Blame
| 2e2eec | Samuli Seppänen | 2025-02-28 13:38:20 | 1 | # Upgrading EasyRSA |
| 2 | ||||
| 3 | **Note**: This wiki is a *work in progress*. |
|||
| 4 | ||||
| 5 | This page describes the EasyRSA PKI upgrade process: |
|||
| 6 | EasyRSA PKI version 2 to EasyRSA version 3, see below. |
|||
| 7 | ||||
| 8 | ||||
| 9 | ## Setup |
|||
| 10 | ||||
| 11 | 1. You must install a new copy of EasyRSA v3.0.7 or above |
|||
| 12 | 1. Copy your existing **EasyRSA version 2 files and directories** into `./easyrsa3` |
|||
| 13 | Your `./easyrsa3` directory should now look *something* like below (in Before section). |
|||
| 14 | 1. Linux: run `./easyrsa upgrade pki` |
|||
| 15 | 1. Windows: run `easyrsa-start.bat` and then `./easyrsa upgrade pki` |
|||
| 16 | If you have trouble starting EasyRSA-v3, please consult the relevant documentation. \\ |
|||
| 17 | Your `./easyrsa3` directory should now look *something* like below (in After section). |
|||
| 18 | ||||
| 19 | ### Examples |
|||
| 20 | ||||
| 21 | * **Linux** |
|||
| 22 | ||||
| 23 | Your current Easy-RSA **Version 2** PKI is located under `/root/easyrsa` |
|||
| 24 | Your new Easy-RSA **Version 3** PKI will be located at `/etc/openvpn/easyrsa/pki` |
|||
| 25 | ||||
| 26 | Change directory to `/etc/openvpn/easyrsa` |
|||
| 27 | Test that `easyrsa help` works, if that does not work then test that `./easyrsa help` works. |
|||
| 28 | ||||
| 29 | If you do not have a working copy of the `easyrsa` script then you **cannot** continue. |
|||
| 30 | ||||
| 31 | Copy `/root/easyrsa` to `/etc/openvpn/easyrsa` |
|||
| 32 | ||||
| 33 | * **Windows** |
|||
| 34 | ||||
| 35 | Your current Easy-RSA **Version 2** PKI is located under `\users\easyrsa` |
|||
| 36 | Your new Easy-RSA **Version 3** PKI will be located at `\Program Files\Openvpn\easy-rsa\pki` |
|||
| 37 | ||||
| 38 | Start Easy-RSA `EasyRSA-Start.bat` |
|||
| 39 | ||||
| 40 | Copy `\users\easyrsa` to `/Program Files\Openvpn\easy-rsa` |
|||
| 41 | ||||
| 42 | ## Usage |
|||
| 43 | ||||
| 44 | To perform the upgrade: |
|||
| 45 | ||||
| 46 | ||||
| 47 | 1. ``` ./easyrsa upgrade pki ``` |
|||
| 48 | This will upgrade a version 2 PKI to version 3. |
|||
| 49 | This upgrade will also perform the CA upgrade below. |
|||
| 50 | The CA is set to allow duplicate certificates to allow for for renewal. |
|||
| 51 | The PKI is not changed only copied. |
|||
| 52 | ||||
| 53 | 2. ``` ./easyrsa upgrade ca ``` |
|||
| 54 | The CA is set to allow duplicate certificates to allow for for renewal. |
|||
| 55 | The PKI is not changed. |
|||
| 56 | ||||
| 57 | To automate this upgrade use `--batch` |
|||
| 58 | ||||
| 59 | ## Steps |
|||
| 60 | ||||
| 61 | These CHECKS will be made if you upgrade now: |
|||
| 62 | ||||
| 63 | Before ANY changes are made a test run will be attempted ... |
|||
| 64 | ||||
| 65 | * Verify: new PKI dir does not exist and will not be over written. |
|||
| 66 | * Verify: new backup PKI dir does not exist and will not be over written. |
|||
| 67 | * Verify and Source the current PKI settings: ./vars or ./vars.bat |
|||
| 68 | * Verify the current ca.crt |
|||
| 69 | ||||
| 70 | Then: |
|||
| 71 | * CONFIRM NOW THAT THIS IS THE CORRECT ca.crt and continue or quit |
|||
| 72 | ||||
| 73 | These CHANGES will be made if you continue: |
|||
| 74 | ||||
| 75 | Before ANY changes are made a test run will be attempted ... |
|||
| 76 | * Complete backup of the current PKI to ./VERY-SAFE-PKI |
|||
| 77 | * Create new PKI dirs for use with EasyRSA-3 |
|||
| 78 | * Copy required working database files to new PKI |
|||
| 79 | * Copy current PKI to new PKI |
|||
| 80 | * Update the CA to allow duplicates for renewal |
|||
| 81 | * create new openssl-easyrsa.cnf file |
|||
| 82 | * Remove EasyRSA-2 program files |
|||
| 83 | * Build new EasyRSA-3 vars file |
|||
| 84 | ||||
| 85 | ### Before |
|||
| 86 | ||||
| 87 | (This list is not completely accurate ... ) |
|||
| 88 | ||||
| 89 | ``` |
|||
| 90 | . |
|||
| 91 | ├── bin |
|||
| 92 | │ ├── { EasyRSA v3 Windows executables ... } |
|||
| 93 | │ |
|||
| 94 | ├── keys |
|||
| 95 | │ ├── { Your current EasyRSA v2 PKI ... } |
|||
| 96 | │ |
|||
| 97 | └── x509-types |
|||
| 98 | ├── { EasyRSA v3 x509 definition files ... } |
|||
| 99 | ||||
| 100 | Linux EasyRSA-v2 program files: |
|||
| 101 | ├── build-ca |
|||
| 102 | ├── build-dh |
|||
| 103 | ├── build-inter |
|||
| 104 | ├── build-key |
|||
| 105 | ├── build-key-pass |
|||
| 106 | ├── build-ca.bat |
|||
| 107 | ├── build-key-pkcs12 |
|||
| 108 | ├── build-key-server |
|||
| 109 | ├── build-req |
|||
| 110 | ├── build-req-pass |
|||
| 111 | ├── clean-all |
|||
| 112 | ├── inherit-inter |
|||
| 113 | ├── list-crl |
|||
| 114 | ├── make-crl |
|||
| 115 | ├── pkitool |
|||
| 116 | ├── revoke-crt |
|||
| 117 | ├── revoke-full |
|||
| 118 | └── sign-req |
|||
| 119 | ||||
| 120 | Windows EasyRSA-v2 program files: |
|||
| 121 | ├── build-ca-pass.bat |
|||
| 122 | ├── build-dh.bat |
|||
| 123 | ├── build-key.bat |
|||
| 124 | ├── build-key-pass.bat |
|||
| 125 | ├── build-key-pkcs12.bat |
|||
| 126 | ├── build-key-server.bat |
|||
| 127 | ├── build-key-server-pass.bat |
|||
| 128 | ├── clean-all.bat |
|||
| 129 | ├── EasyRSA-Start.bat |
|||
| 130 | ├── init-config.bat |
|||
| 131 | ├── revoke-full.bat |
|||
| 132 | ├── vars.bat |
|||
| 133 | ├── vars.bat.sample |
|||
| 134 | └── whichopensslcnf |
|||
| 135 | ||||
| 136 | Common EasyRSA-v2 files: |
|||
| 137 | ├── index.txt.start |
|||
| 138 | ├── README.txt |
|||
| 139 | └── serial.start |
|||
| 140 | ||||
| 141 | Common EasyRSA-v3 files: |
|||
| 142 | ├── easyrsa |
|||
| 143 | ├── openssl-easyrsa.cnf |
|||
| 144 | └── vars.example |
|||
| 145 | ||||
| 146 | ``` |
|||
| 147 | ||||
| 148 | ### After |
|||
| 149 | ||||
| 150 | ``` |
|||
| 151 | . |
|||
| 152 | ├── bin |
|||
| 153 | │ ├── { EasyRSA v3 Windows executables ... } |
|||
| 154 | │ |
|||
| 155 | ├── keys |
|||
| 156 | │ ├── { Your old EasyRSA v2 PKI ... } |
|||
| 157 | │ |
|||
| 158 | ├── pki |
|||
| 159 | │ ├── { Your new EasyRSA v3 PKI ... } |
|||
| 160 | │ |
|||
| 161 | ├── VERY-SAFE-PKI |
|||
| 162 | │ ├── { Your old EasyRSA v2 PKI ... backup files } |
|||
| 163 | │ |
|||
| 164 | └── x509-types |
|||
| 165 | ├── { EasyRSA v3 x509 definition files ... } |
|||
| 166 | ||||
| 167 | Common EasyRSA-v3 files: |
|||
| 168 | ├── easyrsa |
|||
| 169 | ├── openssl-easyrsa.cnf |
|||
| 170 | ├── vars |
|||
| 171 | └── vars.example |
|||
| 172 | ||||
| 173 | ``` |
|||
| 174 | ||||
| 175 | ## Fails |
|||
| 176 | **Correct the error reported first.** |
|||
| 177 | ||||
| 178 | Before you can try the update again you MUST remove these two directories: |
|||
| 179 | ||||
| 180 | * `./easyrsa3/pki` |
|||
| 181 | * `./easyrsa3/VERY_SAFE_PKI` |
|||
| 182 | ||||
| 183 | You **may** also need to remove the newly created vars file at: |
|||
| 184 | ||||
| 185 | * `./easyrsa3/vars` |
|||
| 186 | ||||
| 187 | If you find this warning at the top of the ./vars file then it is safe to remove: |
|||
| 188 | ``` |
|||
| 189 | ########################++++++++++######################### |
|||
| 190 | ### ### |
|||
| 191 | ### WARNING: THIS FILE WAS AUTOMATICALLY GENERATED ### |
|||
| 192 | ### ALL SETTINGS ARE AT THE END OF THE FILE ### |
|||
| 193 | ### ### |
|||
| 194 | ########################++++++++++######################### |
|||
| 195 | ``` |
|||
| 196 | ||||
| 197 | ### Incompatible `vars` file |
|||
| 198 | ||||
| 199 | The the `vars` file in place uses export which Easyrsa3 does not support. |
|||
| 200 | ||||
| 201 | ### Too many `vars` files #ersa-up23-fails-vars-bat |
|||
| 202 | ||||
| 203 | There exists a `vars` file and a `vars.bat` file. Only one of these files may exist. |
|||
| 204 | ||||
| 205 | ### CA certificate does not match `vars`/`vars.bat` file settings |
|||
| 206 | ||||
| 207 | The current CA details do not match the `vars` file in place. |
|||
| 208 | ||||
| 209 | ## v30x to v306 |
|||
| 210 | ||||
| 211 | Only one change is required: |
|||
| 212 | `pki/index.txt.attr` \\ |
|||
| 213 | Required: `unique_subject = no` |
|||
| 214 | ||||
| 215 | ||||
| 216 | ## Debian-based distros |
|||
| 217 | ||||
| 218 | For users of Debian-based distros (Debian, Ubuntu, Mint, Devuan, …): |
|||
| 219 | ||||
| 220 | EasyRSA can be installed with standard package manager: `apt install easy-rsa`. |
|||
| 221 | ||||
| 222 | **Do not** use `make-cadir` to create a directory for migration, because it creates a symlink `.easyrsa` to `/usr/share/easy-rsa/easyrsa`, but when you run a function `./easyrsa upgrade`, it will try to create subdirectories in `/usr/share/easy-rsa/`: |
|||
| 223 | ||||
| 224 | > mkdir: cannot create directory ‘/usr/share/easy-rsa/VERY-SAFE-PKI’: Permission denied |
|||
| 225 | ||||
| 226 | Follow these steps to perform upgrade from v2 keys structure to v3: |
|||
| 227 | ||||
| 228 | * create an empty directory for migration, like `mkdir migrate-from-v2-to-v3`, |
|||
| 229 | * go into it: `cd migrate-from-v2-to-v3`, |
|||
| 230 | * copy old structure, something like: `rsync -a ~/vpn-keys/my-old-keys-v2/ .`, |
|||
| 231 | * check the current structure, it should look like described in [#ersa-up23-before Before], |
|||
| 232 | * copy the main script and 2 more files needed for upgrade: `cp -pv /usr/share/easy-rsa/{easyrsa,openssl-easyrsa.cnf,vars.example} .` |
|||
| 233 | * perform the upgrade: `./easyrsa upgrade pki`, |
|||
| 234 | * check the current structure, it should look like in [#ersa-up23-after After], |
|||
| 235 | * now you can replace script by a symlink, so following `easy-rsa` package update in future will adjust your `./easyrsa`: `ln -sfv /usr/share/easy-rsa/easyrsa ./easyrsa`. |
|||
| 236 | ||||
| 237 | ||||
| 238 | ## Help |
|||
| 239 | ||||
| 240 | https://forums.openvpn.net/viewforum.php?f=31 |
