Blame

579e9c Samuli Seppänen 2025-03-18 11:51:11 1
# Easy-RSA v3 OpenVPN Howto
a23d9e Samuli Seppänen 2025-02-11 07:47:31 2
8734a8 Samuli Seppänen 2025-02-12 14:34:34 3
Note for small setups, it often much easier to *not* setup a PKI but instead of the peer-fingeprint method instead. A small tutorial can be found here: https://github.com/OpenVPN/openvpn/blob/master/doc/man-sections/example-fingerprint.rst
a23d9e Samuli Seppänen 2025-02-11 07:47:31 4
5
This Howto walks through the use of Easy-RSA v3 with OpenVPN.
6
7
8734a8 Samuli Seppänen 2025-02-12 14:34:34 8
Skip to the : [Beginners Guide](https://community.openvpn.net/openvpn/wiki/EasyRSA3-OpenVPN-Howto#PKIprocedure:ProducingyourcompletePKIontheCAmachine)
a23d9e Samuli Seppänen 2025-02-11 07:47:31 9
8734a8 Samuli Seppänen 2025-02-12 14:34:34 10
## Process Overview
11
12
The best way to create a PKI for OpenVPN is to separate your CA duty from each server & client. The CA should ideally be on a secure environment (whatever that means to you.) Loss/theft of the CA key destroys the security of the entire PKI.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 13
14
To use Easy-RSA to set up a new OpenVPN PKI, you will:
15
8734a8 Samuli Seppänen 2025-02-12 14:34:34 16
1. Set up a CA PKI and build a root CA
17
18
2. Configure secondary PKI environments on your server and each client and generate a keypair & request on them
19
20
3. Send the certificate requests to the CA, where the CA signs and returns a valid certificate
21
22
4. On your OpenVPN server, generate DH parameters (see the DH Generation section of this Howto)
a23d9e Samuli Seppänen 2025-02-11 07:47:31 23
579e9c Samuli Seppänen 2025-03-18 11:51:11 24
## Easy-RSA and MITM protection with OpenVPN
a23d9e Samuli Seppänen 2025-02-11 07:47:31 25
26
**Important note:** some OpenVPN configs rely on the deprecated "Netscape" cert attribute called nsCertType. This is deprecated behavior, and Easy-RSA 3 does **not** enable this by default like v2 did. Please use the `--remote-cert-tls` directive in your OpenVPN config files for MITM protection.
27
28
If you really need the old, deprecated behavior, enable the Netscape extensions by reading vars.example before signing certs with your CA. This will allow you to use `--ns-cert-type` with OpenVPN.
29
579e9c Samuli Seppänen 2025-03-18 11:51:11 30
## PKI procedure: using a separate CA system
a23d9e Samuli Seppänen 2025-02-11 07:47:31 31
32
Pick locations for the CA and each entity that will be assigned certs. All keypair/request generation should occur on the target system that will use them; put another way, generate a server request on the actual server system, and your client requests on each client.
33
34
You will end up with the following locations used in the steps below:
35
8734a8 Samuli Seppänen 2025-02-12 14:34:34 36
CA:: your secured CA environment; this will be on a separate system, or at least a separate directory from anything else
37
server:: each server has a unique directory for its own key & request (on the actual server system)
38
entity:: each client has a unique directory for its own key & request (on the actual client system)
a23d9e Samuli Seppänen 2025-02-11 07:47:31 39
40
1. On the CA, start a new PKI and build a CA keypair/cert:
8734a8 Samuli Seppänen 2025-02-12 14:34:34 41
```
42
./easyrsa init-pki
43
./easyrsa build-ca
44
```
a23d9e Samuli Seppänen 2025-02-11 07:47:31 45
46
2. On each server system, generate a keypair and request. Normally these are left unencrypted by using the "nopass" argument since servers usually start up without any password input. This generates an **unencrypted** key, so protect its access and file permissions carefully.
8734a8 Samuli Seppänen 2025-02-12 14:34:34 47
```
48
./easyrsa init-pki
49
./easyrsa gen-req UNIQUE_SERVER_SHORT_NAME nopass
50
```
a23d9e Samuli Seppänen 2025-02-11 07:47:31 51
52
3. On each client, generate a keypair and request. The name selected must be unique across the PKI and is otherwise arbitrary. Create a new PKI and request on each client as follows:
8734a8 Samuli Seppänen 2025-02-12 14:34:34 53
```
54
./easyrsa init-pki
55
./easyrsa gen-req UNIQUE_CLIENT_SHORT_NAME
56
```
57
A. Optionally, the private key can be left unencrypted on-disk with the additional `nopass` option after the name. This is **not** recommended unless automated VPN startup is required. Unencrypted private keys can be used by anyone who obtains a copy of the file. Encrypted keys offer stronger protection, but will require the passphrase on initial use.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 58
59
4. Send the request files from each entity to the CA system. This is not security sensitive, though it is wise to verify the received file matches the sender's copy if the transport is untrusted.
60
61
5. On the CA, import each entity request file, giving it an arbitrary "short name" as follows. This basically just copies the request file into `reqs/` under the PKI dir to prepare it for review and signing.
8734a8 Samuli Seppänen 2025-02-12 14:34:34 62
```
63
./easyrsa import-req /path/to/received.req UNIQUE_SHORT_FILE_NAME
64
```
a23d9e Samuli Seppänen 2025-02-11 07:47:31 65
66
6. Review each request's details if you wish, then sign it as one of the types: server or client.
8734a8 Samuli Seppänen 2025-02-12 14:34:34 67
A. (optional) review the request:
68
```
69
./easyrsa show-req UNIQUE_SHORT_FILE_NAME
70
```
71
B. If you are signing as a **client**:
72
```
73
./easyrsa sign-req client UNIQUE_SHORT_FILE_NAME
74
```
75
C. If you are signing as a **server**:
76
```
77
./easyrsa sign-req server UNIQUE_SHORT_FILE_NAME
78
```
a23d9e Samuli Seppänen 2025-02-11 07:47:31 79
80
7. The CA returns the signed certificate produced in the above step, and includes the CA certificate (ca.crt) unless the client already has it. This can be done over an insecure channel, though the client is encouraged to confirm the received CA cert is valid if the transport is untrusted.
81
8734a8 Samuli Seppänen 2025-02-12 14:34:34 82
## DH Generation
a23d9e Samuli Seppänen 2025-02-11 07:47:31 83
84
On the PKI for the OpenVPN server, this command will generate DH parameters used during the TLS handshake with connecting clients. The DH params are not security sensitive and are used only by an OpenVPN server.
85
86
```
87
./easyrsa gen-dh
88
```
89
579e9c Samuli Seppänen 2025-03-18 11:51:11 90
## PKI procedure: Producing your complete PKI on the CA machine
a23d9e Samuli Seppänen 2025-02-11 07:47:31 91
8734a8 Samuli Seppänen 2025-02-12 14:34:34 92
It is most common for beginners to produce a complete PKI on one machine and then distribute the files as needed. If you have followed the steps above and already have a partial PKI then make sure you do not over write it. The simplest approach is to make a complete copy of Easyrsa3 in a new folder.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 93
94
Starting with a fresh copy of Easyrsa3 follow these steps:
95
8734a8 Samuli Seppänen 2025-02-12 14:34:34 96
Copy the file `vars.example` to file named `vars` and open `vars` for editing.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 97
Read through `vars` for instructions on what to edit.
8734a8 Samuli Seppänen 2025-02-12 14:34:34 98
For example, you can chose if your PKI will use RSA or Elliptic Curve cryptography.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 99
Save your changes and close `vars`.
100
8734a8 Samuli Seppänen 2025-02-12 14:34:34 101
Initialise your PKI:
a23d9e Samuli Seppänen 2025-02-11 07:47:31 102
```
103
./easyrsa init-pki
104
```
105
Create your CA:
106
```
107
./easyrsa build-ca
108
```
8734a8 Samuli Seppänen 2025-02-12 14:34:34 109
Option `nopass` can be used to disable password locking the CA.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 110
111
Build a server certificate and key:
112
```
113
./easyrsa build-server-full <SERVER_NAME>
114
```
8734a8 Samuli Seppänen 2025-02-12 14:34:34 115
Replace `<SERVER_NAME>` with your server name. eg. `Server-01`
116
Option `nopass` can be used to disable password locking the key.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 117
118
Build a client certificate and key:
119
```
120
./easyrsa build-client-full <CLIENT_NAME>
121
```
8734a8 Samuli Seppänen 2025-02-12 14:34:34 122
Replace `<CLIENT_NAME>` with your client name. eg. `Client-01` or `alice`
123
Option `nopass` can be used to disable password locking the key.
124
Repeat for all clients.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 125
126
Using this method, server and client keys must be distributed over a secure medium, such as using SFTP.
127
128
Finally, you can use [Easy-TLS](https://github.com/TinCanTech/easy-tls) to add the finishing touches to your PKI.
129
8734a8 Samuli Seppänen 2025-02-12 14:34:34 130
a23d9e Samuli Seppänen 2025-02-11 07:47:31 131
Download `easytls` to your current EasyRSA-3 working directory and follow these steps:
132
8734a8 Samuli Seppänen 2025-02-12 14:34:34 133
Initialise Easy-TLS:
a23d9e Samuli Seppänen 2025-02-11 07:47:31 134
```
135
./easytls init-tls
136
```
8734a8 Samuli Seppänen 2025-02-12 14:34:34 137
This creates a directory called `easytls` in your current PKI directory (Default: `pki/easytls`)
a23d9e Samuli Seppänen 2025-02-11 07:47:31 138
139
Create a TLS-AUTH key:
140
```
141
./easytls build-tls-auth
142
```
143
144
Create a TLS-CRYPT key:
145
```
146
./easytls build-tls-crypt
147
```
148
149
Create a TLS-CRYPT-V2 server key:
150
```
151
./easytls build-tls-crypt-v2-server <SERVER_NAME>
152
```
8734a8 Samuli Seppänen 2025-02-12 14:34:34 153
This key **must** be kept secure.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 154
Create a TLS-CRYPT-V2 client key:
155
```
156
./easytls build-tls-crypt-v2-client <SERVER_NAME> <CLIENT_NAME>
157
```
8734a8 Samuli Seppänen 2025-02-12 14:34:34 158
The Server key is used to encrypt the client key which is why the server key must also be specified.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 159
160
Now Easy-TLS can create `.inline` files for each of your VPN nodes.
161
162
Depending on which type of TLS key you are using (TLS auth, crypt or crypt-v2) build an inline file:
163
```
164
./easytls inline-tls-auth Server-01
165
```
8734a8 Samuli Seppänen 2025-02-12 14:34:34 166
Repeat for all your VPN nodes.
a23d9e Samuli Seppänen 2025-02-11 07:47:31 167
8734a8 Samuli Seppänen 2025-02-12 14:34:34 168
If you used the first method to build your PKI and do not have access to the keys of each of your nodes then you can still use Easy-TLS to build `.inline` files by using the option `nokey`. This will build `.inline` files which leave the inline `<key></key>` field blank so that the key can be pasted in by the respective user.