.+&#8230;&#8230;+&#8230;&#8230;&#8230;+&#8230;+&#8230;..+&#8230;&#8230;.+&#8230;..+&#8230;&#8230;&#8230;+&#8230;&#8230;.+..+&#8230;+&#8230;&#8230;.+..+&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;+&#8230;+<br \/>\n&#8230;&#8230;+.+..+.+&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;&#8230;&#8230;..+.+..+&#8230;&#8230;&#8230;.+&#8230;..+&#8230;+&#8230;.+&#8230;&#8230;&#8230;..+&#8230;.+&#8230;..+&#8230;&#8230;&#8230;.+&#8230;..+&#8230;+&#8230;&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;+&#8230;+&#8230;+&#8230;+..+&#8230;+&#8230;<br \/>\n&#8230;&#8230;&#8230;&#8230;&#8230;.+..+&#8230;.+&#8230;..+&#8230;&#8230;&#8230;+.+&#8230;&#8230;+&#8230;+..+&#8230;.+&#8230;&#8230;&#8230;..+.+..+&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.+&#8230;..+.+&#8230;&#8230;..+&#8230;&#8230;&#8230;.+..+&#8230;&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;&#8230;..+.+&#8230;..+&#8230;&#8230;.+&#8230;&#8230;&#8230;+++++++<br \/>\n++++++++++++++++++++++++++++++++++++++++++++++++++++++++++<br \/>\n.+&#8230;.+&#8230;+&#8230;..+&#8230;&#8230;.+&#8230;&#8230;&#8230;..+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;+.+..+.+&#8230;..+&#8230;.+&#8230;..+&#8230;&#8230;.+&#8230;..+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*.+..+&#8230;+.<br \/>\n&#8230;..+&#8230;&#8230;+&#8230;&#8230;.+..+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.+..+&#8230;&#8230;.+..+&#8230;+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++*&#8230;&#8230;+&#8230;+&#8230;&#8230;&#8230;.+&#8230;..+&#8230;&#8230;&#8230;+&#8230;+&#8230;&#8230;.+&#8230;&#8230;+&#8230;&#8230;&#8230;..<br \/>\n.+&#8230;..+&#8230;.+&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.+&#8230;..+&#8230;+&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;.+&#8230;&#8230;..+&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;+.+&#8230;..+.+&#8230;+&#8230;..+.+&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;..+&#8230;+.+&#8230;&#8230;&#8230;+&#8230;<br \/>\n&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;+..+&#8230;.+&#8230;..+&#8230;&#8230;.+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..+&#8230;&#8230;+.+&#8230;&#8230;&#8230;+&#8230;+&#8230;..+&#8230;+&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;.+..+&#8230;+&#8230;&#8230;.+&#8230;&#8230;&#8230;&#8230;..+&#8230;.+&#8230;&#8230;+..+&#8230;&#8230;.+..+.+&#8230;&#8230;..+..<br \/>\n&#8230;.+&#8230;.+..+&#8230;+.+&#8230;&#8230;..+&#8230;+&#8230;&#8230;.+&#8230;+&#8230;&#8230;&#8230;&#8230;+..+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;.+&#8230;+&#8230;&#8230;&#8230;+&#8230;+..+&#8230;&#8230;&#8230;+.+&#8230;&#8230;..+.+&#8230;..+.+&#8230;..+&#8230;&#8230;&#8230;&#8230;.+&#8230;+&#8230;+&#8230;&#8230;&#8230;&#8230;+..+&#8230;&#8230;&#8230;<br \/>\n&#8230;&#8230;&#8230;+&#8230;+.+&#8230;&#8230;+&#8230;+&#8230;..+&#8230;&#8230;+&#8230;+&#8230;&#8230;+&#8230;&#8230;.+&#8230;+&#8230;..+&#8230;&#8230;.+..+&#8230;&#8230;&#8230;&#8230;+&#8230;.+..+&#8230;+&#8230;&#8230;&#8230;.+&#8230;&#8230;+&#8230;+..+&#8230;+&#8230;+&#8230;+&#8230;.+&#8230;+&#8230;..+&#8230;+&#8230;&#8230;&#8230;+.+&#8230;&#8230;+&#8230;&#8230;&#8230;..+&#8230;<br \/>\n&#8230;&#8230;+.+&#8230;&#8230;&#8230;+&#8230;..+.+&#8230;..+&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;+&#8230;&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;+..+.+..+&#8230;&#8230;.+&#8230;&#8230;..+&#8230;&#8230;+&#8230;&#8230;+&#8230;+&#8230;&#8230;+.+&#8230;+..+.+&#8230;&#8230;..+&#8230;.+&#8230;..+&#8230;&#8230;&#8230;&#8230;&#8230;.+&#8230;..+..<br \/>\n&#8230;&#8230;&#8230;&#8230;..+&#8230;..+&#8230;.+&#8230;..+&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;..+&#8230;&#8230;&#8230;.+&#8230;&#8230;&#8230;+..+&#8230;&#8230;&#8230;.+&#8230;+..+&#8230;&#8230;&#8230;&#8230;+.+..+&#8230;.+&#8230;&#8230;+&#8230;..+&#8230;.+&#8230;+..+&#8230;+++++++++++++++++++++++++++++++++++++++++++++++<br \/>\n++++++++++++++++++<br \/>\n&#8212;&#8211;<br \/>\n* Notice:<\/p>\n<p>Keypair and certificate request completed. Your files are:<br \/>\nreq: \/etc\/openvpn\/easy-rsa\/pki\/reqs\/picinin3.req<br \/>\nkey: \/etc\/openvpn\/easy-rsa\/pki\/private\/picinin3.key<\/p>\n<p>You are about to sign the following certificate.<br \/>\nPlease check over the details shown below for accuracy. Note that this request<br \/>\nhas not been cryptographically verified. Please be sure it came from a trusted<br \/>\nsource or that you have verified the request checksum with the sender.<\/p>\n<p>Request subject, to be signed as a client certificate for 825 days:<\/p>\n<p>subject=<br \/>\ncommonName \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0= picinin3<\/p>\n<p>Type the word &#8216;yes&#8217; to continue, or any other input to abort.<br \/>\nConfirm request details: yes<br \/>\nUsing configuration from \/etc\/openvpn\/easy-rsa\/pki\/a19c4363\/temp.5b4d6217<br \/>\nEnter pass phrase for \/etc\/openvpn\/easy-rsa\/pki\/private\/ca.key:<br \/>\nCheck that the request matches the signature<br \/>\nSignature ok<br \/>\nThe Subject&#8217;s Distinguished Name is as follows<br \/>\ncommonName \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0:ASN.1 12:&#8217;picinin3&#8242;<br \/>\nCertificate is to be certified until Mar 25 10:52:54 2026 GMT (825 days)<\/p>\n<p>Write out database with 1 new entries<br \/>\nDatabase updated<\/p>\n<p>* Notice:<br \/>\nCertificate created at: \/etc\/openvpn\/easy-rsa\/pki\/issued\/picinin3.crt<br \/>\ncreazione certificati e chiavi per il client picinin3 (il mio portatile da combattimento) e a seguire stessa procedura per tutti client che si rendessero necessari.<\/p>\n<p>Per il formato del file dei client un po per comodit\u00e0 un po per voglia di provare anche su macchine linux ho scelto <a href=\"http:\/\/clark.tipistrani.it\/?p=2133\">l&#8217;unified format<\/a>.<br \/>\nUnica differenza per le macchine Linux l&#8217;estensione deve essee .conf e non .ovpn<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dopo 3 anni dall&#8217;ultima volta mi sono trovato a dover configurare un altra VPN da affiancare a quella aziendale per poter accedere al mio PC da remoto e quindi da li con IDRAC che secondo me \u00e8 l&#8217;invenzione del secolo per chi fa il mio lavoro, poter riaccendere la LAN da casa durante un giorno [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,14,284,6],"tags":[285,78],"class_list":["post-2491","post","type-post","status-publish","format-standard","hentry","category-linux","category-networking","category-openvpn","category-work","tag-daedalus","tag-openvpn"],"_links":{"self":[{"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/posts\/2491","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2491"}],"version-history":[{"count":5,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/posts\/2491\/revisions"}],"predecessor-version":[{"id":2528,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=\/wp\/v2\/posts\/2491\/revisions\/2528"}],"wp:attachment":[{"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2491"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2491"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/clark.tipistrani.it\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2491"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}