Re: I have a question about Easy-RSA

Peter Davis via Openvpn-users <[email protected]>
Newsgroups gmane.network.openvpn.user
Message-ID <1tG5993WEcj_NSUwjowlkDIkv28-OGn5bJKxOkhowXjNnrvLyhOwIHavcpjFiT8lcBvTYIDB6AgCZF3shmndd-Jd0YGuy1-TjO1bH90lYOU=@proton.me>
>On Tuesday, January 9th, 2024 at 2:40 PM, Antonio Quartulli <[email protected]> wrote:


> Hi,
> 
> On 09/01/2024 08:18, Peter Davis via Openvpn-users wrote:
> 
> > Hi,
> > So if I want to revoke the keys in the future and prevent clients from connecting to the server, then I need the Easy-RSA directory that I used to generate the keys at that time. is it true?
> 
> 
> Correct. More specifically, you need the CA key in order to sign your
> CRL (Certificate Revocation List).
> 
> The CA is the trusted entity that is in charge of signing "documents"
> that others need to accept. IF you delete it, you have no way of
> creating new "documents".
> 
> Cheers,
> 
> 
> 
> --
> Antonio Quartulli

Hi,
In the Easy-RSA directory I have the following files and directories:
easyrsa  openssl-easyrsa.cnf  pki  ta.key  vars  x509-types

Is it enough to keep the pki directory?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.