diff --git a/install_openvpn.txt b/install_openvpn.txt index abd45f6..ce87e06 100644 --- a/install_openvpn.txt +++ b/install_openvpn.txt @@ -182,7 +182,9 @@ openvpn --genkey --secret $OPENVPN_BASE_DIR/keys/ta.key ## - Create empty CRL (Certificate Revokation List) ## - -openssl ca -gencrl -out /etc/openvpn/keys/crl.pem -config $KEY_CONFIG +#openssl ca -gencrl -out /etc/openvpn/keys/crl.pem -config $KEY_CONFIG +openssl ca -gencrl -out /etc/openvpn/crl.pem -config $KEY_CONFIG +ln -s ../crl.pem /etc/openvpn/keys/crl.pem cd $OPENVPN_BASE_DIR ln -s keys/crl.pem @@ -538,7 +540,8 @@ verb 4 # category will be output to the log. ;mute 20 -crl-verify /etc/openvpn/keys/crl.pem +#crl-verify /etc/openvpn/keys/crl.pem +crl-verify /etc/openvpn/crl.pem EOF @@ -865,7 +868,8 @@ verb 4 # category will be output to the log. ;mute 20 -crl-verify /etc/openvpn/keys/crl.pem +#crl-verify /etc/openvpn/keys/crl.pem +crl-verify /etc/openvpn/crl.pem EOF