Re: I have a question about Easy-RSA

Antonio Quartulli <[email protected]>
Newsgroups gmane.network.openvpn.user
Message-ID <[email protected]>
Hi,

On 09/01/2024 08:18, Peter Davis via Openvpn-users wrote:
> Hi,
> So if I want to revoke the keys in the future and prevent clients from connecting to the server, then I need the Easy-RSA directory that I used to generate the keys at that time. is it true?

Correct. More specifically, you need the CA key in order to sign your 
CRL (Certificate Revocation List).

The CA is the *trusted* entity that is in charge of signing "documents" 
that others need to accept. IF you delete it, you have no way of 
creating new "documents".

Cheers,



-- 
Antonio Quartulli
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.