3
Accept the default parameters, but insert for
Common Name
the value
server
.
4
Answer the next two questions (“Sign the certificate? [y/n]” and “1 out of 1 cer-
tificate requests certified, commit? [y/n]”) with
y
(yes).
After this procedure, the private server key is saved
/usr/share/openvpn/
easy-ca/keys/server.*
.
Procedure 16.3
Generate Certificates and Keys for a Client
1
Make sure your current directory is
/usr/share/openvpn/easy-ca
.
2
Create the key as in
Step 2
(page 188) from
Generate The Private Server Key
(page 188):
./build-key client
3
Repeat the previous step for each client that is allowed to connect to the VPN
server. Make sure you use a different name (other than “client”) and an appropriate
Common Name
, because this parameter has to be unique for each client.
After this procedure, the certificate client keys are saved in
/usr/share/openvpn/
easy-ca/keys/client.*
(depending on the name that you have given for the
build-key
command.)
Procedure 16.4
Some Final Configuration Steps
1
Make sure your current directory is
/usr/share/openvpn/easy-ca
.
2
Create the Diffie-Hellman parameter:
./build-dh
3
Copy the following files:
cp keys/ca.{crt,key} keys/dh1024.pem keys/server.{crt,key}
/etc/openvpn/ssl/
4
Copy the client keys to the respective client machine. You should have the files
client.crt
and
client.key
in the
/etc/openvpn/ssl
directory.
Configuring VPN Server
189
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......