Re: I have a question about Easy-RSA
Jochen Bern <[email protected]>
| Newsgroups | gmane.network.openvpn.user |
|---|---|
| Organization | Binect GmbH |
| Message-ID | <[email protected]> |
On 07.01.24 06:50, Peter Davis via Openvpn-users wrote:
> As you can see, I have moved the files to /etc/openvpn/server directory.
Correction: You have copied SOME files to that directory, namely, those
that the server needs.
> Now if I ignore the warning message above, what is the risk?
Then you'll lose the content of those files that only the *CA* needs,
and thus the ability to continue operating that (first) CA, in particular:
-- You'll be unable to create a CRL, whether it is to actually revoke a
cert or just to replace an expiring one.
-- When the (first) server cert expires, you'll be unable to have a new
one created by the same CA, thus requiring a config change on *every*
client - wherever and in whosever hands it is - before it'll be able
to connect to the VPN again.
Kind regards,
--
Jochen Bern
Systemingenieur
Binect GmbH
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users
smime.p7s
(application/pkcs7-signature, 3.4 KB) - not displayed