ããã§ã¯ãOpenVPNãããCAã®èšå®ã«éç¹ã眮ããŠããããšã«ããã«æ³šæããããšæããŸãã
å§ããåã«ãç§ã®äŸã§ããã䜿çšã§ãã人ã«è©±ããŸãã
OpenVPNãµãŒããŒèšŒææžã1人ã ãã§çœ²åãããVPNãµãŒããŒãå€æ°ãããéšéããšã«è€æ°ã®VPNãµãŒããŒãã»ããã¢ãããããããã«ã倧äŒæ¥åãã®ã·ã¹ãã ãäœæããã¿ã¹ã¯ããããŸãããåŸæ¥å¡ãéåžžã«éãè² æ ïŒèšæåŸæ¥å¡ã¯èšããŸã§ããªãïŒã«æ¥ã/é¢ãããã³ã«ãããã«å€ãã®åŸæ¥å¡ïŒã¯ã©ã€ã¢ã³ãïŒãšç®¡çïŒçºè¡/åãæ¶ãïŒèšŒææžããããŸããåéšéã®åŸæ¥å¡ã¯ãæ°æ§ã®åŸæ¥å¡ã®èšŒææžãããããçºè¡ãŸãã¯åãæ¶ãéšéã®è²¬ä»»è ã«ãã£ãŠç£ç£ãããŠããŸãã
ã©ã®ãããªèšŒææžãšããžã¿ã«ããŒãå¿ èŠãã«ã€ããŠã¯ãå€ãã®ããšãèšãããŠããŸããä»ã®èè ãç¹°ãè¿ãããšã¯ããŸããããèŠããã«ïŒ
- ä¿¡é Œæ§ãæ€èšŒããããã«ïŒãããã«ãã³ãã·ã§ã€ã¯ããçºçããŸãïŒãã¯ã©ã€ã¢ã³ããšãµãŒããŒã¯ããäºããä¿¡é ŒããŠæ¥ç¶ã確ç«ã§ãããã©ããã確èªããŸãã
- æå·å/埩å·å;
- äŸå€ãçãäžã®ç·ïŒMITMïŒãã¯ã誰ããã¡ãã»ãŒãž/ãã©ãã£ãã¯ãååããªãããã«ããŸãã
- æå·åããããã¹ã¯ãŒããäœæããŸããããã«ãããã»ãã¥ãªãã£ã匷åãããæ»æè ããã¹ãã«ã¢ã¯ã»ã¹ãã«ãããªããŸãã
ãã«ãã¬ãã«CAéå±€ã®åäœåçã¯ããããã¬ãã«CAïŒRootCAïŒãååã«é·ãæéïŒãã ããããã¯çŽç²ã«åå¥ã®åé¡ã§ãïŒããã®èšŒææžã«çœ²åããããšã§ããCAéå±€ã®æ¬¡ã«äœãã¬ãã«ãŸãã¯ãµãŒãã¹ã¯ãäžäœCAïŒéåžžã¯ïŒã§èšŒææžã«çœ²åããŸãã bureaucracyïŒããã ããäžäœã¬ãã«ã®èšŒææžã®æå¹æéã¯ãäžäœã¬ãã«ã®èšŒææžã®æå¹æéã®åå以äžã§ãªããã°ãªããŸããã
CAãäœæãããšãca.crtïŒå ¬ééµïŒãšca.keyïŒç§å¯éµïŒã®2ã€ã®ãã¡ã€ã«ãäœæãããŸãã
ç§å¯éµã¯ä¿è·ããå¿ èŠãããã第äžè ãšå ±æããŠã¯ãªããŸããã
åŸå±/眲åCAãäœæããå¿ èŠãããå Žåã¯ããã®CAã«ç§å¯éµãäœæããRootCAããã®çœ²åèŠæ±ãäœæããŸãã
äžçäžã®ã³ã³ãã¥ãŒã¿ãŒãšãŠãŒã¶ãŒã¯ããµãŒãã¹ããµã€ããä¿¡é Œã§ããããšãã©ã®ããã«ããŠç¥ãã®ã§ãããããç°¡åã§ãïŒçè«çã«ã¯ïŒãCAã®å ¬éããŒïŒRootCAïŒã¯ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã«é 眮ããããããã®ã³ã³ãã¥ãŒã¿ãŒã¯ãã®CAã«ãã£ãŠçºè¡ããããã¹ãŠã®èšŒææžãä¿¡é ŒããŸããå®éã«ã¯ãããã¯ç¢ºãã«ãã£ãšé£ãããå®ãã¯ãããŸãããããããããªãã®äŒç€Ÿã®äžã§ãããããã®ã¯ãšãŠãç°¡åã§ãã
å®è£ ã«ã¯ã3ã€ã®ãµãŒããŒãå¿ èŠã§ãããã®ãã¥ãŒããªã¢ã«ã§ã¯ãdebian 9ã䜿çšããŸããã¢ããªã±ãŒã·ã§ã³ã«å¿ããŠãµãŒããŒã«ååãä»ããŸãïŒOpenVPNãSubCAãRootCAã
ãã¹ãŠã®ã¢ã¯ã·ã§ã³ã¯ãrootã§ã¯ãªããŠãŒã¶ãŒã®äžã§å®è¡ãããŸãã
ãããè¡ãã«ã¯ããŠãŒã¶ãŒãsudoã°ã«ãŒãã«å±ããŠããå¿ èŠããããŸãã
sudoããµãŒããŒã«ã€ã³ã¹ããŒã«ãããŠããªãå Žåã¯ãrootãšããŠãã°ã€ã³ããŸãã
# su - root
# apt-get install sudo -y
# usermod -aG sudo username
# exit
ãã¹ãŠã®ãµãŒããŒã«å¿ èŠãªãŠãŒãã£ãªãã£ãã€ã³ã¹ããŒã«ããŸãïŒããã§ã¯ãããã®ãŠãŒãã£ãªãã£ã§ã³ãã³ããå®è¡ããããããŠãŒãã£ãªãã£ã¯ä¿¡å¿µãšä¿¡å¿µã«ãã£ãŠç°ãªãå ŽåããããŸããwgetãufwãvimã¯å¿ é ã§ãïŒïŒ
# sudo apt-get update
# sudo apt-get upgrade
# sudo apt-get install wget curl net-tools ufw vim -y
# cd ~
# wget -P ~/ https://github.com/OpenVPN/easy-rsa/releases/download/v3.0.4/EasyRSA-3.0.4.tgz
# tar xvf EasyRSA-3.0.4.tgz
OpenVPNãµãŒããŒã«openvpnãã€ã³ã¹ããŒã«ããŸãã
# sudo apt-get install openvpn -y
RootCAãµãŒããŒã«ç§»åããŸããããã§ãeasyrsaãå€æ°ã®å€ãååŸãããã¡ã€ã«ãäœæããå¿ èŠããããŸãïŒ
# mv ~/EasyRSA-3.0.4 ~/easyrsa/
# cd ~/easyrsa/
# cp vars.example vars
# vim vars
ãããã¯ãèŠã€ããïŒãåé€ããŠãå€ã眮ãæããŸãã蚌ææžã«çœ²åãããšãã«ããŒã¿ãå ¥åããªãããã«ãããã«ããŒã¿ãæžã蟌ã¿ãŸãã
#set_var EASYRSA_REQ_COUNTRY "US"
#set_var EASYRSA_REQ_PROVINCE "California"
#set_var EASYRSA_REQ_CITY "San Francisco"
#set_var EASYRSA_REQ_ORG "Copyleft Certificate Co"
#set_var EASYRSA_REQ_EMAIL "me@example.net"
#set_var EASYRSA_REQ_OU "My Organizational Unit"
次ã«ã次ã®èšå®ãèŠã€ããïŒãåé€ããŠå€ãç·šéããŸãããããã®ãã£ã¬ã¯ãã£ãã¯ã蚌ææžã®æå¹æéãæ åœããŸãïŒ1ã€ç®ã¯CA蚌ææžã®æå¹æéã2ã€ç®ã¯çœ²åãããŠãã蚌ææžã®æå¹æéã§ãïŒã
#set_var EASYRSA_CA_EXPIRE 3650 #--> 3650
#set_var EASYRSA_CERT_EXPIRE 3650 #--> 1825
ããã«ïŒ
# ./easyrsa init-pki
次ã®ã³ãã³ããå®è¡ãããšãCNãèŠæ±ãããŸããããã©ã«ãã®ãŸãŸã«ããããšãã§ããŸããããã¹ãåèå¥åïŒRootCAïŒãå ¥åããããšããå§ãããŸããå€ãnopassãã¯ããã¹ã¯ãŒããäœæããå¿ èŠããªãããšãæå³ããŸãã
# ./easyrsa build-ca nopass
SubCAãµãŒããŒã«ç§»åããå°ããªå€æŽãå ããŠåæ§ã®æé ãå®è¡ããŸãã
# mv ~/EasyRSA-3.0.4 ~/easyrsa/
# cd ~/easyrsa/
# cp vars.example vars
# vim vars
ãããã¯ãèŠã€ããïŒãåé€ããŠãå€ã眮ãæããŸãã
#set_var EASYRSA_REQ_COUNTRY "US"
#set_var EASYRSA_REQ_PROVINCE "California"
#set_var EASYRSA_REQ_CITY "San Francisco"
#set_var EASYRSA_REQ_ORG "Copyleft Certificate Co"
#set_var EASYRSA_REQ_EMAIL "me@example.net"
#set_var EASYRSA_REQ_OU "My Organizational Unit"
次ã«ã次ã®èšå®ãèŠã€ããïŒãåé€ããŠå€ãç·šéããŸãã
#set_var EASYRSA_CA_EXPIRE 3650 #--> 1825
#set_var EASYRSA_CERT_EXPIRE 3650 #--> 365
ããã«ïŒ
# ./easyrsa init-pki
次ã®ã³ãã³ããå®è¡ãããšãCNãèŠæ±ãããŸããããã©ã«ãã®ãŸãŸã«ããããšãã§ããŸããããã¹ãèå¥ååïŒSubCAïŒãå ¥åããããšããå§ãããŸããå€ãsubcaãã¯ãäžäœCAãäœæããŠããã蚌ææžçœ²åèŠæ±ãäœæããå¿ èŠãããããšãæå³ããŸãã
# ./easyrsa build-ca subca nopass
次ã«ããã¡ã€ã«ã/ easyrsa / pki / reqs / ca.reqïŒããã¯ãŸãã«ãªã¯ãšã¹ãã§ãïŒãèŠã€ããŠããããRootCAãµãŒããŒã«è»¢éããŸãïŒWinSCPãšscpã®2ã€ã®æ¹æ³ã䜿çšã§ããŸãïŒã
# scp ~/easyrsa/pki/reqs/ca.req user@ip_RootCA:/tmp
RootCAãµãŒããŒã«ç§»åãããªã¯ãšã¹ãã«çœ²åããŸãããªã¯ãšã¹ãã«çœ²åããåã«ããããäœæ¥ãã£ã¬ã¯ããªã«ã€ã³ããŒãããå¿ èŠããããŸããäžäœCAã®èšŒææžã«çœ²åããã«ã¯ããcaãå±æ§ãšèšŒææžã®ååã䜿çšããŸãïŒcaãšåŒã¶ããšãã§ããŸãããæ··ä¹±ããªãããã«ã眲åå ã®ãµãŒããŒã®ååãšåŒã³ããµãŒããŒã«è»¢éãããšãã«ååãå€æŽããŸãïŒã
# cd ~/easyrsa/
# ./easyrsa import-req /tmp/ca.req SubCA
# ./easyrsa sign-req ca SubCA
確èªãæ±ããããŸãã®ã§ããã¯ãããšå ¥åããŠãã ããã
SubCAã§çœ²åããã蚌ææžãè¿ããŸãã
# scp ~/easyrsa/pki/issued/SubCA.crt user@ip_SubCA:/tmp
SubCAãµãŒããŒã«ç§»åãã蚌ææžãeasyrsaäœæ¥ãã£ã¬ã¯ããªã«ç§»åããŸãã
# mv /tmp/SubCA.crt ~/easyrsa/pki/ca.crt
ãã®æç¹ã§ãã«ãŒãCAãšçœ²åãããã«ãŒãã»ã«ã³ããªCAããã§ã«ãããŸãã
ããã§ã¯ãOpenVPNãµãŒããŒã«å ¥ããŸãããããã®æ§æã§ã¯ãåã®ã¹ãããã®ããã€ããç¹°ãè¿ãããŸããOpenVPNãµãŒããŒã«ç§»åããŸãã
# cd ~/easyrsa/
# ./easyrsa init-pki
ããã§ã¯ã眲åçšã®èšŒææžã®äœæãå§ããŸããããããŒäº€æã§äœ¿çšããDiffie-HellmanããŒïŒdh.pem / dh2048.pem / dh1024.pemïŒãäœæããTLSæŽåæ§ãã§ãã¯æ©èœã匷åããããã«HMAC眲åïŒta.keyïŒãäœæããŸãã
RootCAã§OpenVPNãµãŒããŒã®èšŒææžã«çœ²åããSubCAã§ãŠãŒã¶ãŒã®èšŒææžã«çœ²åããŸããããŒã蚌ææžãã¯ã©ã€ã¢ã³ãæ§æãè¿œå ãããã£ã¬ã¯ããªãããã«äœæããŸãããã
# mkdir -p ~/client-configs/files/
# mkdir ~/client-configs/keys/
# chmod 700 ~/client-configs/
# sudo mkdir /etc/openvpn/vpnsrv1/
# ./easyrsa gen-req vpnsrv1 nopass
# ./easyrsa gen-req dumasti nopass
# ./easyrsa gen-dh
# sudo openvpn --genkey --secret ta.key
# cp /home/dumasti/easyrsa/pki/private/dumasti.key ~/client-configs/keys/
# sudo cp /home/dumasti/easyrsa/pki/dh.pem /etc/openvpn/vpnsrv1/
# sudo cp /home/dumasti/easyrsa/ta.key /etc/openvpn/vpnsrv1/
# sudo cp /home/dumasti/easyrsa/ta.key ~/client-configs/keys/
# sudo cp /home/dumasti/easyrsa/pki/private/vpnsrv1.key /etc/openvpn/vpnsrv1/
# scp ~/easyrsa/pki/reqs/vpnsrv1.req user@ip_RootCA:/tmp
# scp ~/easyrsa/pki/reqs/dumasti.req user@ip_SubCA:/tmp
RootCAãµãŒããŒã«ç§»åãã蚌ææžã«çœ²åããŸãããµãŒããŒã®èšŒææžã«çœ²åããã«ã¯ãã¯ã©ã€ã¢ã³ããclientãã®ãserverãå±æ§ã䜿çšããŸãã
# cd ~/easyrsa/
# ./easyrsa import-req /tmp/vpnsrv1.req vpnsrv1
# ./easyrsa sign-req server vpnsrv1
確èªãæ±ããããŸãã®ã§ããã¯ãããšå ¥åããŠãã ããã
# scp ~/easyrsa/pki/issued/vpnsrv1.crt user@ip_OpenVPN:/tmp
# scp ~/easyrsa/pki/ca.crt user@ip_OpenVPN:/tmp/RootCA.crt
SubCAãµãŒããŒã«ç§»åãã蚌ææžã«çœ²åããŸãã
# cd ~/easyrsa/
# ./easyrsa import-req /tmp/dumasti.req dumasti
# ./easyrsa sign-req client dumasti
確èªãæ±ããããŸãã®ã§ããã¯ãããšå ¥åããŠãã ããã
# scp ~/easyrsa/pki/issued/dumasti.crt user@ip_OpenVPN:/tmp
# scp ~/easyrsa/pki/ca.crt user@ip_OpenVPN:/tmp/SubCA.crt
OpenVPNãµãŒããŒã«æ»ãã眲åããã蚌ææžãå¿ èŠãªãã£ã¬ã¯ããªã«è»¢éããŸãã
# cd /tmp
OpenVPNãµãŒããŒãã¯ã©ã€ã¢ã³ãããŒãåãå ¥ããããã«ã¯ãã¯ã©ã€ã¢ã³ãã®å ¬éããŒãšåŸå±/眲åCAã1ã€ã®ãã¡ã€ã«ã«çµåããå¿ èŠããããŸãã
# cat dumasti.crt SubCA.crt > ~/client-configs/keys/dumasti.crt
# cp /tmp/RootCA.crt ~/client-configs/keys/ca.crt
# sudo mv /tmp/RootCA.crt /etc/openvpn/vpnsrv1/
# sudo mv /tmp/vpnsrv1.crt /etc/openvpn/vpnsrv1/
ããã§ãå¿ èŠãªãã¹ãŠã®èªå®ãé©åãªå Žæã«ãããŸããOpenVPNãµãŒããŒãšã¯ã©ã€ã¢ã³ãã®æ§æãäœæããããšã¯æ®ã£ãŠããŸãïŒããããããã®åé¡ã«é¢ããŠç¬èªã®ä¿¡å¿µãšèŠè§£ãæã£ãŠããå¯èœæ§ããããŸãããããšãã°ã次ã®æ§æããããŸãïŒã
ãµãŒããŒãšã¯ã©ã€ã¢ã³ãã®æ§æãã³ãã¬ãŒãã䜿çšããŠãèªåã§ç·šéã§ããŸãã
# sudo cp /usr/share/doc/openvpn/examples/sample-config-files/server.conf.gz /etc/openvpn/
# sudo gzip -d /etc/openvpn/server.conf.gz
# cp /usr/share/doc/openvpn/examples/sample-config-files/client.conf ~/client-configs/base.conf
ãããã以äžã«ãæ¢è£œã®æ§æãã¡ã€ã«ã®å 容ïŒèšå·;ããã³ïŒè¡ãã³ã¡ã³ãã¢ãŠãïŒã瀺ããŸãã
# sudo cat /etc/openvpn/vpnsrv1.conf
port 1194
proto udp
dev tun
ca vpnsrv1/RootCA.crt
cert vpnsrv1/vpnsrv1.crt
key vpnsrv1/vpnsrv1.key
dh vpnsrv1/dh.pem
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
;push "route 192.168.10.0 255.255.255.0"
;push "route 192.168.20.0 255.255.255.0"
;client-config-dir ccd
;client-config-dir ccd
push "redirect-gateway def1 bypass-dhcp"
push "dhcp-option DNS 208.67.222.222"
push "dhcp-option DNS 208.67.220.220"
client-to-client
;duplicate-cn
keepalive 10 120
tls-auth vpnsrv1/ta.key 0
key-direction 0
cipher AES-256-CBC
auth SHA256
max-clients 100
user nobody
group nogroup
persist-key
persist-tun
status /var/log/openvpn/openvpn-status.log
log-append /var/log/openvpn/openvpn.log
verb 3
;mute 20
explicit-exit-notify 1
# cat ~/client-configs/base.conf
client
dev tun
proto udp
remote your_server_ip 1194
;remote my-server-2 1194
;remote-random
resolv-retry infinite
nobind
user nobody
group nogroup
persist-key
persist-tun
remote-cert-tls server
;tls-auth ta.key 1
cipher AES-256-CBC
auth SHA256
key-direction 1
verb 3
;mute 20
# script-security 2
# up /etc/openvpn/update-resolv-conf
# down /etc/openvpn/update-resolv-conf
ãŸãããã¡ã€ã¢ãŠã©ãŒã«ãšãã±ãã転éãæ§æããå¿ èŠããããŸããiptablesãæ§æããããšã¯å¯èœã§ãããããã§ã¯ufwã«ã€ããŠèŠãŠãããŸãã
ãŸããã€ã³ã¿ãŒãã§ãŒã¹ã®ååãèŠã€ããŸãããã
# ip addr
次ã®ããŒããéããŸãããïŒããŒã22ã«sshãããã1194ã«openvpnããããŸããä»ã®ããŒããããå Žåã¯ãããã«å¿ããŠåäœããŸãïŒã
# sudo ufw allow 1194
# sudo ufw allow 22
次ã«ãufwæ§æãã¡ã€ã«ãéãããã£ã«ã¿ãŒãã§ãŒã³ã®éå§åã«ä»¥äžã貌ãä»ããŸãïŒç§ã®å€ãç¬èªã®å€ã«çœ®ãæããŸãïŒïŒ
# sudo vim /etc/ufw/before.rules
# START OPENVPN RULES
# NAT table rules
*nat
:POSTROUTING ACCEPT [0:0]
# Allow traffic from OpenVPN client to eth0 (change to the interface you discovered!)
-A POSTROUTING -s 10.8.0.0/8 -o ens192 -j MASQUERADE
COMMIT
# END OPENVPN RULES
ãã以åã¯ïŒ
# Don't delete these required lines, otherwise there will be errors
*filter
ããã©ã«ãã§ãã±ããã®UFW転éãæå¹ã«ããå¿ èŠããããŸããå¿ èŠãªè¡ãèŠã€ããŠãå€ãDROPãããACCEPTãã«å€æŽããŸãã
# sudo vim /etc/default/ufw
DEFAULT_FORWARD_POLICY="ACCEPT"
ãã±ãã転éã®æ§æãè¡ïŒnet.ipv4.ip_forward = 0ãŸãã¯ïŒnet.ipv4.ip_forward = 1ãèŠã€ããïŒãåé€ããŸããå€ã0ã®å Žåã¯ã1ã«å€æŽããŸãã
# sudo vim /etc/sysctl.conf
net.ipv4.ip_forward=1
# sudo sysctl -p
# sudo ufw enable
次ã«ãVPNãèµ·åããŸãã
# sudo systemctl start openvpn@vpnsrv1
ããŒã³ãã®ç¢ºèªïŒ
# ip addr
ip10.8.0.1ã®æ°ããtun0ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ãããã¯ãã§ã
# sudo systemctl status openvpn@vpnsrv1
åèµ·ååŸã«VPNãèªåçã«èµ·åããå¿ èŠãããå Žåã¯ããµãŒãã¹ãèªåå®è¡ã«è¿œå ããŸãã
# sudo systemctl enable openvpn@vpnsrv1
次ã«ãã¯ã©ã€ã¢ã³ãæ§æãäœæããŸãã以åã¯ããã¹ãŠã®ããŒãšèšŒææžãã/ client-configs / keys / directoryã«é 眮ããŸããã
æ§æãããŒãããã³èšŒææžã1ã€ã®ãã¡ã€ã«user.ovpnã«åéããã¹ã¯ãªãããäœæããŸãããã
# cd ~/client-configs/
# vim configs-maker.sh
#!/bin/bash
# First argument: Client identifier
KEY_DIR=/home/dumasti/client-configs/keys
OUTPUT_DIR=/home/dumasti/client-configs/files
BASE_CONFIG=/home/dumasti/client-configs/base.conf
cat ${BASE_CONFIG} \
<(echo -e '<ca>') \
${KEY_DIR}/ca.crt \
<(echo -e '</ca>\n<cert>') \
${KEY_DIR}/${1}.crt \
<(echo -e '</cert>\n<key>') \
${KEY_DIR}/${1}.key \
<(echo -e '</key>\n<tls-auth>') \
${KEY_DIR}/ta.key \
<(echo -e '</tls-auth>') \
> ${OUTPUT_DIR}/${1}.ovpn
ãã®ã¹ã¯ãªããã¯ãèµ·åæã«æå®ããååã®ãã¡ã€ã«ãåãåããfilesãã£ã¬ã¯ããªã«1ã€ã®ãã¡ã€ã«ãæ§æããŸãã
ãã¡ã€ã«ãå®è¡å¯èœã«ããŸãããïŒ
# chmod +x configs-maker.sh
ãããå®è¡ããŸãããïŒ
# sudo ./configs-maker.sh dumasti
ããã§ãã¯ã©ã€ã¢ã³ãæ§æã/ home / dumasti / client-configs / files / directoryããã³ã³ãã¥ãŒã¿ãŒã«è»¢éããŸã
ãVPNãéå§ããŸãã
ã»ãã¥ãªãã£äžã®çç±ãããCAããã¹ããããµãŒããŒã¯ã蚌ææžã«çœ²åããå Žåã«ã®ã¿ãªãã«ããŠãããªã³ã«ããå¿ èŠããããŸãã
蚌ææžã®å€±å¹ãç¡èŠããããšã¯ãããŸããã蚌ææžãåãæ¶ãã«ã¯ã蚌ææžã眲åãããCAãµãŒããŒã«ç§»åãã次ã®æé ãå®è¡ããŸãïŒããšãã°ãSubCAãµãŒããŒã§çœ²åãããŠãŒã¶ãŒèšŒææžïŒdumastiïŒãåãæ¶ããŸãïŒãSubCAãµãŒããŒã«ç§»åããŸãã
# cd ~/easyrsa/
# ./easyrsa revoke dumasti
倱å¹ã®ç¢ºèªãæ±ããããŸãã®ã§ããã¯ãããšå ¥åããŠãã ãã
# ./easyrsa gen-crl
crl.pemãã¡ã€ã«ãçæãããŸããããããOpenVPNãµãŒããŒã«é 眮ãããµãŒããŒæ§æã®ãã¡ã€ã«ã«ãã£ã¬ã¯ãã£ããšãã¹ãè¿œå ããå¿ èŠããããŸãã
# scp ~/easyrsa/pki/crl.pem user@ip_OpenVPN:/tmp
OpenVPNãµãŒããŒã«ç§»åããŸãã
# sudo mv /tmp/crl.pem /etc/openvpn/vpnsrv1/
# sudo vim /etc/openvpn/vpnsrv1.conf
ããŒãšèšŒææžãç»é²ãããŠããå Žæã«ã次ã®è¡ãè¿œå ããŸãã
crl-verify vpnsrv1/crl.pem
openvpnãåèµ·åããŸãã
# sudo systemctl restart openvpn@vpnsrv1
ããã§ãdumastiã¯ã©ã€ã¢ã³ãã¯VPNã«æ¥ç¶ã§ããªããªããŸãã
æž èŽããããšãããããŸããïŒ