Commit 579e9c

2025-03-18 11:51:11 Samuli Seppänen: Fix Tracisms
Pages/EasyRSA3-OpenVPN-Howto.md ..
@@ 1,4 1,4 @@
- # Easy-RSA v3 OpenVPN Howto =
+ # Easy-RSA v3 OpenVPN Howto
Note for small setups, it often much easier to *not* setup a PKI but instead of the peer-fingeprint method instead. A small tutorial can be found here: https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst
@@ 21,13 21,13 @@
4. On your OpenVPN server, generate DH parameters (see the DH Generation section of this Howto)
- ## Easy-RSA and MITM protection with OpenVPN ==
+ ## Easy-RSA and MITM protection with OpenVPN
**Important note:** some OpenVPN configs rely on the deprecated "Netscape" cert attribute called nsCertType. This is deprecated behavior, and Easy-RSA 3 does **not** enable this by default like v2 did. Please use the `--remote-cert-tls` directive in your OpenVPN config files for MITM protection.
If you really need the old, deprecated behavior, enable the Netscape extensions by reading vars.example before signing certs with your CA. This will allow you to use `--ns-cert-type` with OpenVPN.
- ## PKI procedure: using a separate CA system ==
+ ## PKI procedure: using a separate CA system
Pick locations for the CA and each entity that will be assigned certs. All keypair/request generation should occur on the target system that will use them; put another way, generate a server request on the actual server system, and your client requests on each client.
@@ 87,7 87,7 @@
./easyrsa gen-dh
```
- ## PKI procedure: Producing your complete PKI on the CA machine ==
+ ## PKI procedure: Producing your complete PKI on the CA machine
It is most common for beginners to produce a complete PKI on one machine and then distribute the files as needed. If you have followed the steps above and already have a partial PKI then make sure you do not over write it. The simplest approach is to make a complete copy of Easyrsa3 in a new folder.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9