Changes between Version 6 and Version 7 of EasyRSA3-OpenVPN-Howto


Ignore:
Timestamp:
11/30/13 22:29:06 (10 years ago)
Author:
JoshC
Comment:

clarify separate locations better

Legend:

Unmodified
Added
Removed
Modified
  • EasyRSA3-OpenVPN-Howto

    v6 v7  
    99== Separate CA system procedure ==
    1010
    11 Pick a location for the CA and each entity that will be assigned certs. All keypair/request generation should occur on the target system that will use them; put another way, generate your client & server requests/keys on each system for best security.
     11Pick locations for the CA and each entity that will be assigned certs. All keypair/request generation should occur on the target system that will use them; put another way, generate your client & server requests/keys on each system for best security.
    1212
    1313You will end up with the following locations used in the steps below:
    1414
    1515 CA:: your secured CA environment
    16  entity:: each client and server has their own, separate environment
     16 entity:: each client and server has their own, separate environment; this will usually include at least 2 locations, one for the server and another for your client (on their respective machines.)
    1717
    18181. On the CA, start a new PKI and build a CA keypair/cert: