Blame
| a955d0 | Samuli Seppänen | 2025-03-18 12:34:13 | 1 | # IOSinline |
| 2 | ||||
| 3 | I had to setup openvpn on 4 non-jailbroken IOS devices yesterday. These devices were not setup to sync to computers, so I had to add the openvpn files via email. |
|||
| 4 | This is a bad (insecure) way to add openvpn to the devices, but in this case it was the only way, and security was not very important on this setup. |
|||
| 5 | If I was able to sync these devices with a computer, I could have used my original config file and cert files by adding the files from within iTunes. |
|||
| 6 | In order to make this work, You need to use in-line certificate files. |
|||
| 7 | My original config file looked like this: |
|||
| 8 | Before: |
|||
| 9 | ||||
| 10 | ``` |
|||
| 11 | client |
|||
| 12 | dev tun |
|||
| 13 | proto udp |
|||
| 14 | remote vpn.server.hostname 1194 |
|||
| 15 | resolv-retry infinite |
|||
| 16 | nobind |
|||
| 17 | persist-key |
|||
| 18 | persist-tun |
|||
| 19 | ns-cert-type server |
|||
| 20 | verb 3 |
|||
| 21 | ca ca.crt |
|||
| 22 | cert jeff.crt |
|||
| 23 | key jeff.key |
|||
| 24 | tls-auth ta.key 1 |
|||
| 25 | ``` |
|||
| 26 | ||||
| 27 | After changing my config files to work with in-line certificates, they looked like this: |
|||
| 28 | After |
|||
| 29 | ||||
| 30 | ``` |
|||
| 31 | client |
|||
| 32 | dev tun |
|||
| 33 | proto udp |
|||
| 34 | remote vpn.server.hostname 1194 |
|||
| 35 | resolv-retry infinite |
|||
| 36 | nobind |
|||
| 37 | persist-key |
|||
| 38 | persist-tun |
|||
| 39 | ns-cert-type server |
|||
| 40 | verb 3 |
|||
| 41 | key-direction 1 |
|||
| 42 | <ca> |
|||
| 43 | -----BEGIN CERTIFICATE----- |
|||
| 44 | ... |
|||
| 45 | -----END CERTIFICATE----- |
|||
| 46 | </ca> |
|||
| 47 | <cert> |
|||
| 48 | -----BEGIN CERTIFICATE----- |
|||
| 49 | ... |
|||
| 50 | -----END CERTIFICATE----- |
|||
| 51 | </cert> |
|||
| 52 | <key> |
|||
| 53 | -----BEGIN RSA PRIVATE KEY----- |
|||
| 54 | ... |
|||
| 55 | -----END RSA PRIVATE KEY----- |
|||
| 56 | </key> |
|||
| 57 | <tls-auth> |
|||
| 58 | -----BEGIN OpenVPN Static key V1----- |
|||
| 59 | ... |
|||
| 60 | -----END OpenVPN Static key V1----- |
|||
| 61 | </tls-auth> |
|||
| 62 | ``` |
|||
| 63 | ||||
| 64 | ||||
| 65 | Notice that --tls-auth takes a direction (1/0) when using it from a file, but when using tls-auth inline you must also use --key-direction (1/0). |
|||
| 66 | Then on the !Iphone/Ipad/Ipod touch go to the app store, search for openvpn connect, and install it. |
|||
| 67 | Then email the final config (with file extension .ovpn) as an attachment from an email account on your computer (or a webmail) to the email address setup on IOS in the Mail app. |
|||
| 68 | In the mail app open the email and open the .ovpn file, then choose to open it with OpenVPN. If you did it right, OpenVPN opens and you can click a + icon next to your config to import it. |
|||
| 69 | Now you can simply slide Off to On and your VPN connects. |
|||
| 70 | If your VPN server is at your house, and you are connecting to the Internet IP (as opposed to using the LAN IP in --remote) you can not connect to it from your house. |
