Re: I have a question about Easy-RSA

Gert Doering <[email protected]>
Newsgroups gmane.network.openvpn.user
Message-ID <[email protected]>
Hi,

On Mon, Jan 08, 2024 at 11:54:23AM +0100, Jochen Bern wrote:
> In a nutshell, if a specific CA certificate is used(!) in the config of
> whatever OpenVPN peer and is about to expire, you'll need to have it
> replaced, yes, *in every such config*.

What we do here ("we" being "one of the companies I support that use
OpenVPN") is to have personal certificates that expire after one year,
so every employee is used to "go to the portal and get a new .ovpn
once a year".

So when I need to change things (like, roll out tls-auth, get rid of
compression in client configs, new corp CA, etc.) - I just change the
template on the portal, and wait for a year - magically, all user configs
are updated.

Of course this only makes sense if there's a significant number of users -
if it's just like "5 users", I'd send everyone a new .ovpn and make sure
they start using it in a timely fashion ;-)

gert
-- 
"If was one thing all people took for granted, was conviction that if you 
 feed honest figures into a computer, honest figures come out. Never doubted 
 it myself till I met a computer with a sense of humor."
                             Robert A. Heinlein, The Moon is a Harsh Mistress

Gert Doering - Munich, Germany                             [email protected]

_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users
signature.asc (application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE-----

iQGcBAEBAgAGBQJlm9ZdAAoJEB2Cnv7KVigSyMEL/3g/Itr48I5ZLM3WSp7dKmp9
UJ8POI9La44NIQQDwWI9QEJ+P8f8pi+FbeVxO6QGua9DfSwIDZhOezlHjVSnKC75
YBCpLHGARSzzgR4QfavhPRkeSxp6ePmDA+oexkx+AJ6GBJNQczx/2bFNaxbONvqW
qqR0pltBYuh9T8FFwJi1CymyyoGP0B84WKZmaDMRYvGYHS4dW3T8nAF8RQLKbjPo
TG+f79QwFvWE1uggji1OlZckMNAhAFvNJ9VQ4IO/2HCnUII0YjyTFGtLlhCasBXw
ajSz2wy1JNhCa+kKxf7iasi6AFymxKumuwYkCO8UYtfnqd4QyfkJyV1utETo0fO2
Pq4fnEvPGjLSUZrNTpS6dqX0pvbrLvfXMRVeXNpQ2GWcnHV3CfMeaj5+nMfVbNnX
N1EhLjkRzaH5joIsVLJKc8fWuOvmY5ZKJCXc1cMMIOw65JsbFMn5n0jOf4Vt5t+l
nWZVmbOy4DnLnNe7JoAhwE4jK6WPz1UsY2j/hq+piw==
=lP5N
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.