Blame

ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1
# New to OpenVPN? 
0c0510 Samuli Seppänen 2025-02-11 12:59:17 2
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 3
This howto has been the main howto since the early days of OpenVPN. It covers a lot of details, many areas here may require deeper understanding of how OpenVPN works or networking in general. Some of this information is also outdated, but it is currently kept here as historic reference.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 4
2e45f9 David Sommerseth 2025-05-22 09:39:16 5
**If you are completely new to OpenVPN, please consider our [Getting Started With OpenVPN](/Pages/Getting%20started%20with%20OpenVPN) guide first.**
0c0510 Samuli Seppänen 2025-02-11 12:59:17 6
7
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 8
# Introduction
0c0510 Samuli Seppänen 2025-02-11 12:59:17 9
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 10
OpenVPN is a full-featured SSL VPN which implements OSI layer 2 or 3 secure network extension using the industry standard SSL/TLS protocol, supports flexible client authentication methods based on certificates, smart cards, and/or username/password credentials, and allows user or group-specific access control policies using firewall rules applied to the VPN virtual interface. OpenVPN is not a web application proxy and does not operate through a web browser.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 11
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 12
OpenVPN 2.0 expands on the capabilities of OpenVPN 1.x by offering a scalable client/server mode, allowing multiple clients to connect to a single OpenVPN server process over a single TCP or UDP port. OpenVPN 2.3 includes a large number of improvements, including full IPv6 support and PolarSSL support.
13
14
The official version of this document is stored on the main website. If you find a problem in the official version you can fix it in the [Wiki version](HOWTO). Changes made to the Wiki version will be merged periodically to the official version.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 15
16
This document provides step-by-step instructions for configuring an OpenVPN 2.x client/server VPN, including:
17
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 18
0c0510 Samuli Seppänen 2025-02-11 12:59:17 19
The impatient may wish to jump straight to the sample configuration files:
20
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 21
* [Server configuration file](https://github.com/OpenVPN/openvpn/blob/master/sample/sample-config-files/server.conf).
22
* [Client configuration file](https://github.com/OpenVPN/openvpn/blob/master/sample/sample-config-files/client.conf).
23
24
# Intended Audience
0c0510 Samuli Seppänen 2025-02-11 12:59:17 25
26
This HOWTO assumes that readers possess a prior understanding of basic networking concepts such as IP addresses, DNS names, netmasks, subnets, IP routing, routers, network interfaces, LANs, gateways, and firewall rules.
27
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 28
# Additional Documentation
0c0510 Samuli Seppänen 2025-02-11 12:59:17 29
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 30
The original [OpenVPN 1.x HOWTO](/Openvpn1xHOWTO) is still available, and remains relevant for point-to-point or static-key configurations. Complete list of documentation is available on the [documentation front page](/WikiStart).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 31
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 32
While this HOWTO will guide you in setting up a scalable client/server VPN using an X509 PKI (public key infrastructure using certificates and private keys), this might be overkill if you are only looking for a simple VPN setup with a server that can handle a single client.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 33
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 34
If you would like to get a VPN running quickly with minimal configuration, you might check out the [Static Key Mini-HOWTO](/StaticKeyMiniHowto). The advantages of a static key setup:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 35
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 36
* Simple Setup
37
* No X509 PKI (Public Key Infrastructure) to maintain
0c0510 Samuli Seppänen 2025-02-11 12:59:17 38
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 39
And the disadvantages:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 40
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 41
* Limited scalability -- one client, one server
42
* Lack of perfect forward secrecy -- key compromise results in total disclosure of previous sessions
43
* Secret key must exist in plaintext form on each VPN peer
44
* Secret key must be exchanged using a pre-existing secure channel
0c0510 Samuli Seppänen 2025-02-11 12:59:17 45
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 46
# Installing OpenVPN
0c0510 Samuli Seppänen 2025-02-11 12:59:17 47
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 48
OpenVPN source code and Windows installers can be [downloaded here]. Recent releases (2.2 and later) are also available as Debian and Ubuntu packages; see [this article](https://openvpn.net/community-downloads/)(/OpenvpnSoftwareRepos) for details.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 49
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 50
For security, it's a good idea to check the [file release signature](https://community.openvpn.net/signatures.html) after downloading.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 51
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 52
The OpenVPN executable should be installed on both server and client machines, since the single executable provides both client and server functions.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 53
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 54
## Linux Notes
6f556a Samuli Seppänen 2025-02-11 13:02:50 55
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 56
If you are using Linux, it's usually best to use your distribution's own mechanism (yum, apt-get, zypper, emerge...) for installing OpenVPN.
6f556a Samuli Seppänen 2025-02-11 13:02:50 57
0c0510 Samuli Seppänen 2025-02-11 12:59:17 58
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 59
It is also possible to install OpenVPN on Linux using the universal ./configure method. First expand the .tar.gz file:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 60
```
61
tar xfz openvpn-[version].tar.gz
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 62
```
63
Then cd to the top-level directory and type:
64
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 65
./configure
66
make
67
make install
68
```
69
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 70
## Windows Notes
0c0510 Samuli Seppänen 2025-02-11 12:59:17 71
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 72
OpenVPN for Windows can be installed from the self-installing exe file on the [OpenVPN download page]. Remember that OpenVPN will only run on Windows XP or later. Also note that OpenVPN must be installed and run by a user who has administrative privileges (this restriction is imposed by Windows, not OpenVPN). The restriction can be sidestepped by running OpenVPN in the background as a service, in which case even non-admin users will be able to access the VPN, once it is installed. More discussion on OpenVPN + Windows privilege issues [http://openvpn.se/files/howto/openvpn-howto_run_openvpn_as_nonadmin.html here](https://openvpn.net/community-downloads/).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 73
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 74
Official OpenVPN Windows installers include [OpenVPN-GUI](/OpenVPN-GUI), which allows managing OpenVPN connections from a system tray applet. Other GUI applications are also available.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 75
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 76
After you've run the Windows installer, OpenVPN is ready for use and will associate itself with files having the **.ovpn** extension. To run OpenVPN, you can:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 77
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 78
* Right click on an OpenVPN configuration file (.ovpn) and select **Start OpenVPN on this configuration file**. Once running, you can use the **F4** key to exit.
79
* Run OpenVPN from a command prompt Window with a command such as "**openvpn myconfig.ovpn**". Once running in a command prompt window, the F4 key can stop OpenVPN.
80
* Run OpenVPN as a service by putting one or more .ovpn configuration files in **\Program Files\OpenVPN\config** and starting the OpenVPN Service, which can be controlled from Start Menu -> Control Panel -> Administrative Tools -> Services.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 81
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 82
[Additional Windows install notes](https://github.com/OpenVPN/openvpn-build/blob/master/windows-nsis/INSTALL-win32.txt).
83
84
## Mac OS X Notes
0c0510 Samuli Seppänen 2025-02-11 12:59:17 85
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 86
Angelo Laub and Dirk Theisen have developed an [OpenVPN GUI for OS X](https://tunnelblick.net/).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 87
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 88
## Other OSes
0c0510 Samuli Seppänen 2025-02-11 12:59:17 89
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 90
Some notes are available in the [INSTALL](https://github.com/OpenVPN/openvpn/blob/master/INSTALL) file for specific OSes. In general, the
91
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 92
./configure
93
make
94
make install
95
```
96
method can be used, or you can search for an OpenVPN port or package that is specific to your OS/distribution.
97
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 98
# Determining whether to use a routed or bridged VPN
0c0510 Samuli Seppänen 2025-02-11 12:59:17 99
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 100
See the documentation [front page](/WikiStart) and [FAQ](/FAQ) for an overview of Routing vs. Ethernet Bridging.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 101
102
Overall, routing is probably a better choice for most people, as it is more efficient and easier to set up (as far as the OpenVPN configuration itself) than bridging. Routing also provides a greater ability to selectively control access rights on a client-specific basis.
103
104
I would recommend using routing unless you need a specific feature which requires bridging, such as:
105
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 106
* the VPN needs to be able to handle non-IP protocols such as IPX,
107
* you are running applications over the VPN which rely on network broadcasts (such as LAN games), or
108
* you would like to allow browsing of Windows file shares across the VPN without setting up a Samba or WINS server.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 109
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 110
# Numbering private subnets
111
See here also: AvoidRoutingConflicts
0c0510 Samuli Seppänen 2025-02-11 12:59:17 112
113
Setting up a VPN often entails linking together private subnets from different locations.
114
115
The Internet Assigned Numbers Authority (IANA) has reserved the following three blocks of the IP address space for private internets (codified in RFC 1918):
116
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 117
| | | |
118
|-|-|-|
119
|10.0.0.0|10.255.255.255|(10/8 prefix)|
120
|172.16.0.0|172.31.255.255|(172.16/12 prefix)|
121
|192.168.0.0|192.168.255.255|(192.168/16 prefix)|
0c0510 Samuli Seppänen 2025-02-11 12:59:17 122
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 123
While addresses from these netblocks should normally be used in VPN configurations, it's important to select addresses that minimize the probability of IP address or subnet conflicts. The types of conflicts that need to be avoided are:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 124
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 125
* conflicts from different sites on the VPN using the same LAN subnet numbering, or
126
* remote access connections from sites that are using private subnets which conflict with your VPN subnets.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 127
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 128
For example, suppose you use the popular 192.168.0.0/24 subnet as your private LAN subnet. Now you are trying to connect to the VPN from an internet cafe which is using the same subnet for its !WiFi LAN. You will have a routing conflict because your machine won't know if 192.168.0.1 refers to the local !WiFi gateway or to the same address on the VPN.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 129
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 130
As another example, suppose you want to link together multiple sites by VPN, but each site is using 192.168.0.0/24 as its LAN subnet. This won't work without adding a complexifying layer of NAT translation, because the VPN won't know how to route packets between multiple sites if those sites don't use a subnet which uniquely identifies them.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 131
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 132
The best solution is to avoid using 10.0.0.0/24 or 192.168.0.0/24 as private LAN network addresses. Instead, use something that has a lower probability of being used in a WiFi cafe, airport, or hotel where you might expect to connect from remotely. The best candidates are subnets in the middle of the vast 10.0.0.0/8 netblock (for example 10.66.77.0/24).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 133
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 134
And to avoid cross-site IP numbering conflicts, always use unique numbering for your LAN subnets.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 135
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 136
# Setting up your own Certificate Authority (CA) and generating certificates and keys for an OpenVPN server and multiple clients
0c0510 Samuli Seppänen 2025-02-11 12:59:17 137
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 138
## Overview
0c0510 Samuli Seppänen 2025-02-11 12:59:17 139
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 140
The first step in building an OpenVPN 2.x configuration is to establish a PKI (public key infrastructure). The PKI consists of:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 141
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 142
* a separate certificate (also known as a public key) and private key for the server and each client, and
143
* a master Certificate Authority (CA) certificate and key which is used to sign each of the server and client certificates.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 144
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 145
OpenVPN supports bidirectional authentication based on certificates, meaning that the client must authenticate the server certificate and the server must authenticate the client certificate before mutual trust is established.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 146
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 147
Both server and client will authenticate the other by first verifying that the presented certificate was signed by the master certificate authority (CA), and then by testing information in the now-authenticated certificate header, such as the certificate common name or certificate type (client or server).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 148
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 149
This security model has a number of desirable features from the VPN perspective:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 150
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 151
* The server only needs its own certificate/key -- it doesn't need to know the individual certificates of every client which might possibly connect to it.
152
* The server will only accept clients whose certificates were signed by the master CA certificate (which we will generate below). And because the server can perform this signature verification without needing access to the CA private key itself, it is possible for the CA key (the most sensitive key in the entire PKI) to reside on a completely different machine, even one without a network connection.
153
* If a private key is compromised, it can be disabled by adding its certificate to a CRL (certificate revocation list). The CRL allows compromised certificates to be selectively rejected without requiring that the entire PKI be rebuilt.
154
* The server can enforce client-specific access rights based on embedded certificate fields, such as the Common Name.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 155
156
Note that the server and client clocks need to be roughly in sync or certificates might not work properly.
157
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 158
## Generate the master Certificate Authority (CA) certificate & key
0c0510 Samuli Seppänen 2025-02-11 12:59:17 159
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 160
In this section we will generate a master CA certificate/key, a server certificate/key, and certificates/keys for 3 separate clients.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 161
162
**Please take note:** Easy-RSA Version 3 is now preferred over Easy-RSA Version 2.
163
164
EasyRSA-3 has a [Quick-Start Guide](https://github.com/OpenVPN/easy-rsa/blob/master/README.quickstart.md)
165
166
There is also [Easy-TLS](https://github.com/TinCanTech/easy-tls), which is an add-on utility to manage `.inline` files and **TLS Crypt V2** keys. (It's very useful)
167
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 168
0c0510 Samuli Seppänen 2025-02-11 12:59:17 169
The following instruction **only** work for Easy-RSA **v2**.
170
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 171
For PKI management, we will use [easy-rsa 2], a set of scripts which is bundled with OpenVPN 2.2.x and earlier. If you're using OpenVPN 2.3.x, you may need to download easy-rsa 2 separately from the [https://github.com/OpenVPN/easy-rsa-old easy-rsa-old project page]. An easy-rsa 2 package is also available for Debian and Ubuntu in the [OpenVPN software repos](https://github.com/OpenVPN/easy-rsa-old)(/OpenvpnSoftwareRepos).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 172
173
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 174
You should also look into using [easy-rsa 3](https://github.com/OpenVPN/easy-rsa/releases), available to most OS's, including Windows; refer to its own documentation for details.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 175
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 176
If you are using Linux, BSD, or a unix-like OS, open a shell and cd to the easy-rsa subdirectory. If you installed OpenVPN from an RPM or DEB file provided by your distribution, the easy-rsa directory can usually be found in **/usr/share/doc/packages/openvpn** or **/usr/share/doc/openvpn** (it's best to copy this directory to another location such as **/etc/openvpn**, before any edits, so that future OpenVPN package upgrades won't overwrite your modifications).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 177
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 178
If you are using Windows, (**AND you are using Version 2 of Easy-RSA**) open up a Command Prompt window and cd to **\Program Files\OpenVPN\easy-rsa**. Run the following batch file to copy configuration files into place (this will overwrite any preexisting vars.bat and openssl.cnf files):
0c0510 Samuli Seppänen 2025-02-11 12:59:17 179
```
180
init-config
181
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 182
Now edit the vars file (called vars.bat on Windows) and set the KEY_COUNTRY, KEY_PROVINCE, KEY_CITY, KEY_ORG, and KEY_EMAIL parameters. Don't leave any of these parameters blank.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 183
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 184
Next, initialize the PKI. On Linux/BSD/Unix:
185
186
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 187
. ./vars
188
./clean-all
189
./build-ca
190
```
191
192
On Windows:
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 193
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 194
vars
195
```
196
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 197
If you get an error message that says:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 198
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 199
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 200
You appear to be sourcing an Easy-RSA *vars* file.
201
This is no longer necessary and is disallowed. See the section called
202
*How to use this file* near the top comments for more details.
203
```
204
205
You are using [Easy-RSA Version 3](https://github.com/OpenVPN/easy-rsa/releases).
206
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 207
OpenVPN For Windows only installs Easy-RSA Version 3
0c0510 Samuli Seppänen 2025-02-11 12:59:17 208
209
----
210
211
Otherwise, continue:
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 212
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 213
clean-all
214
build-ca
215
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 216
The final command (**build-ca**) will build the certificate authority (CA) certificate and key by invoking the interactive **openssl** command:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 217
218
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 219
ai:easy-rsa # ./build-ca
220
Generating a 1024 bit RSA private key
221
............++++++
222
...........++++++
223
writing new private key to 'ca.key'
0c0510 Samuli Seppänen 2025-02-11 12:59:17 224
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 225
----
226
-
227
You are about to be asked to enter information that will be incorporated
228
into your certificate request.
229
What you are about to enter is what is called a Distinguished Name or a DN.
230
There are quite a few fields but you can leave some blank
231
For some fields there will be a default value,
232
If you enter '.', the field will be left blank.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 233
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 234
----
235
-
236
Country Name (2 letter code) [KG]:
237
State or Province Name (full name) [NA]:
238
Locality Name (eg, city) [BISHKEK]:
239
Organization Name (eg, company) [OpenVPN-TEST]:
240
Organizational Unit Name (eg, section) []:
241
Common Name (eg, your name or your server's hostname) []:OpenVPN-CA
242
Email Address [me@myhost.mydomain]:
243
```
244
Note that in the above sequence, most queried parameters were defaulted to the values set in the vars or vars.bat files. The only parameter which must be explicitly entered is the Common Name. In the example above, I used "OpenVPN-CA".
0c0510 Samuli Seppänen 2025-02-11 12:59:17 245
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 246
## Generate certificate & key for server
0c0510 Samuli Seppänen 2025-02-11 12:59:17 247
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 248
Next, we will generate a certificate and private key for the server. On Linux/BSD/Unix:
249
```
250
./build-key-server server
0c0510 Samuli Seppänen 2025-02-11 12:59:17 251
```
252
On Windows:
253
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 254
build-key-server server
0c0510 Samuli Seppänen 2025-02-11 12:59:17 255
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 256
As in the previous step, most parameters can be defaulted. When the **Common Name** is queried, enter "server". Two other queries require positive responses, "Sign the certificate? [y/n]" and "1 out of 1 certificate requests certified, commit? [y/n]".
0c0510 Samuli Seppänen 2025-02-11 12:59:17 257
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 258
## Generate certificates & keys for 3 clients
0c0510 Samuli Seppänen 2025-02-11 12:59:17 259
260
Generating client certificates is very similar to the previous step. On Linux/BSD/Unix:
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 261
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 262
./build-key client1
263
./build-key client2
264
./build-key client3
265
```
266
On Windows:
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 267
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 268
build-key client1
269
build-key client2
270
build-key client3
271
```
272
If you would like to password-protect your client keys, substitute the **build-key-pass** script.
273
274
Remember that for each client, make sure to type the appropriate **Common Name** when prompted, i.e. "client1", "client2", or "client3". Always use a unique common name for each client.
275
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 276
## Generate Diffie Hellman parameters
0c0510 Samuli Seppänen 2025-02-11 12:59:17 277
278
Diffie Hellman parameters must be generated for the OpenVPN server. On Linux/BSD/Unix:
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 279
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 280
./build-dh
281
```
282
On Windows:
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 283
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 284
build-dh
285
```
286
Output:
287
288
```
289
ai:easy-rsa # ./build-dh
290
Generating DH parameters, 1024 bit long safe prime, generator 2
291
This is going to take a long time
292
.................+...........................................
293
...................+.............+.................+.........
294
......................................
295
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 296
## Key Files
0c0510 Samuli Seppänen 2025-02-11 12:59:17 297
298
Now we will find our newly-generated keys and certificates in the **keys** subdirectory. Here is an explanation of the relevant files:
299
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 300
|**Filename**|**Needed By**|**Purpose**|**Secret**|
301
|-|-|-|-|
302
|ca.crt|server + all clients|Root CA certificate|NO|
303
|ca.key|key signing machine only|Root CA key|YES|
304
|dh{n}.pem|server only|Diffie Hellman parameters|NO|
305
|server.crt|server only|Server Certificate|NO|
306
|server.key|server only|Server Key|YES|
307
|client1.crt|client1 only|Client1 Certificate|NO|
308
|client1.key|client1 only|Client1 Key|YES|
309
|client2.crt|client2 only|Client2 Certificate|NO|
310
|client2.key|client2 only|Client2 Key|YES|
311
|client3.crt|client3 only|Client3 Certificate|NO|
312
|client3.key|client3 only|Client3 Key|YES|
0c0510 Samuli Seppänen 2025-02-11 12:59:17 313
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 314
The final step in the key generation process is to copy all files to the machines which need them, taking care to copy secret files over a secure channel.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 315
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 316
Now wait, you may say. Shouldn't it be possible to set up the PKI without a pre-existing secure channel?
0c0510 Samuli Seppänen 2025-02-11 12:59:17 317
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 318
The answer is ostensibly yes. In the example above, for the sake of brevity, we generated all private keys in the same place. With a bit more effort, we could have done this differently. For example, instead of generating the client certificate and keys on the server, we could have had the client generate its own private key locally, and then submit a Certificate Signing Request (CSR) to the key-signing machine. In turn, the key-signing machine could have processed the CSR and returned a signed certificate to the client. This could have been done without ever requiring that a secret .key file leave the hard drive of the machine on which it was generated.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 319
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 320
# Creating configuration files for server and clients
0c0510 Samuli Seppänen 2025-02-11 12:59:17 321
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 322
## Getting the sample config files
0c0510 Samuli Seppänen 2025-02-11 12:59:17 323
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 324
It's best to use the OpenVPN [sample configuration files](https://github.com/OpenVPN/openvpn/tree/master/sample/sample-config-files) as a starting point for your own configuration. These files can also be found in
0c0510 Samuli Seppänen 2025-02-11 12:59:17 325
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 326
* the **sample/sample-config-files** directory of the OpenVPN source distribution
327
* the **sample-config-files** directory in **/usr/share/doc/packages/openvpn** or **/usr/share/doc/openvpn** if you installed from an RPM or DEB package
328
* **Start Menu -> All Programs -> OpenVPN -> OpenVPN Sample Configuration Files** on Windows
0c0510 Samuli Seppänen 2025-02-11 12:59:17 329
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 330
Note that on Linux, BSD, or unix-like OSes, the sample configuration files are named **server.conf** and **client.conf**. On Windows they are named **server.ovpn** and **client.ovpn**.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 331
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 332
## Editing the server configuration file
0c0510 Samuli Seppänen 2025-02-11 12:59:17 333
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 334
The sample server configuration file is an ideal starting point for an OpenVPN server configuration. It will create a VPN using a virtual **TUN** network interface (for routing), will listen for client connections on **UDP port 1194** (OpenVPN's official port number), and distribute virtual addresses to connecting clients from the **10.8.0.0/24** subnet.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 335
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 336
Before you use the sample configuration file, you should first edit the ca, cert, key, and dh parameters to point to the files you generated in the PKI section above.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 337
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 338
At this point, the server configuration file is usable, however you still might want to customize it further:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 339
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 340
* If you are using Ethernet bridging, you must use **server-bridge** and **dev tap** instead of **server** and **dev tun**.
341
* If you want your OpenVPN server to listen on a TCP port instead of a UDP port, use **proto tcp** instead of **proto udp** (If you want OpenVPN to listen on both a UDP and TCP port, you must run two separate OpenVPN instances).
342
* If you want to use a virtual IP address range other than **10.8.0.0/24**, you should modify the server directive. Remember that this virtual IP address range should be a private range which is currently unused on your network.
343
* Uncomment out the **client-to-client** directive if you would like connecting clients to be able to reach each other over the VPN. By default, clients will only be able to reach the server.
344
* If you are using Linux, BSD, or a Unix-like OS, you can improve security by uncommenting out the **user nobody** and **group nobody** directives.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 345
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 346
If you want to run multiple OpenVPN instances on the same machine, each using a different configuration file, it is possible if you:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 347
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 348
* Use a different **port** number for each instance (the UDP and TCP protocols use different port spaces so you can run one daemon listening on UDP-1194 and another on TCP-1194).
349
* If you are using Windows, each OpenVPN configuration needs to have its own TAP-Windows adapter. You can add additional adapters by going to **Start Menu -> All Programs -> TAP-Windows -> Add a new TAP-Windows virtual ethernet adapter**.
350
* If you are running multiple OpenVPN instances out of the same directory, make sure to edit directives which create output files so that multiple instances do not overwrite each other's output files. These directives include **log, log-append, status**, and **ifconfig-pool-persist**.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 351
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 352
## Editing the client configuration files
0c0510 Samuli Seppänen 2025-02-11 12:59:17 353
354
The sample client configuration file (**client.conf** on Linux/BSD/Unix or **client.ovpn** on Windows) mirrors the default directives set in the sample server configuration file.
355
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 356
* Like the server configuration file, first edit the **ca**, **cert**, and **key** parameters to point to the files you generated in the PKI section above. Note that each client should have its own **cert/key** pair. Only the cafile is universal across the OpenVPN server and all clients.
357
* Next, edit the **remote** directive to point to the hostname/IP address and port number of the OpenVPN server (if your OpenVPN server will be running on a single-NIC machine behind a firewall/NAT-gateway, use the public IP address of the gateway, and a port number which you have configured the gateway to forward to the OpenVPN server).
358
* Finally, ensure that the client configuration file is consistent with the directives used in the server configuration. The major thing to check for is that the **dev** (tun or tap) and **proto** (udp or tcp) directives are consistent. Also make sure that **comp-lzo** and **fragment**, if used, are present in both client and server config files.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 359
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 360
# Starting up the VPN and testing for initial connectivity
0c0510 Samuli Seppänen 2025-02-11 12:59:17 361
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 362
## Starting the server
0c0510 Samuli Seppänen 2025-02-11 12:59:17 363
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 364
First, make sure the OpenVPN server will be accessible from the internet. That means:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 365
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 366
* opening up UDP port 1194 on the firewall (or whatever TCP/UDP port you've configured), or
367
* setting up a port forward rule to forward UDP port 1194 from the firewall/gateway to the machine running the OpenVPN server.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 368
369
Next, make sure that the TUN/TAP interface is not firewalled.
370
371
To simplify troubleshooting, it's best to initially start the OpenVPN server from the command line (or right-click on the .ovpn file on Windows), rather than start it as a daemon or service:
372
```
373
openvpn [server config file]
374
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 375
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 376
A normal server startup should look like this (output will vary across platforms):
377
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 378
Sun Feb 6 20:46:38 2005 OpenVPN 2.0_rc12 i686-suse-linux [SSL] [LZO] [EPOLL] built on Feb 5 2005
379
Sun Feb 6 20:46:38 2005 Diffie-Hellman initialized with 1024 bit key
380
Sun Feb 6 20:46:38 2005 TLS-Auth MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
381
Sun Feb 6 20:46:38 2005 TUN/TAP device tun1 opened
382
Sun Feb 6 20:46:38 2005 /sbin/ifconfig tun1 10.8.0.1 pointopoint 10.8.0.2 mtu 1500
383
Sun Feb 6 20:46:38 2005 /sbin/route add -net 10.8.0.0 netmask 255.255.255.0 gw 10.8.0.2
384
Sun Feb 6 20:46:38 2005 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:23 ET:0 EL:0 AF:3/1 ]
385
Sun Feb 6 20:46:38 2005 UDPv4 link local (bound): [undef]:1194
386
Sun Feb 6 20:46:38 2005 UDPv4 link remote: [undef]
387
Sun Feb 6 20:46:38 2005 MULTI: multi_init called, r# 256 v
388
Sun Feb 6 20:46:38 2005 IFCONFIG POOL: base# 10.8.0.4 size
389
Sun Feb 6 20:46:38 2005 IFCONFIG POOL LIST
390
Sun Feb 6 20:46:38 2005 Initialization Sequence Completed
0c0510 Samuli Seppänen 2025-02-11 12:59:17 391
```
392
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 393
## Starting the client
0c0510 Samuli Seppänen 2025-02-11 12:59:17 394
395
As in the server configuration, it's best to initially start the OpenVPN server from the command line (or on Windows, by right-clicking on the client.ovpn file), rather than start it as a daemon or service:
396
```
397
openvpn [client config file]
398
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 399
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 400
A normal client startup on Windows will look similar to the server output above, and should end with the **Initialization Sequence Completed** message.
401
402
Now, try a ping across the VPN from the client. If you are using routing (i.e. **dev tun** in the server config file), try:
403
```
404
ping 10.8.0.1
405
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 406
If you are using bridging (i.e. **dev tap** in the server config file), try to ping the IP address of a machine on the server's ethernet subnet.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 407
408
If the ping succeeds, congratulations! You now have a functioning VPN.
409
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 410
## Troubleshooting
0c0510 Samuli Seppänen 2025-02-11 12:59:17 411
412
If the ping failed or the OpenVPN client initialization failed to complete, here is a checklist of common symptoms and their solutions.
413
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 414
1. You get the error message: **TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)**. This error indicates that the client was unable to establish a network connection with the server.
415
* Solutions:
416
* Make sure the client is using the correct hostname/IP address and port number which will allow it to reach the OpenVPN server.
417
* If the OpenVPN server machine is a single-NIC box inside a protected LAN, make sure you are using a correct port forward rule on the server's gateway firewall. For example, suppose your OpenVPN box is at 192.168.4.4 inside the firewall, listening for client connections on UDP port 1194. The NAT gateway servicing the 192.168.4.x subnet should have a port forward rule that says **forward UDP port 1194 from my public IP address to 192.168.4.4**.
418
* Open up the server's firewall to allow incoming connections to UDP port 1194 (or whatever TCP/UDP port you have configured in the server config file).
419
1. You get the error message: **Initialization Sequence Completed with errors**-- This error can occur on Windows if (a) You don't have the DHCP client service running, or (b) You are using certain third-party personal firewalls on XP SP2.
420
* Solution:
421
* Start the DHCP client server and make sure that you are using a personal firewall which is known to work correctly on XP SP2.
422
1. You get the **Initialization Sequence Completed** message but the ping test fails -- This usually indicates that a firewall on either server or client is blocking VPN network traffic by filtering on the TUN/TAP interface.
423
* Solution:
424
* Disable the client firewall (if one exists) from filtering the TUN/TAP interface on the client. For example on Windows XP SP2, you can do this by going to **Windows Security Center -> Windows Firewall -> Advanced** and unchecking the box which corresponds to the TAP-Windows adapter (disabling the client firewall from filtering the TUN/TAP adapter is generally reasonable from a security perspective, as you are essentially telling the firewall not to block authenticated VPN traffic). Also make sure that the TUN/TAP interface on the server is not being filtered by a firewall (having said that, note that selective firewalling of the TUN/TAP interface on the server side can confer certain security benefits. See the access policies section below).
425
1. The connection stalls on startup when using a proto udp configuration, the server log file shows the line *TLS: Initial packet from x.x.x.x:x, sid=xxxxxxxx xxxxxxxx*, but the client log does not show an equivalent line.
426
* Solution:
427
* You have a one-way connection from client to server. The server to client direction is blocked by a firewall, usually on the client side. The firewall can either be (a) a personal software firewall running on the client, or (b) the NAT router gateway for the client. Modify the firewall to allow returning UDP packets from the server to reach the client.
428
429
See the [FAQ](/FAQ) for additional troubleshooting information.
430
431
# Configuring OpenVPN to run automatically on system startup
0c0510 Samuli Seppänen 2025-02-11 12:59:17 432
433
The lack of standards in this area means that most OSes have a different way of configuring daemons/services for autostart on boot. The best way to have this functionality configured by default is to install OpenVPN as a package, such as via RPM on Linux or using the Windows installer.
434
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 435
## Linux
436
437
If you install OpenVPN via an RPM or DEB package on Linux, the installer will set up an initscript. When executed, the initscript will scan for .conf configuration files in /etc/openvpn, and if found, will start up a separate OpenVPN daemon for each file.
438
439
## Windows
440
441
The Windows installer will set up a Service Wrapper, but leave it turned off by default. To activate it, go to Control Panel / Administrative Tools / Services, select the OpenVPN service, right-click on properties, and set the Startup Type to Automatic. This will configure the service for automatic start on the next reboot.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 442
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 443
When started, the OpenVPN Service Wrapper will scan the **\Program Files\OpenVPN\config** folder for **.ovpn** configuration files, starting a separate OpenVPN process on each file.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 444
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 445
# Controlling a running OpenVPN process
0c0510 Samuli Seppänen 2025-02-11 12:59:17 446
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 447
## Running on Linux/BSD/Unix
0c0510 Samuli Seppänen 2025-02-11 12:59:17 448
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 449
OpenVPN accepts several signals:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 450
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 451
* **SIGUSR1** -- Conditional restart, designed to restart without root privileges
452
* **SIGHUP** -- Hard restart
453
* **SIGUSR2** -- Output connection statistics to log file or syslog
454
* **SIGTERM, SIGINT** -- Exit
0c0510 Samuli Seppänen 2025-02-11 12:59:17 455
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 456
Use the **writepid** directive to write the OpenVPN daemon's PID to a file, so that you know where to send the signal (if you are starting openvpn with an **initscript**, the script may already be passing a **--writepid** directive on the **openvpn** command line).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 457
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 458
## Running on Windows as a GUI
0c0510 Samuli Seppänen 2025-02-11 12:59:17 459
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 460
See the [OpenVPN-GUI page](/OpenVPN-GUI).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 461
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 462
## Running in a Windows command prompt window
0c0510 Samuli Seppänen 2025-02-11 12:59:17 463
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 464
On Windows, you can start OpenVPN by right clicking on an OpenVPN configuration file (.ovpn file) and selecting "Start OpenVPN on this config file".
0c0510 Samuli Seppänen 2025-02-11 12:59:17 465
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 466
Once running in this fashion, several keyboard commands are available:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 467
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 468
* **F1** -- Conditional restart (doesn't close/reopen TAP adapter)
469
* **F2** -- Show connection statistics
470
* **F3** -- Hard restart
471
* **F4** -- Exit
0c0510 Samuli Seppänen 2025-02-11 12:59:17 472
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 473
## Running as a Windows Service
0c0510 Samuli Seppänen 2025-02-11 12:59:17 474
475
When OpenVPN is started as a service on Windows, the only way to control it is:
476
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 477
* Via the service control manager (Control Panel / Administrative Tools / Services) which gives start/stop control.
478
* Via the management interface (see below).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 479
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 480
## Modifying a live server configuration
0c0510 Samuli Seppänen 2025-02-11 12:59:17 481
482
While most configuration changes require you to restart the server, there are two directives in particular which refer to files which can be dynamically updated on-the-fly, and which will take immediate effect on the server without needing to restart the server process.
483
484
**client-config-dir** -- This directive sets a client configuration directory, which the OpenVPN server will scan on every incoming connection, searching for a client-specific configuration file (see the manual page for more information). Files in this directory can be updated on-the-fly, without restarting the server. Note that changes in this directory will only take effect for new connections, not existing connections. If you would like a client-specific configuration file change to take immediate effect on a currently connected client (or one which has disconnected, but where the server has not timed-out its instance object), kill the client instance object by using the management interface (described below). This will cause the client to reconnect and use the new **client-config-dir** file.
485
486
**crl-verify** -- This directive names a Certificate Revocation List file, described below in the Revoking Certificates section. The CRL file can be modified on the fly, and changes will take effect immediately for new connections, or existing connections which are renegotiating their SSL/TLS channel (occurs once per hour by default). If you would like to kill a currently connected client whose certificate has just been added to the CRL, use the management interface (described below).
487
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 488
## Status File
0c0510 Samuli Seppänen 2025-02-11 12:59:17 489
490
The default [server.conf](https://github.com/OpenVPN/openvpn/blob/master/sample/sample-config-files/server.conf) file has a line
491
```
492
status openvpn-status.log
493
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 494
which will output a list of current client connections to the file **openvpn-status.log** once per minute.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 495
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 496
## Using the management interface
0c0510 Samuli Seppänen 2025-02-11 12:59:17 497
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 498
The [OpenVPN management interface](https://github.com/OpenVPN/openvpn/blob/master/doc/management-notes.txt) allows a great deal of control over a running OpenVPN process. You can use the management interface directly, by telneting to the management interface port, or indirectly by using an OpenVPN GUI which itself connects to the management interface.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 499
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 500
To enable the management interface on either an OpenVPN server or client, add this to the configuration file:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 501
```
502
management localhost 7505
503
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 504
This tells OpenVPN to listen on TCP port 7505 for management interface clients (port 7505 is an arbitrary choice -- you can use any free port).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 505
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 506
Once OpenVPN is running, you can connect to the management interface using a **telnet** client. For example:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 507
508
```
509
ai:~ # telnet localhost 7505
510
Trying 127.0.0.1...
511
Connected to localhost.
512
Escape character is '^]'.
513
>INFO:OpenVPN Management Interface Version 1 -- type 'help' for more info
514
help
515
Management Interface for OpenVPN 2.0_rc14 i686-suse-linux [SSL] [LZO] [EPOLL] built on Feb 15 2005
516
Commands:
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 517
echo [on|off] [N|all] : Like log, but only show messages in echo buffer.
518
exit|quit : Close management session.
519
help : Print this message.
520
hold [on|off|release] : Set/show hold flag to on/off state, or
521
release current hold and start tunnel.
522
kill cn : Kill the client instance(s) having common name cn.
523
kill IP:port : Kill the client instance connecting from IP:port.
524
log [on|off] [N|all] : Turn on/off realtime log display
525
+ show last N lines or 'all' for entire history.
526
mute [n] : Set log mute level to n, or show level if n is absent.
527
net : (Windows only) Show network info and routing table.
528
password type p : Enter password p for a queried OpenVPN password.
529
signal s : Send signal s to daemon,
530
s = SIGHUP|SIGTERM|SIGUSR1|SIGUSR2.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 531
state [on|off] [N|all] : Like log, but show state history.
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 532
status [n] : Show current daemon status info using format #n.
533
test n : Produce n lines of output for testing/debugging.
534
username type u : Enter username u for a queried OpenVPN username.
535
verb [n] : Set log verbosity level to n, or show if n is absent.
536
version : Show current version number.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 537
END
538
exit
539
Connection closed by foreign host.
540
ai:~ #
541
```
542
For more information, see the [OpenVPN Management Interface Documentation](https://github.com/OpenVPN/openvpn/blob/master/doc/management-notes.txt).
543
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 544
# Expanding the scope of the VPN to include additional machines on either the client or server subnet
0c0510 Samuli Seppänen 2025-02-11 12:59:17 545
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 546
## Including multiple machines on the server side when using a routed VPN (dev tun)
0c0510 Samuli Seppänen 2025-02-11 12:59:17 547
548
Once the VPN is operational in a point-to-point capacity between client and server, it may be desirable to expand the scope of the VPN so that clients can reach multiple machines on the server network, rather than only the server machine itself.
549
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 550
For the purpose of this example, we will assume that the server-side LAN uses a subnet of **10.66.0.0/24** and the VPN IP address pool uses **10.8.0.0/24** as cited in the **server** directive in the OpenVPN server configuration file.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 551
552
First, you must advertise the 10.66.0.0/24 subnet to VPN clients as being accessible through the VPN. This can easily be done with the following server-side config file directive:
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 553
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 554
push "route 10.66.0.0 255.255.255.0"
555
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 556
Next, you must set up a route on the server-side LAN gateway to route the VPN client subnet (**10.8.0.0/24**) to the OpenVPN server (this is only necessary if the OpenVPN server and the LAN gateway are different machines).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 557
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 558
Make sure that you've enabled IP and TUN/TAP forwarding on the OpenVPN server machine.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 559
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 560
## Including multiple machines on the server side when using a bridged VPN (dev tap)
0c0510 Samuli Seppänen 2025-02-11 12:59:17 561
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 562
One of the benefits of using ethernet bridging is that you get this for free without needing any additional configuration.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 563
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 564
## Including multiple machines on the client side when using a routed VPN (dev tun)
0c0510 Samuli Seppänen 2025-02-11 12:59:17 565
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 566
In a typical road-warrior or remote access scenario, the client machine connects to the VPN as a single machine. But suppose the client machine is a gateway for a local LAN (such as a home office), and you would like each machine on the client LAN to be able to route through the VPN.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 567
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 568
For this example, we will assume that the client LAN is using the **192.168.4.0/24** subnet, and that the VPN client is using a certificate with a common name of **client2**. Our goal is to set up the VPN so that any machine on the client LAN can communicate with any machine on the server LAN through the VPN.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 569
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 570
Before setup, there are some basic prerequisites, which must be followed:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 571
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 572
* The client LAN subnet (**192.168.4.0/24** in our example) must not be exported to the VPN by the server or any other client sites that are using the same subnet. Every subnet which is joined to the VPN via routing must be unique.
573
* The client must have a unique Common Name in its certificate ("client2" in our example), and the **duplicate-cn** flag must not be used in the OpenVPN server configuration file.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 574
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 575
First, make sure that IP and TUN/TAP forwarding is enabled on the client machine.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 576
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 577
Next, we will deal with the necessary configuration changes on the server side. If the server configuration file does not currently reference a client configuration directory, add one now:
578
```
579
client-config-dir ccd
580
```
581
In the above directive, ccd should be the name of a directory which has been pre-created in the default directory where the OpenVPN server daemon runs. On Linux this tends to be **/etc/openvpn** and on Windows it is usually **\Program Files\OpenVPN\config**. When a new client connects to the OpenVPN server, the daemon will check this directory for a file which matches the common name of the connecting client. If a matching file is found, it will be read and processed for additional configuration file directives to be applied to the named client.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 582
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 583
The next step is to create a file called **client2** in the **ccd** directory. This file should contain the line:
584
```
585
iroute 192.168.4.0 255.255.255.0
586
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 587
This will tell the OpenVPN server that the 192.168.4.0/24 subnet should be routed to **client2**.
588
589
Next, add the following line to the main server config file (not the ccd/client2 file):
590
```
591
route 192.168.4.0 255.255.255.0
592
```
593
Why the redundant **route** and **iroute** statements, you might ask? The reason is that **route** controls the routing from the kernel to the OpenVPN server (via the TUN interface) while **iroute** controls the routing from the OpenVPN server to the remote clients. Both are necessary.
594
595
Next, ask yourself if you would like to allow network traffic between client2's subnet (192.168.4.0/24) and other clients of the OpenVPN server. If so, add the following to the server config file.
596
```
597
client-to-client
598
push "route 192.168.4.0 255.255.255.0"
599
```
600
This will cause the OpenVPN server to *advertise* client2's subnet to other connecting clients.
601
602
The last step, and one that is often forgotten, is to add a route to the server's LAN gateway which directs 192.168.4.0/24 to the OpenVPN server box (you won't need this if the OpenVPN server box is the gateway for the server LAN). Suppose you were missing this step and you tried to ping a machine (not the OpenVPN server itself) on the server LAN from 192.168.4.8? The outgoing ping would probably reach the machine, but then it wouldn't know how to route the ping reply, because it would have no idea how to reach 192.168.4.0/24. The rule of thumb to use is that when routing entire LANs through the VPN (when the VPN server is not the same machine as the LAN gateway), make sure that the gateway for the LAN routes all VPN subnets to the VPN server machine.
603
604
Similarly, if the client machine running OpenVPN is not also the gateway for the client LAN, then the gateway for the client LAN must have a route which directs all subnets which should be reachable through the VPN to the OpenVPN client machine.
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 605
## Including multiple machines on the client side when using a bridged VPN (dev tap)
0c0510 Samuli Seppänen 2025-02-11 12:59:17 606
607
This requires a more complex setup (maybe not more complex in practice, but more complicated to explain in detail):
608
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 609
* You must bridge the client TAP interface with the LAN-connected NIC on the client.
610
* You must manually set the IP/netmask of the TAP interface on the client.
611
* You must configure client-side machines to use an IP/netmask that is inside of the bridged subnet, possibly by querying a DHCP server on the OpenVPN server side of the VPN.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 612
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 613
# Pushing DHCP options to clients
0c0510 Samuli Seppänen 2025-02-11 12:59:17 614
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 615
The OpenVPN server can push DHCP options such as DNS and WINS server addresses to clients. Windows clients can accept pushed DHCP options natively, while non-Windows clients can accept them by using a client-side `--up` script which parses the `foreign_option_n` environmental variable list. See [Using DNS servers pushed to clients](https://community.openvpn.net/openvpn/wiki/Pushing-DNS-to-clients).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 616
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 617
For example, suppose you would like connecting clients to use an internal DNS server at 10.66.0.4 or 10.66.0.5 and a WINS server at 10.66.0.8. Add this to the OpenVPN server configuration:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 618
```
619
push "dhcp-option DNS 10.66.0.4"
620
push "dhcp-option DNS 10.66.0.5"
621
push "dhcp-option WINS 10.66.0.8"
622
```
623
To test this feature on Windows, run the following from a command prompt window after the machine has connected to an OpenVPN server:
624
```
625
ipconfig /all
626
```
627
The entry for the TAP-Windows adapter should show the DHCP options which were pushed by the server.
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 628
# Configuring client-specific rules and access policies
0c0510 Samuli Seppänen 2025-02-11 12:59:17 629
630
Suppose we are setting up a company VPN, and we would like to establish separate access policies for 3 different classes of users:
631
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 632
* **System administrators** -- full access to all machines on the network
633
* **Employees** -- access only to Samba/email server
634
* **Contractors** -- access to a special server only
0c0510 Samuli Seppänen 2025-02-11 12:59:17 635
636
The basic approach we will take is (a) segregate each user class into its own virtual IP address range, and (b) control access to machines by setting up firewall rules which key off the client's virtual IP address.
637
638
In our example, suppose that we have a variable number of employees, but only one system administrator, and two contractors. Our IP allocation approach will be to put all employees into an IP address pool, and then allocate fixed IP addresses for the system administrator and contractors.
639
640
Note that one of the prerequisites of this example is that you have a software firewall running on the OpenVPN server machine which gives you the ability to define specific firewall rules. For our example, we will assume the firewall is Linux **iptables**.
641
642
First, let's create a virtual IP address map according to user class:
643
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 644
|**Class**|**Virtual IP Range**|**Allowed LAN Access**|**Common Names**|
645
|-|-|-|-|
646
|Employees|10.8.0.0/24|Samba/email server at 10.66.4.4|[variable]|
647
|System Administrators|10.8.1.0/24|Entire 10.66.4.0/24 subnet|sysadmin1|
648
|Contractors|10.8.2.0/24|Contractor server at 10.66.4.12|contractor1, contracter2|
0c0510 Samuli Seppänen 2025-02-11 12:59:17 649
650
Next, let's translate this map into an OpenVPN server configuration. First of all, make sure you've followed the steps above for making the 10.66.4.0/24 subnet available to all clients (while we will configure routing to allow client access to the entire 10.66.4.0/24 subnet, we will then impose access restrictions using firewall rules to implement the above policy table).
651
652
First, define a static unit number for our tun interface, so that we will be able to refer to it later in our firewall rules:
653
```
654
dev tun0
655
```
656
In the server configuration file, define the Employee IP address pool:
657
```
658
server 10.8.0.0 255.255.252.0
659
```
660
Add routes for the System Administrator and Contractor IP ranges:
661
```
662
route 10.8.1.0 255.255.255.0
663
route 10.8.2.0 255.255.255.0
664
```
665
Because we will be assigning fixed IP addresses for specific System Administrators and Contractors, we will use a client configuration directory:
666
```
667
client-config-dir ccd
668
```
669
Now place special configuration files in the ccd subdirectory to define the fixed IP address for each non-Employee VPN client.
670
```
671
ccd/sysadmin1
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 672
673
ifconfig-push 10.8.1.2 10.8.1.1
0c0510 Samuli Seppänen 2025-02-11 12:59:17 674
675
ccd/contractor1
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 676
677
ifconfig-push 10.8.2.2 10.8.2.1
0c0510 Samuli Seppänen 2025-02-11 12:59:17 678
679
ccd/contractor2
680
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 681
ifconfig-push 10.8.2.6 10.8.2.5
0c0510 Samuli Seppänen 2025-02-11 12:59:17 682
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 683
Each pair of **ifconfig-push** addresses represent the virtual client and server IP endpoints. They must be taken from successive /30 subnets in order to be compatible with Windows clients and the TAP-Windows driver. Specifically, the last octet in the IP address of each endpoint pair must be taken from this set:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 684
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 685
[ 1, 2] [ 5, 6] [ 9, 10] [ 13, 14] [ 17, 18]
0c0510 Samuli Seppänen 2025-02-11 12:59:17 686
[ 21, 22] [ 25, 26] [ 29, 30] [ 33, 34] [ 37, 38]
687
[ 41, 42] [ 45, 46] [ 49, 50] [ 53, 54] [ 57, 58]
688
[ 61, 62] [ 65, 66] [ 69, 70] [ 73, 74] [ 77, 78]
689
[ 81, 82] [ 85, 86] [ 89, 90] [ 93, 94] [ 97, 98]
690
[101,102] [105,106] [109,110] [113,114] [117,118]
691
[121,122] [125,126] [129,130] [133,134] [137,138]
692
[141,142] [145,146] [149,150] [153,154] [157,158]
693
[161,162] [165,166] [169,170] [173,174] [177,178]
694
[181,182] [185,186] [189,190] [193,194] [197,198]
695
[201,202] [205,206] [209,210] [213,214] [217,218]
696
[221,222] [225,226] [229,230] [233,234] [237,238]
697
[241,242] [245,246] [249,250] [253,254]
698
```
699
This completes the OpenVPN configuration. The final step is to add firewall rules to finalize the access policy. For this example, we will use firewall rules in the Linux iptables syntax:
700
```
701
# Employee rule
702
iptables -A FORWARD -i tun0 -s 10.8.0.0/24 -d 10.66.4.4 -j ACCEPT
703
704
# Sysadmin rule
705
iptables -A FORWARD -i tun0 -s 10.8.1.0/24 -d 10.66.4.0/24 -j ACCEPT
706
707
# Contractor rule
708
iptables -A FORWARD -i tun0 -s 10.8.2.0/24 -d 10.66.4.12 -j ACCEPT
709
710
# Close remaining of /22 tunnel
711
iptables -A FORWARD -i tun0 -s 10.8.3.0/24 -j DROP
712
```
713
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 714
# Using alternative authentication methods
0c0510 Samuli Seppänen 2025-02-11 12:59:17 715
716
OpenVPN 2.0 and later include a feature that allows the OpenVPN server to securely obtain a username and password from a connecting client, and to use that information as a basis for authenticating the client.
717
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 718
To use this authentication method, first add the **auth-user-pass** directive to the client configuration. It will direct the OpenVPN client to query the user for a username/password, passing it on to the server over the secure TLS channel.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 719
720
Next, configure the server to use an authentication plugin, which may be a script, shared object, or DLL. The OpenVPN server will call the plugin every time a VPN client tries to connect, passing it the username/password entered on the client. The authentication plugin can control whether or not the OpenVPN server allows the client to connect by returning a failure (1) or success (0) value.
721
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 722
## Using Script Plugins
0c0510 Samuli Seppänen 2025-02-11 12:59:17 723
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 724
Script plugins can be used by adding the auth-user-pass-verify directive to the server-side configuration file. For example:
725
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 726
auth-user-pass-verify auth-pam.pl via-file
727
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 728
will use the auth-pam.pl perl script to authenticate the username/password of connecting clients. See the description of **auth-user-pass-verify** in the manual page for more information.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 729
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 730
The **auth-pam.pl** script is included in the OpenVPN source file distribution in the sample-scripts subdirectory. It will authenticate users on a Linux server using a PAM authentication module, which could in turn implement shadow password, RADIUS, or LDAP authentication. auth-pam.pl is primarily intended for demonstration purposes. For real-world PAM authentication, use the openvpn-auth-pam shared object plugin described below.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 731
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 732
## Using Shared Object or DLL Plugins
0c0510 Samuli Seppänen 2025-02-11 12:59:17 733
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 734
Shared object or DLL plugins are usually compiled C modules which are loaded by the OpenVPN server at run time. For example if you are using an RPM-based OpenVPN package on Linux, the **openvpn-auth-pam** plugin should be already built. To use it, add this to the server-side config file:
735
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 736
plugin /usr/share/openvpn/plugin/lib/openvpn-auth-pam.so login
737
```
738
This will tell the OpenVPN server to validate the username/password entered by clients using the login PAM module.
739
740
For real-world production use, it's better to use the **openvpn-auth-pam** plugin, because it has several advantages over the **auth-pam.pl** script:
741
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 742
* The shared object **openvpn-auth-pam** plugin uses a split-privilege execution model for better security. This means that the OpenVPN server can run with reduced privileges by using the directives user **nobody, group nobody**, and **chroot**, and will still be able to authenticate against the root-readable-only shadow password file.
743
* OpenVPN can pass the username/password to a plugin via virtual memory, rather than via a file or the environment, which is better for local security on the server machine.
744
* C-compiled plugin modules generally run faster than scripts.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 745
746
If you would like more information on developing your own plugins for use with OpenVPN, see the **README** files in the **plugin** subdirectory of the OpenVPN source distribution.
747
748
To build the **openvpn-auth-pam** plugin on Linux, cd to the **plugin/auth-pam** directory in the OpenVPN source distribution and run make.
749
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 750
## Using username/password authentication as the only form of client authentication
0c0510 Samuli Seppänen 2025-02-11 12:59:17 751
752
By default, using **auth-user-pass-verify** or a username/password-checking **plugin** on the server will enable dual authentication, requiring that both client-certificate and username/password authentication succeed in order for the client to be authenticated.
753
754
While it is discouraged from a security perspective, it is also possible to disable the use of client certificates, and force username/password authentication only. On the server:
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 755
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 756
client-cert-not-required
757
```
758
Such configurations should usually also set:
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 759
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 760
username-as-common-name
761
```
762
which will tell the server to use the username for indexing purposes as it would use the Common Name of a client which was authenticating via a client certificate.
763
764
Note that **client-cert-not-required** will not obviate the need for a server certificate, so a client connecting to a server which uses **client-cert-not-required** may remove the **cert** and **key** directives from the client configuration file, but not the ca directive, because it is necessary for the client to verify the server certificate.
765
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 766
# How to add dual-factor authentication to an OpenVPN configuration using client-side smart cards
767
768
Also see Article: [The OpenVPN Smartcard HOWTO](http://acksyn.org/docs/smart-cards-openvpn.html).
769
770
## About dual-factor authentication
771
772
Dual-factor authentication is a method of authentication that combines two elements: something you have and something you know.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 773
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 774
Something you have should be a device that cannot be duplicated; such a device can be a cryptographic token that contains a private secret key. This private key is generated inside the device and never leaves it. If a user possessing this token attempts to access protected services on a remote network, the authorization process which grants or denies network access can establish, with a high degree of certainty, that the user seeking access is in physical possession of a known, certified token.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 775
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 776
Something you know can be a password presented to the cryptographic device. Without presenting the proper password you cannot access the private secret key. Another feature of cryptographic devices is to prohibit the use of the private secret key if the wrong password had been presented more than an allowed number of times. This behavior ensures that if a user lost his device, it would be infeasible for another person to use it.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 777
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 778
Cryptographic devices are commonly called "smart cards" or "tokens", and are used in conjunction with a PKI (Public Key Infrastructure). The VPN server can examine a X.509 certificate and verify that the user holds the corresponding private secret key. Since the device cannot be duplicated and requires a valid password, the server is able to authenticate the user with a high degree of confidence.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 779
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 780
Dual-factor authentication is much stronger than password-based authentication, because in the worst-case scenario, only one person at a time can use the cryptographic token. Passwords can be guessed and can be exposed to other users, so in the worst-case scenario an infinite number of people could attempt to gain unauthorized access when resources are protected using password-only authentication.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 781
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 782
If you store the secret private key in a file, the key is usually encrypted by a password. The problem with this approach is that the encrypted key is exposed to decryption attacks or spyware/malware running on the client machine. Unlike when using a cryptographic device, the file cannot erase itself automatically after several failed decryption attempts.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 783
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 784
## What is PKCS#11?
0c0510 Samuli Seppänen 2025-02-11 12:59:17 785
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 786
*This standard specifies an API, called Cryptoki, to devices which hold cryptographic information and perform cryptographic functions. Cryptoki, pronounced "crypto-key" and short for cryptographic token interface, follows a simple object-based approach, addressing the goals of technology independence (any kind of device) and resource sharing (multiple applications accessing multiple devices), presenting to applications a common, logical view of the device called a cryptographic token.*
0c0510 Samuli Seppänen 2025-02-11 12:59:17 787
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 788
Source: RSA Security Inc. (https://www.emc.com/emc-plus/rsa-labs/standards-initiatives/pkcs-11-cryptographic-token-interface-standard.htm).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 789
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 790
To summarize, PKCS!#11 is a standard that can be used by application software to access cryptographic tokens such as smart cards and other devices. Most device vendors provide a library that implements the PKCS!#11 provider interface -- this library can be used by applications in order to access these devices. PKCS!#11 is a cross-platform, vendor-independent free standard.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 791
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 792
## Finding PKCS#11 provider library
0c0510 Samuli Seppänen 2025-02-11 12:59:17 793
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 794
The first thing you need to do is to find the provider library, it should be installed with the device drivers. Each vendor has its own library. For example, the OpenSC PKCS!#11 provider is located at /usr/lib/pkcs11/opensc-pkcs11.so on Unix or at opensc-pkcs11.dll on Windows.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 795
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 796
## How to configure cryptographic token
0c0510 Samuli Seppänen 2025-02-11 12:59:17 797
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 798
You should follow an enrollment procedure:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 799
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 800
* Initialize the PKCS!#11 token.
801
* Generate RSA key pair on the PKCS!#11 token.
802
* Create a certificate request based on the key pair, you can use OpenSC and OpenSSL in order to do that.
803
* Submit the certificate request to a certificate authority, and receive a certificate.
804
* Load the certificate onto the token, while noting that the id and label attributes of the certificate must match those of the private key.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 805
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 806
A configured token is a token that has a private key object and a certificate object, where both share the same id and label attributes.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 807
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 808
A simple enrollment utility is Easy-RSA 2.0 which is part of OpenVPN 2.1 series. Follow the instructions specified in the README file, and then use the pkitool in order to enroll.
809
810
Initialize a token using the following command:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 811
```
812
$ ./pkitool --pkcs11-slots /usr/lib/pkcs11/
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 813
$ ./pkitool --pkcs11-init /usr/lib/pkcs11/
0c0510 Samuli Seppänen 2025-02-11 12:59:17 814
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 815
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 816
Enroll a certificate using the following command:
817
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 818
$ ./pkitool --pkcs11 /usr/lib/pkcs11/ client1
0c0510 Samuli Seppänen 2025-02-11 12:59:17 819
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 820
## How to modify an OpenVPN configuration to make use of cryptographic tokens
0c0510 Samuli Seppänen 2025-02-11 12:59:17 821
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 822
You should have OpenVPN 2.1 or above in order to use the PKCS!#11 features.
823
### Determine the correct object
0c0510 Samuli Seppänen 2025-02-11 12:59:17 824
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 825
Each PKCS#11 provider can support multiple devices. In order to view the available object list you can use the following command:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 826
827
```
828
$ openvpn --show-pkcs11-ids /usr/lib/pkcs11/
829
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 830
The following objects are available for use.
831
Each object shown below may be used as parameter to
832
--pkcs11-id option please remember to use single quote mark.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 833
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 834
Certificate
835
DN: /CN=User1
836
Serial: 490B82C4000000000075
837
Serialized id: aaaa/bbb/41545F5349474E415455524581D2A1A1B23C4AA4CB17FAF7A4600
838
```
839
Each certificate/private key pair have unique "Serialized id" string. The serialized id string of the requested certificate should be specified to the **pkcs11-id** option using single quote marks.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 840
```
841
pkcs11-id 'aaaa/bbb/41545F5349474E415455524581D2A1A1B23C4AA4CB17FAF7A4600'
842
```
843
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 844
### Using OpenVPN with PKCS#11
0c0510 Samuli Seppänen 2025-02-11 12:59:17 845
846
A typical set of OpenVPN options for PKCS!#11:
847
```
848
pkcs11-providers /usr/lib/pkcs11/
849
pkcs11-id 'aaaa/bbb/41545F5349474E415455524581D2A1A1B23C4AA4CB17FAF7A4600'
850
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 851
This will select the object which matches the pkcs11-id string.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 852
853
**Advanced OpenVPN options for PKCS#11**
854
```
855
pkcs11-providers /usr/lib/pkcs11/provider1.so /usr/lib/pkcs11/provider2.so
856
pkcs11-id 'aaaa/bbb/41545F5349474E415455524581D2A1A1B23C4AA4CB17FAF7A4600'
857
pkcs11-pin-cache 300
858
daemon
859
auth-retry nointeract
860
management-hold
861
management-signal
862
management 127.0.0.1 8888
863
management-query-passwords
864
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 865
This will load two providers into OpenVPN, use the certificate specified on **pkcs11-id** option, and use the management interface in order to query passwords. The daemon will resume into hold state on the event when token cannot be accessed. The token will be used for 300 seconds after which the password will be re-queried, session will disconnect if management session disconnects.
866
### PKCS#11 implementation considerations
0c0510 Samuli Seppänen 2025-02-11 12:59:17 867
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 868
Many PKCS!#11 providers make use of threads, in order to avoid problems caused by implementation of !LinuxThreads (setuid, chroot), it is highly recommend to upgrade to Native POSIX Thread Library (NPTL) enabled glibc if you intend to use PKCS!#11.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 869
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 870
### OpenSC PKCS#11 provider
0c0510 Samuli Seppänen 2025-02-11 12:59:17 871
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 872
OpenSC PKCS!#11 provider is located at /usr/lib/pkcs11/opensc-pkcs11.so on Unix or at opensc-pkcs11.dll on Windows.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 873
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 874
## Difference between PKCS#11 and Microsoft Cryptographic API (CryptoAPI)
0c0510 Samuli Seppänen 2025-02-11 12:59:17 875
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 876
PKCS!#11 is a free, cross-platform vendor independent standard. CryptoAPI is a Microsoft specific API. Most smart card vendors provide support for both interfaces. In the Windows environment, the user should select which interface to use.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 877
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 878
The current implementation of OpenVPN that uses the MS CryptoAPI (**cryptoapicert** option) works well as long as you don't run OpenVPN as a service. If you wish to run OpenVPN in an administrative environment using a service, the implementation will not work with most smart cards because of the following reasons:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 879
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 880
* Most smart card providers do not load certificates into the local machine store, so the implementation will be unable to access the user certificate.
881
* If the OpenVPN client is running as a service without direct interaction with the end-user, the service cannot query the user to provide a password for the smart card, causing the password-verification process on the smart card to fail.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 882
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 883
Using the PKCS!#11 interface, you can use smart cards with OpenVPN in any implementation, since PKCS!#11 does not access Microsoft stores and does not necessarily require direct interaction with the end-user.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 884
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 885
# Routing all client traffic (including web-traffic) through the VPN
0c0510 Samuli Seppänen 2025-02-11 12:59:17 886
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 887
## Overview
0c0510 Samuli Seppänen 2025-02-11 12:59:17 888
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 889
By default, when an OpenVPN client is active, only network traffic to and from the OpenVPN server site will pass over the VPN. General web browsing, for example, will be accomplished with direct connections that bypass the VPN.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 890
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 891
In certain cases this behavior might not be desirable -- you might want a VPN client to tunnel all network traffic through the VPN, including general internet web browsing. While this type of VPN configuration will exact a performance penalty on the client, it gives the VPN administrator more control over security policies when a client is simultaneously connected to both the public internet and the VPN at the same time.
892
## Implementation
0c0510 Samuli Seppänen 2025-02-11 12:59:17 893
894
Add the following directive to the server configuration file:
895
```
896
push "redirect-gateway def1"
897
```
898
If your VPN setup is over a wireless network, where all clients and the server are on the same wireless subnet, add the local flag:
899
```
900
push "redirect-gateway local def1"
901
```
902
Pushing the **redirect-gateway** option to clients will cause all IP network traffic originating on client machines to pass through the OpenVPN server. The server will need to be configured to deal with this traffic somehow, such as by NATing it to the internet, or routing it through the server site's HTTP proxy.
903
904
On Linux, you could use a command such as this to NAT the VPN client traffic to the internet:
905
```
906
iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
907
```
908
This command assumes that the VPN subnet is **10.8.0.0/24** (taken from the **server** directive in the OpenVPN server configuration) and that the local ethernet interface is **eth0**.
909
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 910
When **redirect-gateway** is used, OpenVPN clients will route DNS queries through the VPN, and the VPN server will need handle them. This can be accomplished by pushing a DNS server address to connecting clients which will replace their normal DNS server settings during the time that the VPN is active. For example:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 911
```
912
push "dhcp-option DNS 10.8.0.1"
913
```
914
will configure Windows clients (or non-Windows clients with some extra server-side scripting) to use 10.8.0.1 as their DNS server. Any address which is reachable from clients may be used as the DNS server address.
915
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 916
## Caveats
0c0510 Samuli Seppänen 2025-02-11 12:59:17 917
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 918
Redirecting all network traffic through the VPN is not entirely a problem-free proposition. Here are some typical gotchas to be aware of:
919
920
* Many OpenVPN client machines connecting to the internet will periodically interact with a DHCP server to renew their IP address leases. The **redirect-gateway** option might prevent the client from reaching the local DHCP server (because DHCP messages would be routed over the VPN), causing it to lose its IP address lease.
921
* [Issues exist](/279-are-there-any-issues-related-to-pushing-dhcp-options-to-windows-clients) with respect to pushing DNS addresses to Windows clients.
922
* Web browsing performance on the client will be noticeably slower.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 923
924
For more information on the mechanics of the **redirect-gateway** directive, see the manual page.
925
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 926
# Running an OpenVPN server on a dynamic IP address
0c0510 Samuli Seppänen 2025-02-11 12:59:17 927
928
While OpenVPN clients can easily access the server via a dynamic IP address without any special configuration, things get more interesting when the server itself is on a dynamic address. While OpenVPN has no trouble handling the situation of a dynamic server, some extra configuration is required.
929
930
The first step is to get a dynamic DNS address which can be configured to "follow" the server every time the server's IP address changes. There are several dynamic DNS service providers available from which to choose.
931
932
The next step is to set up a mechanism so that every time the server's IP address changes, the dynamic DNS name will be quickly updated with the new IP address, allowing clients to find the server at its new IP address. There are two basic ways to accomplish this:
933
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 934
* Use a NAT router appliance with dynamic DNS support (such as the Linksys BEFSR41). Most of the inexpensive NAT router appliances that are widely available have the capability to update a dynamic DNS name every time a new DHCP lease is obtained from the ISP. This setup is ideal when the OpenVPN server box is a single-NIC machine inside the firewall.
935
* Use a dynamic DNS client application such as ddclient to update the dynamic DNS address whenever the server IP address changes. This setup is ideal when the machine running OpenVPN has multiple NICs and is acting as a site-wide firewall/gateway. To implement this setup, you need to set up a script to be run by your DHCP client software every time an IP address change occurs. This script should (a) run ddclient to notify your dynamic DNS provider of your new IP address and (b) restart the OpenVPN server daemon.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 936
937
The OpenVPN client by default will sense when the server's IP address has changed, if the client configuration is using a **remote** directive which references a dynamic DNS name. The usual chain of events is that (a) the OpenVPN client fails to receive timely keepalive messages from the server's old IP address, triggering a restart, and (b) the restart causes the DNS name in the **remote** directive to be re-resolved, allowing the client to reconnect to the server at its new IP address.
938
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 939
More information can be found in the [FAQ](/FAQ).
0c0510 Samuli Seppänen 2025-02-11 12:59:17 940
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 941
# Connecting to an OpenVPN server via an HTTP proxy
0c0510 Samuli Seppänen 2025-02-11 12:59:17 942
943
OpenVPN supports connections through an HTTP proxy, with the following authentication modes:
944
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 945
* No proxy authentication
946
* Basic proxy authentication
947
* NTLM proxy authentication
0c0510 Samuli Seppänen 2025-02-11 12:59:17 948
949
First of all, HTTP proxy usage requires that you use TCP as the tunnel carrier protocol. So add the following to both client and server configurations:
950
```
951
proto tcp
952
```
953
Make sure that any **proto udp** lines in the config files are deleted.
954
955
Next, add the **http-proxy** directive to the client configuration file (see the manual page for a full description of this directive).
956
957
For example, suppose you have an HTTP proxy server on the client LAN at **192.168.4.1**, which is listening for connections on port **1080**. Add this to the client config:
958
```
959
http-proxy 192.168.4.1 1080
960
```
961
Suppose the HTTP proxy requires Basic authentication:
962
```
963
http-proxy 192.168.4.1 1080 stdin basic
964
```
965
Suppose the HTTP proxy requires NTLM authentication:
966
```
967
http-proxy 192.168.4.1 1080 stdin ntlm
968
```
969
The two authentication examples above will cause OpenVPN to prompt for a username/password from standard input. If you would instead like to place these credentials in a file, replace **stdin** with a filename, and place the username on line 1 of this file and the password on line 2.
970
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 971
# Connecting to a Samba share over OpenVPN
0c0510 Samuli Seppänen 2025-02-11 12:59:17 972
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 973
This example is intended show how OpenVPN clients can connect to a Samba share over a routed **dev tun** tunnel. If you are ethernet bridging (**dev tap**), you probably don't need to follow these instructions, as OpenVPN clients should see server-side machines in their network neighborhood.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 974
975
For this example, we will assume that:
976
977
* the server-side LAN uses a subnet of **10.66.0.0/24**,
978
* the VPN IP address pool uses **10.8.0.0/24** (as cited in the **server** directive in the OpenVPN server configuration file),
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 979
* the Samba server has an IP address of **10.66.0.4**, and
980
* the Samba server has already been configured and is reachable from the local LAN.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 981
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 982
If the Samba and OpenVPN servers are running on different machines, make sure you've followed the section on expanding the scope of the VPN to include additional machines.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 983
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 984
Next, edit your Samba configuration file (**smb.conf**). Make sure the hosts allow directive will permit OpenVPN clients coming from the **10.8.0.0/24** subnet to connect. For example:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 985
```
986
hosts allow = 10.66.0.0/24 10.8.0.0/24 127.0.0.1
987
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 988
If you are running the Samba and OpenVPN servers on the same machine, you may want to edit the **interfaces** directive in the **smb.conf** file to also listen on the TUN interface subnet of **10.8.0.0/24**:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 989
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 990
interfaces = 10.66.0.0/24 10.8.0.0/24
0c0510 Samuli Seppänen 2025-02-11 12:59:17 991
```
992
If you are running the Samba and OpenVPN servers on the same machine, connect from an OpenVPN client to a Samba share using the folder name:
993
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 994
\\10.8.0.1\\sharename
0c0510 Samuli Seppänen 2025-02-11 12:59:17 995
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 996
If the Samba and OpenVPN servers are on different machines, use folder name:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 997
```
998
\\10.66.0.4\sharename
999
```
1000
For example, from a command prompt window:
1001
```
1002
net use z: \\10.66.0.4\sharename /USER:myusername
1003
```
1004
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1005
# Implementing a load-balancing/failover configuration
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1006
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1007
## Client
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1008
1009
The OpenVPN client configuration can refer to multiple servers for load balancing and failover. For example:
1010
```
1011
remote server1.mydomain
1012
remote server2.mydomain
1013
remote server3.mydomain
1014
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1015
will direct the OpenVPN client to attempt a connection with server1, server2, and server3 in that order. If an existing connection is broken, the OpenVPN client will retry the most recently connected server, and if that fails, will move on to the next server in the list. You can also direct the OpenVPN client to randomize its server list on startup, so that the client load will be probabilistically spread across the server pool.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1016
```
1017
remote-random
1018
```
1019
If you would also like DNS resolution failures to cause the OpenVPN client to move to the next server in the list, add the following:
1020
```
1021
resolv-retry 60
1022
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1023
The **60** parameter tells the OpenVPN client to try resolving each remote DNS name for 60 seconds before moving on to the next server in the list.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1024
1025
The server list can also refer to multiple OpenVPN server daemons running on the same machine, each listening for connections on a different port, for example:
1026
```
1027
remote smp-server1.mydomain 8000
1028
remote smp-server1.mydomain 8001
1029
remote smp-server2.mydomain 8000
1030
remote smp-server2.mydomain 8001
1031
```
1032
If your servers are multi-processor machines, running multiple OpenVPN daemons on each server can be advantageous from a performance standpoint.
1033
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1034
OpenVPN also supports the remote directive referring to a DNS name which has multiple **A** records in the zone configuration for the domain. In this case, the OpenVPN client will randomly choose one of the **A** records every time the domain is resolved.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1035
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1036
## Server
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1037
1038
The simplest approach to a load-balanced/failover configuration on the server is to use equivalent configuration files on each server in the cluster, except use a different virtual IP address pool for each server. For example:
1039
```
1040
server1
1041
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1042
server 10.8.0.0 255.255.255.0
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1043
1044
server2
1045
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1046
server 10.8.1.0 255.255.255.0
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1047
1048
server3
1049
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1050
server 10.8.2.0 255.255.255.0
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1051
```
1052
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1053
# Hardening OpenVPN Security
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1054
1055
One of the often-repeated maxims of network security is that one should never place so much trust in a single security component that its failure causes a catastrophic security breach. OpenVPN provides several mechanisms to add additional security layers to hedge against such an outcome.
1056
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1057
## tls-auth
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1058
1059
The **tls-auth** directive adds an additional HMAC signature to all SSL/TLS handshake packets for integrity verification. Any UDP packet not bearing the correct HMAC signature can be dropped without further processing. The tls-auth HMAC signature provides an additional level of security above and beyond that provided by SSL/TLS. It can protect against:
1060
1061
* DoS attacks or port flooding on the OpenVPN UDP port.
1062
* Port scanning to determine which server UDP ports are in a listening state.
1063
* Buffer overflow vulnerabilities in the SSL/TLS implementation.
1064
* SSL/TLS handshake initiations from unauthorized machines (while such handshakes would ultimately fail to authenticate, **tls-auth** can cut them off at a much earlier point).
1065
1066
Using **tls-auth** requires that you generate a shared-secret key that is used in addition to the standard RSA certificate/key:
1067
```
1068
openvpn --genkey --secret ta.key
87ac55 Samuli Seppänen 2025-02-11 13:10:09 1069
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1070
This command will generate an OpenVPN static key and write it to the file **ta.key**. This key should be copied over a pre-existing secure channel to the server and all client machines. It can be placed in the same directory as the RSA **.key** and **.crt** files.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1071
1072
In the server configuration, add:
1073
```
1074
tls-auth ta.key 0
1075
```
1076
In the client configuration, add:
1077
```
1078
tls-auth ta.key 1
1079
```
1080
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1081
## proto udp
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1082
1083
While OpenVPN allows either the TCP or UDP protocol to be used as the VPN carrier connection, the UDP protocol will provide better protection against DoS attacks and port scanning than TCP:
1084
```
1085
proto udp
1086
```
1087
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1088
## user/group (non-Windows only)
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1089
1090
OpenVPN has been very carefully designed to allow root privileges to be dropped after initialization, and this feature should always be used on Linux/BSD/Solaris. Without root privileges, a running OpenVPN server daemon provides a far less enticing target to an attacker.
1091
```
1092
user nobody
1093
group nobody
1094
```
1095
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1096
## Unprivileged mode (Linux only)
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1097
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1098
On Linux OpenVPN can be run completely unprivileged. This configuration is a little more complex, but provides best security.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1099
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1100
In order to work with this configuration, OpenVPN must be configured to use iproute interface, this is done by specifying --enable-iproute2 to configure script. sudo package should also be available on your system.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1101
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1102
This configuration uses the Linux ability to change the permission of a tun device, so that unprivileged user may access it. It also uses sudo in order to execute iproute so that interface properties and routing table may be modified.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1103
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1104
**OpenVPN configuration:**
87ac55 Samuli Seppänen 2025-02-11 13:10:09 1105
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1106
Write the following script and place it at: /usr/local/sbin/unpriv-ip:
1107
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1108
#!/bin/sh
1109
sudo /sbin/ip $*
1110
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1111
Execute visudo, and add the followings to allow user 'user1' to execute /sbin/ip:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1112
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1113
user1 ALL=(ALL) NOPASSWD: /sbin/ip
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1114
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1115
You can also enable a group of users with the following command:
87ac55 Samuli Seppänen 2025-02-11 13:10:09 1116
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1117
```
1118
%users ALL=(ALL) NOPASSWD: /sbin/ip
1119
```
1120
Add the following to your OpenVPN configuration:
1121
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1122
dev tunX/tapX
1123
iproute /usr/local/sbin/unpriv-ip
1124
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1125
Please note that you must select constant X and specify tun or tap not both.
87ac55 Samuli Seppänen 2025-02-11 13:10:09 1126
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1127
As root add persistent interface, and permit user and/or group to manage it, the following create tunX (replace with your own) and allow user1 and group users to access it.
1128
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1129
openvpn --mktun --dev tunX --dev-type tun --user user1 --group users
1130
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1131
Run OpenVPN in the context of the unprivileged user.
87ac55 Samuli Seppänen 2025-02-11 13:10:09 1132
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1133
Further security constraints may be added by examining the parameters at the /usr/local/sbin/unpriv-ip script.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1134
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1135
## chroot (non-Windows only)
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1136
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1137
The **chroot** directive allows you to lock the OpenVPN daemon into a so-called chroot jail, where the daemon would not be able to access any part of the host system's filesystem except for the specific directory given as a parameter to the directive. For example,
1138
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1139
chroot jail
1140
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1141
would cause the OpenVPN daemon to cd into the **jail** subdirectory on initialization, and would then reorient its root filesystem to this directory so that it would be impossible thereafter for the daemon to access any files outside of **jail** and its subdirectory tree. This is important from a security perspective, because even if an attacker were able to compromise the server with a code insertion exploit, the exploit would be locked out of most of the server's filesystem.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1142
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1143
Caveats: because **chroot** reorients the filesystem (from the perspective of the daemon only), it is necessary to place any files which OpenVPN might need after initialization in the **jail** directory, such as:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1144
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1145
* the crl-verify file, or
1146
* the client-config-dir directory.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1147
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1148
## Larger RSA keys
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1149
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1150
The RSA key size is controlled by the **KEY_SIZE** variable in the **easy-rsa/vars** file, which must be set before any keys are generated. Currently set to 1024 by default, this value can reasonably be increased to 2048 with no negative impact on VPN tunnel performance, except for a slightly slower SSL/TLS renegotiation handshake which occurs once per client per hour, and a much slower one-time Diffie Hellman parameters generation process using the **easy-rsa/build-dh** script.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1151
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1152
## Larger symmetric keys
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1153
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1154
By default OpenVPN uses **Blowfish**, a 128 bit symmetrical cipher.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1155
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1156
OpenVPN automatically supports any cipher which is supported by the OpenSSL library, and as such can support ciphers which use large key sizes. For example, the 256-bit version of AES (Advanced Encryption Standard) can be used by adding the following to both server and client configuration files:
1157
```
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1158
cipher AES-256-CBC
1159
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1160
## Keep the root key (ca.key) on a standalone machine without a network connection
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1161
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1162
One of the security benefits of using an X509 PKI (as OpenVPN does) is that the root CA key (ca.key) need not be present on the OpenVPN server machine. In a high security environment, you might want to specially designate a machine for key signing purposes, keep the machine well-protected physically, and disconnect it from all networks. Floppy disks can be used to move key files back and forth, as necessary. Such measures make it extremely difficult for an attacker to steal the root key, short of physical theft of the key signing machine.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1163
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1164
# Revoking Certificates
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1165
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1166
*Revoking a certificate* means to invalidate a previously signed certificate so that it can no longer be used for authentication purposes.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1167
1168
Typical reasons for wanting to revoke a certificate include:
1169
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1170
* The private key associated with the certificate is compromised or stolen.
1171
* The user of an encrypted private key forgets the password on the key.
1172
* You want to terminate a VPN user's access.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1173
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1174
## Example
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1175
1176
As an example, we will revoke the **client2** certificate, which we generated above in the "key generation" section of the HOWTO.
1177
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1178
First open up a shell or command prompt window and cd to the **easy-rsa** directory as you did in the "key generation" section above. On Linux/BSD/Unix:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1179
```
1180
. ./vars
1181
./revoke-full client2
1182
```
1183
On Windows:
1184
```
1185
vars
1186
revoke-full client2
1187
```
1188
You should see output similar to this:
1189
```
1190
Using configuration from /root/openvpn/20/openvpn/tmp/easy-rsa/openssl.cnf
1191
DEBUG[load_index]: unique_subject = "yes"
1192
Revoking Certificate 04.
1193
Data Base Updated
1194
Using configuration from /root/openvpn/20/openvpn/tmp/easy-rsa/openssl.cnf
1195
DEBUG[load_index]: unique_subject = "yes"
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1196
client2.crt: /C# KG/ST=NA/O=OpenVPN-TEST/CN=client2/emailAddress
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1197
error 23 at 0 depth lookup:certificate revoked
1198
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1199
Note the "error 23" in the last line. That is what you want to see, as it indicates that a certificate verification of the revoked certificate failed.
87ac55 Samuli Seppänen 2025-02-11 13:10:09 1200
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1201
The **revoke-full** script will generate a CRL (certificate revocation list) file called **crl.pem** in the **keys** subdirectory. The file should be copied to a directory where the OpenVPN server can access it, then CRL verification should be enabled in the server configuration:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1202
```
1203
crl-verify crl.pem
1204
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1205
Now all connecting clients will have their client certificates verified against the CRL, and any positive match will result in the connection being dropped.
1206
## CRL Notes
87ac55 Samuli Seppänen 2025-02-11 13:10:09 1207
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1208
* When the crl-verify option is used in OpenVPN, the CRL file will be re-read any time a new client connects or an existing client renegotiates the SSL/TLS connection (by default once per hour). This means that you can update the CRL file while the OpenVPN server daemon is running, and have the new CRL take effect immediately for newly connecting clients. If the client whose certificate you are revoking is already connected, you can restart the server via a signal (SIGUSR1 or SIGHUP) and flush all clients, or you can telnet to the management interface and explicitly kill the specific client instance object on the server without disturbing other clients.
1209
* While the crl-verify directive can be used on both the OpenVPN server and clients, it is generally unnecessary to distribute a CRL file to clients unless a server certificate has been revoked. Clients don't need to know about other client certificates which have been revoked because clients shouldn't be accepting direct connections from other clients in the first place.
1210
* The CRL file is not secret, and should be made world-readable so that the OpenVPN daemon can read it after root privileges have been dropped.
1211
* If you are using the chroot directive, make sure to put a copy of the CRL file in the chroot directory, since unlike most other files which OpenVPN reads, the CRL file will be read after the chroot call is executed, not before.
1212
* A common reason why certificates need to be revoked is that the user encrypts their private key with a password, then forgets the password. By revoking the original certificate, it is possible to generate a new certificate/key pair with the user's original common name.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1213
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1214
# Important Note on possible "Man-in-the-Middle" attack if clients do not verify the certificate of the server they are connecting to
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1215
87ac55 Samuli Seppänen 2025-02-11 13:10:09 1216
To avoid a possible Man-in-the-Middle attack where an authorized client tries to connect to another client by impersonating the server, make sure to enforce some kind of server certificate verification by clients. There are currently five different ways of accomplishing this, listed in the order of preference.
1217
1218
Option 1 for OpenVPN 2.1 and above: build your server certificates with specific key usage and extended key usage. The RFC3280 determine that the following attributes should be provided for TLS connections:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1219
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1220
| Mode | Key usage | Extended key usage |
1221
| --- | --- | --- |
1222
| Client | digitalSignature | TLS Web Client Authentication |
1223
| keyAgreement |
1224
| digitalSignature, keyAgreement |
1225
| Server | digitalSignature, keyEncipherment | TLS Web Server Authentication |
1226
| digitalSignature, keyAgreement |
87ac55 Samuli Seppänen 2025-02-11 13:10:09 1227
1228
You can build your server certificates with the build-key-server script (see the easy-rsa documentation for more info). This will designate the certificate as a server-only certificate by setting the right attributes. Now add the following line to your client configuration:
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1229
```
1230
remote-cert-tls server
1231
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1232
Option 2, for OpenVPN 2.0 and below: Build your server certificates with the **build-key-server** script (see the easy-rsa documentation for more info). This will designate the certificate as a server-only certificate by setting **nsCertType=server**. Now add the following line to your client configuration:
87ac55 Samuli Seppänen 2025-02-11 13:10:09 1233
```
1234
ns-cert-type server
1235
```
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1236
This will block clients from connecting to any server which lacks the **nsCertType=server** designation in its certificate, even if the certificate has been signed by the **ca** file in the OpenVPN configuration file.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1237
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1238
Option 3: Use the **tls-remote** directive on the client to accept/reject the server connection based on the common name of the server certificate.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1239
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1240
Option 4: Use a **tls-verify** script or plugin to accept/reject the server connection based on a custom test of the server certificate's embedded X509 subject details.
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1241
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1242
Option 5: Sign server certificates with one CA and client certificates with a different CA. The client configuration **ca** directive should reference the server-signing CA file, while the server configuration **ca** directive should reference the client-signing CA file.
4dfaa2 Samuli Seppänen 2025-02-11 13:10:47 1243
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1244
# Sample OpenVPN 2.0 configuration files
4dfaa2 Samuli Seppänen 2025-02-11 13:10:47 1245
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1246
Latest sample configuration files [are available on GitHub](https://github.com/OpenVPN/openvpn/tree/master/sample/sample-config-files).
4dfaa2 Samuli Seppänen 2025-02-11 13:10:47 1247
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1248
----
0c0510 Samuli Seppänen 2025-02-11 12:59:17 1249
ab4c4d Samuli Seppänen 2025-02-12 11:28:18 1250
Copyright © 2002-2019 by OpenVPN Technologies, Inc. < info@openvpn.net>. OpenVPN is a trademark of OpenVPN Technologies, Inc.