From ef7c1647a164f50c12168e37b2035aa1b66342da Mon Sep 17 00:00:00 2001 From: unknown <31184695+GHOSCHT@users.noreply.github.com> Date: Thu, 20 May 2021 17:08:23 +0200 Subject: [PATCH] Use tls-crypt instead of tls-auth https://github.com/kylemanna/docker-openvpn/pull/501 --- bin/ovpn_genconfig | 2 +- bin/ovpn_getclient | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/bin/ovpn_genconfig b/bin/ovpn_genconfig index c2ebca6c..2d4694ec 100755 --- a/bin/ovpn_genconfig +++ b/bin/ovpn_genconfig @@ -324,7 +324,7 @@ key $EASYRSA_PKI/private/${OVPN_CN}.key ca $EASYRSA_PKI/ca.crt cert $EASYRSA_PKI/issued/${OVPN_CN}.crt dh $EASYRSA_PKI/dh.pem -tls-auth $EASYRSA_PKI/ta.key +tls-crypt $EASYRSA_PKI/ta.key key-direction 0 keepalive $OVPN_KEEPALIVE persist-key diff --git a/bin/ovpn_getclient b/bin/ovpn_getclient index 092aeea9..24d9959a 100755 --- a/bin/ovpn_getclient +++ b/bin/ovpn_getclient @@ -59,16 +59,16 @@ $(openssl x509 -in $EASYRSA_PKI/issued/${cn}.crt) $(cat $EASYRSA_PKI/ca.crt) key-direction 1 - + $(cat $EASYRSA_PKI/ta.key) - + " elif [ "$mode" == "separated" ]; then echo " key ${cn}.key ca ca.crt cert ${cn}.crt -tls-auth ta.key 1 +tls-crypt ta.key 1 " fi