This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
links:openvpn [2016/04/24 13:31] jdg [Generate the openssl.cnf file using above export] |
links:openvpn [2019/03/06 07:33] (current) |
||
---|---|---|---|
Line 208: | Line 208: | ||
- | ==== Set the paramters first ==== | + | ==== Set the parameters first ==== |
<code> | <code> | ||
Line 242: | Line 242: | ||
<code> | <code> | ||
- | #!/bin/sh | + | #!/bin/bash |
# run this script to generate "openssl.cnf" using the previously exported values | # run this script to generate "openssl.cnf" using the previously exported values | ||
# | # | ||
Line 376: | Line 376: | ||
<code> | <code> | ||
+ | # note: we don't need '-newkey rsa:2048 ' because config-file.default_bits = 2048 | ||
+ | |||
cd $tls_cert_dir/ ; | cd $tls_cert_dir/ ; | ||
/usr/bin/openssl req \ | /usr/bin/openssl req \ | ||
- | -days 3650 -nodes -newkey rsa:2048 -new -x509 \ | + | -days 3650 -nodes -new -x509 \ |
-keyout "$tls_ca_CN.key" \ | -keyout "$tls_ca_CN.key" \ | ||
-out "$tls_ca_CN.crt" \ | -out "$tls_ca_CN.crt" \ |