2013-05-14 14:04:19 +02:00
#!/bin/bash
2020-10-21 13:59:49 +02:00
# shellcheck disable=SC1091,SC2164,SC2034,SC1072,SC1073,SC1009
2013-05-14 14:04:19 +02:00
2021-08-27 15:24:53 +02:00
# Secure OpenVPN server installer for Debian, Ubuntu, CentOS, Amazon Linux 2, Fedora, Oracle Linux 8, Arch Linux, Rocky Linux and AlmaLinux.
2018-09-20 17:16:04 +02:00
# https://github.com/angristan/openvpn-install
2013-05-14 14:04:19 +02:00
2020-04-27 14:59:19 +02:00
function isRoot( ) {
2018-09-20 00:05:02 +02:00
if [ " $EUID " -ne 0 ] ; then
return 1
fi
}
2013-05-14 14:04:19 +02:00
2020-04-27 14:59:19 +02:00
function tunAvailable( ) {
2018-09-20 00:05:02 +02:00
if [ ! -e /dev/net/tun ] ; then
return 1
fi
}
2014-03-12 21:06:57 +01:00
2022-09-16 16:00:44 +02:00
function serverChoice( ) {
if [ [ ! " $SERVER_ID " ] ] ; then
SERVER_ID = "server"
echo "Server name not defined using default server name"
else
# prepend 'server.' to the server_id
SERVER_ID = " server. $SERVER_ID "
fi
# Get the higher subnet second octet and start from there
if [ [ ! " $SERVER_SUBNET " ] ] ; then
if [ [ ! -e /etc/openvpn/$SERVER_ID .conf ] ] ; then
SERVER_SUBNET = $(( $( cat /etc/openvpn/server.*.conf | grep server | sed -e "s|server ||g" | cut -d . -f 2 | sort -n | tail -1) + 1 ))
echo " Server not defined using next +1 subnet ( $SERVER_SUBNET ) "
else
SERVER_SUBNET = $( cat /etc/openvpn/$SERVER_ID .conf | grep server | sed -e "s|server ||g" | cut -d . -f 2 | sort -n | tail -1)
#Server defined using used subnet
fi
fi
inrange = '\b(1?[0-9]{1,2}|2[0-4][0-9]|25[0-5])\b'
if ! [ [ $SERVER_SUBNET = ~ $inrange ] ] ; then
echo " Subnet second octet cannot be $SERVER_SUBNET "
return 1
fi
# if server name is not defined get the higher port and define next there
#if [[ ! -e /etc/openvpn/$SERVER_ID/$SERVER_ID.conf ]]; then
# PORT=confs/*.conf | grep port | sed -e "s|port ||g"| sort -n | tail -1
#fi
}
2020-04-27 14:59:19 +02:00
function checkOS( ) {
2018-09-20 00:05:02 +02:00
if [ [ -e /etc/debian_version ] ] ; then
2018-09-29 20:14:44 +02:00
OS = "debian"
2018-09-20 22:00:16 +02:00
source /etc/os-release
2018-09-23 22:22:59 +02:00
2020-04-27 14:59:19 +02:00
if [ [ $ID = = "debian" || $ID = = "raspbian" ] ] ; then
2020-07-28 12:24:57 +02:00
if [ [ $VERSION_ID -lt 9 ] ] ; then
2018-09-23 22:22:59 +02:00
echo "⚠️ Your version of Debian is not supported."
echo ""
2020-07-28 12:24:57 +02:00
echo "However, if you're using Debian >= 9 or unstable/testing then you can continue, at your own risk."
2018-09-23 22:22:59 +02:00
echo ""
until [ [ $CONTINUE = ~ ( y| n) ] ] ; do
read -rp "Continue? [y/n]: " -e CONTINUE
done
2020-04-27 14:59:19 +02:00
if [ [ $CONTINUE = = "n" ] ] ; then
2018-09-23 22:22:59 +02:00
exit 1
fi
fi
2020-04-27 14:59:19 +02:00
elif [ [ $ID = = "ubuntu" ] ] ; then
2018-09-23 22:22:59 +02:00
OS = "ubuntu"
2020-04-27 13:35:32 +02:00
MAJOR_UBUNTU_VERSION = $( echo " $VERSION_ID " | cut -d '.' -f1)
if [ [ $MAJOR_UBUNTU_VERSION -lt 16 ] ] ; then
2018-09-23 22:22:59 +02:00
echo "⚠️ Your version of Ubuntu is not supported."
echo ""
2020-04-27 13:35:32 +02:00
echo "However, if you're using Ubuntu >= 16.04 or beta, then you can continue, at your own risk."
2018-09-23 22:22:59 +02:00
echo ""
until [ [ $CONTINUE = ~ ( y| n) ] ] ; do
read -rp "Continue? [y/n]: " -e CONTINUE
done
2020-04-27 14:59:19 +02:00
if [ [ $CONTINUE = = "n" ] ] ; then
2018-09-23 22:22:59 +02:00
exit 1
fi
2018-09-20 00:05:02 +02:00
fi
2017-11-12 22:51:54 +01:00
fi
2019-08-19 23:25:48 +02:00
elif [ [ -e /etc/system-release ] ] ; then
source /etc/os-release
2021-02-14 10:54:53 +01:00
if [ [ $ID = = "fedora" || $ID_LIKE = = "fedora" ] ] ; then
2020-01-27 18:08:06 +01:00
OS = "fedora"
fi
2021-08-27 15:24:53 +02:00
if [ [ $ID = = "centos" || $ID = = "rocky" || $ID = = "almalinux" ] ] ; then
2019-08-20 13:36:16 +02:00
OS = "centos"
2019-11-11 07:18:34 +01:00
if [ [ ! $VERSION_ID = ~ ( 7| 8) ] ] ; then
2019-08-20 13:36:16 +02:00
echo "⚠️ Your version of CentOS is not supported."
echo ""
2020-06-27 12:30:20 +02:00
echo "The script only support CentOS 7 and CentOS 8."
2019-08-20 13:36:16 +02:00
echo ""
exit 1
fi
fi
2021-03-22 10:48:15 +01:00
if [ [ $ID = = "ol" ] ] ; then
OS = "oracle"
if [ [ ! $VERSION_ID = ~ ( 8) ] ] ; then
echo "Your version of Oracle Linux is not supported."
echo ""
echo "The script only support Oracle Linux 8."
exit 1
fi
fi
2020-04-27 14:59:19 +02:00
if [ [ $ID = = "amzn" ] ] ; then
2019-08-19 23:25:48 +02:00
OS = "amzn"
2020-04-27 14:59:19 +02:00
if [ [ $VERSION_ID != "2" ] ] ; then
2019-08-19 23:25:48 +02:00
echo "⚠️ Your version of Amazon Linux is not supported."
echo ""
echo "The script only support Amazon Linux 2."
echo ""
exit 1
fi
fi
2018-09-23 16:27:36 +02:00
elif [ [ -e /etc/arch-release ] ] ; then
OS = arch
2018-09-20 00:05:02 +02:00
else
2021-03-22 10:48:15 +01:00
echo "Looks like you aren't running this installer on a Debian, Ubuntu, Fedora, CentOS, Amazon Linux 2, Oracle Linux 8 or Arch Linux system"
2018-09-20 00:05:02 +02:00
exit 1
2018-09-16 01:26:30 +02:00
fi
2018-09-20 00:05:02 +02:00
}
2013-05-14 14:04:19 +02:00
2020-04-27 14:59:19 +02:00
function initialCheck( ) {
2018-09-20 00:05:02 +02:00
if ! isRoot; then
echo "Sorry, you need to run this as root"
exit 1
2017-11-12 22:51:54 +01:00
fi
2018-09-20 00:05:02 +02:00
if ! tunAvailable; then
echo "TUN is not available"
exit 1
fi
2022-09-16 16:00:44 +02:00
if ! serverChoice; then
exit 1;
fi
2018-09-20 00:05:02 +02:00
checkOS
2014-10-23 00:19:08 +02:00
}
2020-04-27 14:59:19 +02:00
function installUnbound( ) {
2020-04-27 13:56:34 +02:00
# If Unbound isn't installed, install it
2018-09-16 00:53:33 +02:00
if [ [ ! -e /etc/unbound/unbound.conf ] ] ; then
2020-04-27 14:59:19 +02:00
if [ [ $OS = ~ ( debian| ubuntu) ] ] ; then
2018-09-16 00:53:33 +02:00
apt-get install -y unbound
2018-09-20 00:05:02 +02:00
# Configuration
2018-09-16 00:53:33 +02:00
echo ' interface: 10.8.0.1
access-control: 10.8.0.1/24 allow
hide-identity: yes
hide-version: yes
use-caps-for-id: yes
2020-04-27 14:59:19 +02:00
prefetch: yes' >>/etc/unbound/unbound.conf
2018-09-16 00:53:33 +02:00
2021-03-22 10:48:15 +01:00
elif [ [ $OS = ~ ( centos| amzn| oracle) ] ] ; then
2018-09-16 00:53:33 +02:00
yum install -y unbound
# Configuration
sed -i 's|# interface: 0.0.0.0$|interface: 10.8.0.1|' /etc/unbound/unbound.conf
sed -i 's|# access-control: 127.0.0.0/8 allow|access-control: 10.8.0.1/24 allow|' /etc/unbound/unbound.conf
sed -i 's|# hide-identity: no|hide-identity: yes|' /etc/unbound/unbound.conf
sed -i 's|# hide-version: no|hide-version: yes|' /etc/unbound/unbound.conf
sed -i 's|use-caps-for-id: no|use-caps-for-id: yes|' /etc/unbound/unbound.conf
2020-04-27 14:59:19 +02:00
elif [ [ $OS = = "fedora" ] ] ; then
2018-09-16 00:53:33 +02:00
dnf install -y unbound
# Configuration
sed -i 's|# interface: 0.0.0.0$|interface: 10.8.0.1|' /etc/unbound/unbound.conf
sed -i 's|# access-control: 127.0.0.0/8 allow|access-control: 10.8.0.1/24 allow|' /etc/unbound/unbound.conf
sed -i 's|# hide-identity: no|hide-identity: yes|' /etc/unbound/unbound.conf
sed -i 's|# hide-version: no|hide-version: yes|' /etc/unbound/unbound.conf
sed -i 's|# use-caps-for-id: no|use-caps-for-id: yes|' /etc/unbound/unbound.conf
2018-09-23 16:27:36 +02:00
2020-04-27 14:59:19 +02:00
elif [ [ $OS = = "arch" ] ] ; then
2018-09-23 16:27:36 +02:00
pacman -Syu --noconfirm unbound
# Get root servers list
curl -o /etc/unbound/root.hints https://www.internic.net/domain/named.cache
2020-04-27 13:56:34 +02:00
if [ [ ! -f /etc/unbound/unbound.conf.old ] ] ; then
mv /etc/unbound/unbound.conf /etc/unbound/unbound.conf.old
fi
2019-06-30 23:06:33 +02:00
2018-09-23 16:27:36 +02:00
echo ' server:
use-syslog: yes
do -daemonize: no
username: "unbound"
directory: "/etc/unbound"
trust-anchor-file: trusted-key.key
root-hints: root.hints
interface: 10.8.0.1
access-control: 10.8.0.1/24 allow
port: 53
num-threads: 2
use-caps-for-id: yes
harden-glue: yes
hide-identity: yes
hide-version: yes
qname-minimisation: yes
2020-04-27 14:59:19 +02:00
prefetch: yes' >/etc/unbound/unbound.conf
2018-09-16 00:53:33 +02:00
fi
2020-05-01 00:10:11 +02:00
2020-05-01 00:04:38 +02:00
# IPv6 DNS for all OS
2020-05-01 00:10:11 +02:00
if [ [ $IPV6_SUPPORT = = 'y' ] ] ; then
2020-05-01 00:04:38 +02:00
echo ' interface: fd42:42:42:42::1
2020-05-01 00:10:11 +02:00
access-control: fd42:42:42:42::/112 allow' >>/etc/unbound/unbound.conf
2020-05-01 00:04:38 +02:00
fi
2018-09-16 00:53:33 +02:00
2021-03-22 10:48:15 +01:00
if [ [ ! $OS = ~ ( fedora| centos| amzn| oracle) ] ] ; then
2018-09-16 00:53:33 +02:00
# DNS Rebinding fix
echo " private-address: 10.0.0.0/8
2020-05-01 00:04:38 +02:00
private-address: fd42:42:42:42::/112
2018-09-20 00:05:02 +02:00
private-address: 172.16.0.0/12
private-address: 192.168.0.0/16
private-address: 169.254.0.0/16
private-address: fd00::/8
private-address: fe80::/10
private-address: 127.0.0.0/8
2020-04-27 14:59:19 +02:00
private-address: ::ffff:0:0/96" >>/etc/unbound/unbound.conf
2018-09-16 00:53:33 +02:00
fi
2018-09-20 00:05:02 +02:00
else # Unbound is already installed
2020-04-27 14:59:19 +02:00
echo 'include: /etc/unbound/openvpn.conf' >>/etc/unbound/unbound.conf
2018-09-16 00:53:33 +02:00
2018-09-20 00:05:02 +02:00
# Add Unbound 'server' for the OpenVPN subnet
2018-09-16 00:53:33 +02:00
echo ' server:
interface: 10.8.0.1
access-control: 10.8.0.1/24 allow
hide-identity: yes
hide-version: yes
use-caps-for-id: yes
prefetch: yes
private-address: 10.0.0.0/8
2020-05-01 00:04:38 +02:00
private-address: fd42:42:42:42::/112
2018-09-16 00:53:33 +02:00
private-address: 172.16.0.0/12
private-address: 192.168.0.0/16
private-address: 169.254.0.0/16
private-address: fd00::/8
private-address: fe80::/10
private-address: 127.0.0.0/8
2020-05-01 00:10:11 +02:00
private-address: ::ffff:0:0/96' >/etc/unbound/openvpn.conf
if [ [ $IPV6_SUPPORT = = 'y' ] ] ; then
2020-05-01 00:04:38 +02:00
echo ' interface: fd42:42:42:42::1
2020-05-01 00:10:11 +02:00
access-control: fd42:42:42:42::/112 allow' >>/etc/unbound/openvpn.conf
2020-05-01 00:04:38 +02:00
fi
2018-09-16 00:53:33 +02:00
fi
2020-04-27 14:59:19 +02:00
systemctl enable unbound
systemctl restart unbound
2018-09-16 00:53:33 +02:00
}
2020-04-27 14:59:19 +02:00
function installQuestions( ) {
2018-09-20 00:05:02 +02:00
echo "Welcome to the OpenVPN installer!"
echo "The git repository is available at: https://github.com/angristan/openvpn-install"
2017-11-12 22:51:54 +01:00
echo ""
2018-07-15 11:25:59 +02:00
2018-09-20 00:05:02 +02:00
echo "I need to ask you a few questions before starting the setup."
echo "You can leave the default options and just press enter if you are ok with them."
2017-11-12 22:51:54 +01:00
echo ""
echo "I need to know the IPv4 address of the network interface you want OpenVPN listening to."
2018-09-21 21:53:39 +02:00
echo "Unless your server is behind NAT, it should be your public IPv4 address."
2018-07-15 11:25:59 +02:00
2018-09-20 00:05:02 +02:00
# Detect public IPv4 address and pre-fill for the user
2022-09-16 16:00:44 +02:00
# First detect not private IPS
IP = $( ip -4 addr show type veth| sed -ne 's|^.* inet \([^/]*\)/.* scope global.*$|\1|p' | grep -vE '^(10\.|172\.1[6789]\.|172\.2[0-9]\.|172\.3[01]\.|192\.168)' | head -1)
# If no public ip found fallback to search all including privates
if [ [ -z $IP ] ] ; then
IP = $( ip -4 addr show type veth| sed -ne 's|^.* inet \([^/]*\)/.* scope global.*$|\1|p' | head -1)
fi
2020-10-20 16:42:35 +02:00
2020-04-27 16:25:20 +02:00
if [ [ -z $IP ] ] ; then
2020-04-27 16:24:30 +02:00
# Detect public IPv6 address
IP = $( ip -6 addr | sed -ne 's|^.* inet6 \([^/]*\)/.* scope global.*$|\1|p' | head -1)
fi
2019-02-25 20:02:50 +01:00
APPROVE_IP = ${ APPROVE_IP :- n }
if [ [ $APPROVE_IP = ~ n ] ] ; then
read -rp "IP address: " -e -i " $IP " IP
fi
2018-09-16 17:55:50 +02:00
# If $IP is a private IP address, the server must be behind NAT
if echo " $IP " | grep -qE '^(10\.|172\.1[6789]\.|172\.2[0-9]\.|172\.3[01]\.|192\.168)' ; then
echo ""
2018-09-22 16:17:51 +02:00
echo "It seems this server is behind NAT. What is its public IPv4 address or hostname?"
2018-09-21 21:53:39 +02:00
echo "We need it for the clients to connect to the server."
2020-10-20 16:42:35 +02:00
2020-10-20 16:31:12 +02:00
PUBLICIP = $( curl -s https://api.ipify.org)
2020-04-27 14:59:19 +02:00
until [ [ $ENDPOINT != "" ] ] ; do
2020-10-20 16:31:12 +02:00
read -rp "Public IPv4 address or hostname: " -e -i " $PUBLICIP " ENDPOINT
2018-09-21 21:53:39 +02:00
done
2018-09-16 17:55:50 +02:00
fi
2018-09-20 00:05:02 +02:00
2018-09-16 17:55:50 +02:00
echo ""
echo "Checking for IPv6 connectivity..."
echo ""
2018-10-01 21:00:26 +02:00
# "ping6" and "ping -6" availability varies depending on the distribution
2020-04-27 14:59:19 +02:00
if type ping6 >/dev/null 2>& 1; then
2018-10-01 21:00:26 +02:00
PING6 = "ping6 -c3 ipv6.google.com > /dev/null 2>&1"
else
PING6 = "ping -6 -c3 ipv6.google.com > /dev/null 2>&1"
fi
if eval " $PING6 " ; then
2018-09-16 17:55:50 +02:00
echo "Your host appears to have IPv6 connectivity."
2018-09-20 00:05:02 +02:00
SUGGESTION = "y"
2018-09-16 17:55:50 +02:00
else
echo "Your host does not appear to have IPv6 connectivity."
2018-09-20 00:05:02 +02:00
SUGGESTION = "n"
2018-09-16 17:55:50 +02:00
fi
echo ""
2018-09-20 00:05:02 +02:00
# Ask the user if they want to enable IPv6 regardless its availability.
2018-09-22 15:23:01 +02:00
until [ [ $IPV6_SUPPORT = ~ ( y| n) ] ] ; do
2018-09-20 00:05:02 +02:00
read -rp "Do you want to enable IPv6 support (NAT)? [y/n]: " -e -i $SUGGESTION IPV6_SUPPORT
2018-09-16 17:55:50 +02:00
done
2017-11-12 22:51:54 +01:00
echo ""
2018-09-20 00:05:02 +02:00
echo "What port do you want OpenVPN to listen to?"
2018-08-18 15:57:24 +02:00
echo " 1) Default: 1194"
echo " 2) Custom"
echo " 3) Random [49152-65535]"
2020-04-27 14:59:19 +02:00
until [ [ $PORT_CHOICE = ~ ^[ 1-3] $ ] ] ; do
2018-09-21 23:48:11 +02:00
read -rp "Port choice [1-3]: " -e -i 1 PORT_CHOICE
2018-08-18 15:57:24 +02:00
done
case $PORT_CHOICE in
2020-04-27 14:59:19 +02:00
1)
PORT = "1194"
2018-08-18 15:57:24 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
until [ [ $PORT = ~ ^[ 0-9] +$ ] ] && [ " $PORT " -ge 1 ] && [ " $PORT " -le 65535 ] ; do
read -rp "Custom port [1-65535]: " -e -i 1194 PORT
done
2018-08-18 15:57:24 +02:00
; ;
2020-04-27 14:59:19 +02:00
3)
# Generate random number within private ports range
PORT = $( shuf -i49152-65535 -n1)
echo " Random Port: $PORT "
2018-08-18 15:57:24 +02:00
; ;
esac
2017-11-12 22:51:54 +01:00
echo ""
2018-09-20 00:05:02 +02:00
echo "What protocol do you want OpenVPN to use?"
2018-09-28 16:36:00 +02:00
echo "UDP is faster. Unless it is not available, you shouldn't use TCP."
2018-09-20 00:05:02 +02:00
echo " 1) UDP"
echo " 2) TCP"
2020-04-27 14:59:19 +02:00
until [ [ $PROTOCOL_CHOICE = ~ ^[ 1-2] $ ] ] ; do
2018-09-20 00:05:02 +02:00
read -rp "Protocol [1-2]: " -e -i 1 PROTOCOL_CHOICE
2017-11-12 22:51:54 +01:00
done
2018-09-20 00:05:02 +02:00
case $PROTOCOL_CHOICE in
2020-04-27 14:59:19 +02:00
1)
PROTOCOL = "udp"
2018-09-20 00:05:02 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
PROTOCOL = "tcp"
2018-09-20 00:05:02 +02:00
; ;
esac
2017-11-12 22:51:54 +01:00
echo ""
2018-09-20 00:05:02 +02:00
echo "What DNS resolvers do you want to use with the VPN?"
2017-11-29 11:17:06 +01:00
echo " 1) Current system resolvers (from /etc/resolv.conf)"
2018-09-16 00:53:33 +02:00
echo " 2) Self-hosted DNS Resolver (Unbound)"
echo " 3) Cloudflare (Anycast: worldwide)"
echo " 4) Quad9 (Anycast: worldwide)"
2018-09-24 11:42:29 +02:00
echo " 5) Quad9 uncensored (Anycast: worldwide)"
echo " 6) FDN (France)"
echo " 7) DNS.WATCH (Germany)"
echo " 8) OpenDNS (Anycast: worldwide)"
echo " 9) Google (Anycast: worldwide)"
echo " 10) Yandex Basic (Russia)"
2020-03-31 23:05:44 +02:00
echo " 11) AdGuard DNS (Anycast: worldwide)"
echo " 12) NextDNS (Anycast: worldwide)"
2020-03-03 23:04:18 +01:00
echo " 13) Custom"
2020-04-27 14:59:19 +02:00
until [ [ $DNS = ~ ^[ 0-9] +$ ] ] && [ " $DNS " -ge 1 ] && [ " $DNS " -le 13 ] ; do
2020-06-29 09:09:38 +02:00
read -rp "DNS [1-12]: " -e -i 11 DNS
2020-04-27 14:59:19 +02:00
if [ [ $DNS = = 2 ] ] && [ [ -e /etc/unbound/unbound.conf ] ] ; then
echo ""
echo "Unbound is already installed."
echo "You can allow the script to configure it in order to use it from your OpenVPN clients"
echo "We will simply add a second server to /etc/unbound/unbound.conf for the OpenVPN subnet."
echo "No changes are made to the current configuration."
echo ""
until [ [ $CONTINUE = ~ ( y| n) ] ] ; do
read -rp "Apply configuration changes to Unbound? [y/n]: " -e CONTINUE
done
if [ [ $CONTINUE = = "n" ] ] ; then
# Break the loop and cleanup
unset DNS
unset CONTINUE
2018-09-16 00:53:33 +02:00
fi
2020-04-27 14:59:19 +02:00
elif [ [ $DNS = = "13" ] ] ; then
until [ [ $DNS1 = ~ ^( ( 25[ 0-5] | 2[ 0-4] [ 0-9] | [ 01] ?[ 0-9] [ 0-9] ?) \. ) { 3} ( 25[ 0-5] | 2[ 0-4] [ 0-9] | [ 01] ?[ 0-9] [ 0-9] ?) $ ] ] ; do
read -rp "Primary DNS: " -e DNS1
done
until [ [ $DNS2 = ~ ^( ( 25[ 0-5] | 2[ 0-4] [ 0-9] | [ 01] ?[ 0-9] [ 0-9] ?) \. ) { 3} ( 25[ 0-5] | 2[ 0-4] [ 0-9] | [ 01] ?[ 0-9] [ 0-9] ?) $ ] ] ; do
read -rp "Secondary DNS (optional): " -e DNS2
if [ [ $DNS2 = = "" ] ] ; then
break
fi
done
fi
2017-11-12 22:51:54 +01:00
done
echo ""
2021-10-20 14:06:11 +02:00
echo "Do you want to use compression? It is not recommended since the VORACLE attack makes use of it."
2018-09-22 14:07:51 +02:00
until [ [ $COMPRESSION_ENABLED = ~ ( y| n) ] ] ; do
2018-09-22 16:42:48 +02:00
read -rp"Enable compression? [y/n]: " -e -i n COMPRESSION_ENABLED
2018-09-22 14:07:51 +02:00
done
2020-04-27 14:59:19 +02:00
if [ [ $COMPRESSION_ENABLED = = "y" ] ] ; then
2019-07-05 17:49:31 +02:00
echo "Choose which compression algorithm you want to use: (they are ordered by efficiency)"
echo " 1) LZ4-v2"
echo " 2) LZ4"
echo " 3) LZ0"
until [ [ $COMPRESSION_CHOICE = ~ ^[ 1-3] $ ] ] ; do
read -rp"Compression algorithm [1-3]: " -e -i 1 COMPRESSION_CHOICE
2018-09-22 14:07:51 +02:00
done
case $COMPRESSION_CHOICE in
2020-04-27 14:59:19 +02:00
1)
2019-07-05 17:49:31 +02:00
COMPRESSION_ALG = "lz4-v2"
2018-09-22 14:07:51 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
2019-07-05 17:49:31 +02:00
COMPRESSION_ALG = "lz4"
; ;
2020-04-27 14:59:19 +02:00
3)
2018-09-22 14:07:51 +02:00
COMPRESSION_ALG = "lzo"
; ;
esac
fi
echo ""
2018-09-21 17:17:41 +02:00
echo "Do you want to customize encryption settings?"
echo "Unless you know what you're doing, you should stick with the default parameters provided by the script."
echo "Note that whatever you choose, all the choices presented in the script are safe. (Unlike OpenVPN's defaults)"
2018-09-24 11:45:12 +02:00
echo "See https://github.com/angristan/openvpn-install#security-and-encryption to learn more."
2018-09-20 00:05:02 +02:00
echo ""
2018-09-21 17:17:41 +02:00
until [ [ $CUSTOMIZE_ENC = ~ ( y| n) ] ] ; do
read -rp "Customize encryption settings? [y/n]: " -e -i n CUSTOMIZE_ENC
2017-11-12 22:51:54 +01:00
done
2020-04-27 14:59:19 +02:00
if [ [ $CUSTOMIZE_ENC = = "n" ] ] ; then
2018-09-28 16:36:00 +02:00
# Use default, sane and fast parameters
2018-09-22 22:33:25 +02:00
CIPHER = "AES-128-GCM"
CERT_TYPE = "1" # ECDSA
2018-09-23 17:06:15 +02:00
CERT_CURVE = "prime256v1"
2018-09-22 15:11:15 +02:00
CC_CIPHER = "TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
2018-09-22 22:33:25 +02:00
DH_TYPE = "1" # ECDH
2018-09-23 17:06:15 +02:00
DH_CURVE = "prime256v1"
2018-09-22 17:51:38 +02:00
HMAC_ALG = "SHA256"
2018-09-22 22:34:10 +02:00
TLS_SIG = "1" # tls-crypt
2018-09-21 17:17:41 +02:00
else
echo ""
echo "Choose which cipher you want to use for the data channel:"
2018-09-22 14:20:20 +02:00
echo " 1) AES-128-GCM (recommended)"
echo " 2) AES-192-GCM"
echo " 3) AES-256-GCM"
echo " 4) AES-128-CBC"
echo " 5) AES-192-CBC"
echo " 6) AES-256-CBC"
2020-04-27 14:59:19 +02:00
until [ [ $CIPHER_CHOICE = ~ ^[ 1-6] $ ] ] ; do
2018-09-22 14:20:20 +02:00
read -rp "Cipher [1-6]: " -e -i 1 CIPHER_CHOICE
2018-09-21 17:17:41 +02:00
done
case $CIPHER_CHOICE in
2020-04-27 14:59:19 +02:00
1)
CIPHER = "AES-128-GCM"
2018-09-21 17:17:41 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
CIPHER = "AES-192-GCM"
2018-09-21 17:17:41 +02:00
; ;
2020-04-27 14:59:19 +02:00
3)
CIPHER = "AES-256-GCM"
2018-09-22 14:20:20 +02:00
; ;
2020-04-27 14:59:19 +02:00
4)
CIPHER = "AES-128-CBC"
2018-09-22 14:20:20 +02:00
; ;
2020-04-27 14:59:19 +02:00
5)
CIPHER = "AES-192-CBC"
2018-09-22 14:20:20 +02:00
; ;
2020-04-27 14:59:19 +02:00
6)
CIPHER = "AES-256-CBC"
2018-09-21 17:17:41 +02:00
; ;
esac
echo ""
2018-09-28 16:36:00 +02:00
echo "Choose what kind of certificate you want to use:"
2018-09-22 15:11:15 +02:00
echo " 1) ECDSA (recommended)"
echo " 2) RSA"
2018-09-22 15:23:01 +02:00
until [ [ $CERT_TYPE = ~ ^[ 1-2] $ ] ] ; do
2018-09-22 16:42:48 +02:00
read -rp"Certificate key type [1-2]: " -e -i 1 CERT_TYPE
2018-09-21 17:17:41 +02:00
done
2018-09-22 15:11:15 +02:00
case $CERT_TYPE in
2020-04-27 14:59:19 +02:00
1)
echo ""
echo "Choose which curve you want to use for the certificate's key:"
echo " 1) prime256v1 (recommended)"
echo " 2) secp384r1"
echo " 3) secp521r1"
until [ [ $CERT_CURVE_CHOICE = ~ ^[ 1-3] $ ] ] ; do
read -rp"Curve [1-3]: " -e -i 1 CERT_CURVE_CHOICE
done
case $CERT_CURVE_CHOICE in
2018-09-21 17:17:41 +02:00
1)
2020-04-27 14:59:19 +02:00
CERT_CURVE = "prime256v1"
; ;
2)
CERT_CURVE = "secp384r1"
; ;
3)
CERT_CURVE = "secp521r1"
; ;
esac
2018-09-21 17:17:41 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
echo ""
echo "Choose which size you want to use for the certificate's RSA key:"
echo " 1) 2048 bits (recommended)"
echo " 2) 3072 bits"
echo " 3) 4096 bits"
until [ [ $RSA_KEY_SIZE_CHOICE = ~ ^[ 1-3] $ ] ] ; do
read -rp "RSA key size [1-3]: " -e -i 1 RSA_KEY_SIZE_CHOICE
done
case $RSA_KEY_SIZE_CHOICE in
1)
RSA_KEY_SIZE = "2048"
; ;
2018-09-21 17:17:41 +02:00
2)
2020-04-27 14:59:19 +02:00
RSA_KEY_SIZE = "3072"
; ;
3)
RSA_KEY_SIZE = "4096"
; ;
esac
2018-09-21 17:17:41 +02:00
; ;
2018-09-22 15:11:15 +02:00
esac
echo ""
echo "Choose which cipher you want to use for the control channel:"
case $CERT_TYPE in
2020-04-27 14:59:19 +02:00
1)
echo " 1) ECDHE-ECDSA-AES-128-GCM-SHA256 (recommended)"
echo " 2) ECDHE-ECDSA-AES-256-GCM-SHA384"
until [ [ $CC_CIPHER_CHOICE = ~ ^[ 1-2] $ ] ] ; do
read -rp"Control channel cipher [1-2]: " -e -i 1 CC_CIPHER_CHOICE
done
case $CC_CIPHER_CHOICE in
2018-09-22 15:11:15 +02:00
1)
2020-04-27 14:59:19 +02:00
CC_CIPHER = "TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256"
; ;
2)
CC_CIPHER = "TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384"
; ;
esac
2018-09-22 15:11:15 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
echo " 1) ECDHE-RSA-AES-128-GCM-SHA256 (recommended)"
echo " 2) ECDHE-RSA-AES-256-GCM-SHA384"
until [ [ $CC_CIPHER_CHOICE = ~ ^[ 1-2] $ ] ] ; do
read -rp"Control channel cipher [1-2]: " -e -i 1 CC_CIPHER_CHOICE
done
case $CC_CIPHER_CHOICE in
1)
CC_CIPHER = "TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256"
; ;
2018-09-22 15:11:15 +02:00
2)
2020-04-27 14:59:19 +02:00
CC_CIPHER = "TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384"
; ;
esac
2018-09-21 17:17:41 +02:00
; ;
esac
echo ""
2018-09-28 16:36:00 +02:00
echo "Choose what kind of Diffie-Hellman key you want to use:"
2018-09-22 16:41:28 +02:00
echo " 1) ECDH (recommended)"
echo " 2) DH"
until [ [ $DH_TYPE = ~ [ 1-2] ] ] ; do
2018-09-22 16:42:48 +02:00
read -rp"DH key type [1-2]: " -e -i 1 DH_TYPE
2018-09-21 17:17:41 +02:00
done
2018-09-22 16:41:28 +02:00
case $DH_TYPE in
2020-04-27 14:59:19 +02:00
1)
echo ""
echo "Choose which curve you want to use for the ECDH key:"
echo " 1) prime256v1 (recommended)"
echo " 2) secp384r1"
echo " 3) secp521r1"
while [ [ $DH_CURVE_CHOICE != "1" && $DH_CURVE_CHOICE != "2" && $DH_CURVE_CHOICE != "3" ] ] ; do
read -rp"Curve [1-3]: " -e -i 1 DH_CURVE_CHOICE
done
case $DH_CURVE_CHOICE in
2018-09-21 17:17:41 +02:00
1)
2020-04-27 14:59:19 +02:00
DH_CURVE = "prime256v1"
; ;
2)
DH_CURVE = "secp384r1"
; ;
3)
DH_CURVE = "secp521r1"
; ;
esac
2018-09-21 17:17:41 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
echo ""
echo "Choose what size of Diffie-Hellman key you want to use:"
echo " 1) 2048 bits (recommended)"
echo " 2) 3072 bits"
echo " 3) 4096 bits"
until [ [ $DH_KEY_SIZE_CHOICE = ~ ^[ 1-3] $ ] ] ; do
read -rp "DH key size [1-3]: " -e -i 1 DH_KEY_SIZE_CHOICE
done
case $DH_KEY_SIZE_CHOICE in
1)
DH_KEY_SIZE = "2048"
; ;
2018-09-21 17:17:41 +02:00
2)
2020-04-27 14:59:19 +02:00
DH_KEY_SIZE = "3072"
; ;
3)
DH_KEY_SIZE = "4096"
; ;
esac
2018-09-21 17:17:41 +02:00
; ;
esac
2018-09-22 17:51:38 +02:00
echo ""
# The "auth" options behaves differently with AEAD ciphers
2020-04-27 14:59:19 +02:00
if [ [ $CIPHER = ~ CBC$ ] ] ; then
2018-09-22 17:51:38 +02:00
echo "The digest algorithm authenticates data channel packets and tls-auth packets from the control channel."
2020-04-27 14:59:19 +02:00
elif [ [ $CIPHER = ~ GCM$ ] ] ; then
2018-09-22 17:51:38 +02:00
echo "The digest algorithm authenticates tls-auth packets from the control channel."
fi
echo "Which digest algorithm do you want to use for HMAC?"
echo " 1) SHA-256 (recommended)"
echo " 2) SHA-384"
echo " 3) SHA-512"
until [ [ $HMAC_ALG_CHOICE = ~ ^[ 1-3] $ ] ] ; do
read -rp "Digest algorithm [1-3]: " -e -i 1 HMAC_ALG_CHOICE
done
case $HMAC_ALG_CHOICE in
2020-04-27 14:59:19 +02:00
1)
HMAC_ALG = "SHA256"
2018-09-22 17:51:38 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
HMAC_ALG = "SHA384"
2018-09-22 17:51:38 +02:00
; ;
2020-04-27 14:59:19 +02:00
3)
HMAC_ALG = "SHA512"
2018-09-22 17:51:38 +02:00
; ;
esac
2018-09-22 22:34:10 +02:00
echo ""
echo "You can add an additional layer of security to the control channel with tls-auth and tls-crypt"
echo "tls-auth authenticates the packets, while tls-crypt authenticate and encrypt them."
echo " 1) tls-crypt (recommended)"
echo " 2) tls-auth"
until [ [ $TLS_SIG = ~ [ 1-2] ] ] ; do
2020-04-27 14:59:19 +02:00
read -rp "Control channel additional security mechanism [1-2]: " -e -i 1 TLS_SIG
2018-09-22 22:34:10 +02:00
done
2018-09-21 17:17:41 +02:00
fi
2017-11-12 22:51:54 +01:00
echo ""
2018-09-21 17:17:41 +02:00
echo "Okay, that was all I needed. We are ready to setup your OpenVPN server now."
2018-09-28 16:36:00 +02:00
echo "You will be able to generate a client at the end of the installation."
2019-02-25 20:02:50 +01:00
APPROVE_INSTALL = ${ APPROVE_INSTALL :- n }
if [ [ $APPROVE_INSTALL = ~ n ] ] ; then
read -n1 -r -p "Press any key to continue..."
fi
2018-09-22 17:59:21 +02:00
}
2020-04-27 14:59:19 +02:00
function installOpenVPN( ) {
2019-02-25 21:30:46 +01:00
if [ [ $AUTO_INSTALL = = "y" ] ] ; then
# Set default choices so that no questions will be asked.
APPROVE_INSTALL = ${ APPROVE_INSTALL :- y }
APPROVE_IP = ${ APPROVE_IP :- y }
IPV6_SUPPORT = ${ IPV6_SUPPORT :- n }
PORT_CHOICE = ${ PORT_CHOICE :- 1 }
PROTOCOL_CHOICE = ${ PROTOCOL_CHOICE :- 1 }
DNS = ${ DNS :- 1 }
COMPRESSION_ENABLED = ${ COMPRESSION_ENABLED :- n }
CUSTOMIZE_ENC = ${ CUSTOMIZE_ENC :- n }
CLIENT = ${ CLIENT :- client }
PASS = ${ PASS :- 1 }
2019-02-25 23:31:18 +01:00
CONTINUE = ${ CONTINUE :- y }
2019-02-25 21:30:46 +01:00
2020-04-27 13:56:34 +02:00
# Behind NAT, we'll default to the publicly reachable IPv4/IPv6.
if [ [ $IPV6_SUPPORT = = "y" ] ] ; then
2021-12-13 22:48:27 +01:00
PUBLIC_IP = $( curl --retry 5 --retry-connrefused https://ifconfig.co)
2020-04-27 13:56:34 +02:00
else
2021-12-13 22:48:27 +01:00
PUBLIC_IP = $( curl --retry 5 --retry-connrefused -4 https://ifconfig.co)
2020-04-27 13:56:34 +02:00
fi
ENDPOINT = ${ ENDPOINT :- $PUBLIC_IP }
2019-02-25 21:30:46 +01:00
fi
2017-11-12 22:51:54 +01:00
2022-01-07 15:54:46 +01:00
# Run setup questions first, and set other variables if auto-install
2019-02-25 21:54:36 +01:00
installQuestions
2018-09-20 00:05:02 +02:00
# Get the "public" interface from the default route
NIC = $( ip -4 route ls | grep default | grep -Po '(?<=dev )(\S+)' | head -1)
2020-04-27 14:59:19 +02:00
if [ [ -z $NIC ] ] && [ [ $IPV6_SUPPORT = = 'y' ] ] ; then
2022-09-16 16:00:44 +02:00
NIC = $( ip -6 route show default | sed -ne 's/^default .* dev \([^ ]*\) .*$/\2/p' )
2020-03-26 21:22:22 +01:00
fi
2018-09-20 00:05:02 +02:00
2020-03-26 21:27:16 +01:00
# $NIC can not be empty for script rm-openvpn-rules.sh
2020-04-27 14:59:19 +02:00
if [ [ -z $NIC ] ] ; then
echo
echo "Can not detect public interface."
echo "This needs for setup MASQUERADE."
until [ [ $CONTINUE = ~ ( y| n) ] ] ; do
read -rp "Continue? [y/n]: " -e CONTINUE
done
if [ [ $CONTINUE = = "n" ] ] ; then
exit 1
fi
fi
2020-03-26 21:27:16 +01:00
2020-04-27 13:56:34 +02:00
# If OpenVPN isn't installed yet, install it. This script is more-or-less
# idempotent on multiple runs, but will only install OpenVPN from upstream
# the first time.
2022-09-16 16:00:44 +02:00
if [ [ ! -e /etc/openvpn/$SERVER_ID .conf ] ] ; then
2020-04-27 14:59:19 +02:00
if [ [ $OS = ~ ( debian| ubuntu) ] ] ; then
2018-09-16 17:55:50 +02:00
apt-get update
2020-04-27 13:56:34 +02:00
apt-get -y install ca-certificates gnupg
# We add the OpenVPN repo to get the latest version.
2020-04-27 14:59:19 +02:00
if [ [ $VERSION_ID = = "16.04" ] ] ; then
echo "deb http://build.openvpn.net/debian/openvpn/stable xenial main" >/etc/apt/sources.list.d/openvpn.list
2020-04-27 13:56:34 +02:00
wget -O - https://swupdate.openvpn.net/repos/repo-public.gpg | apt-key add -
apt-get update
fi
# Ubuntu > 16.04 and Debian > 8 have OpenVPN >= 2.4 without the need of a third party repository.
apt-get install -y openvpn iptables openssl wget ca-certificates curl
2020-04-27 14:59:19 +02:00
elif [ [ $OS = = 'centos' ] ] ; then
2020-04-27 13:56:34 +02:00
yum install -y epel-release
2020-04-28 11:51:23 +02:00
yum install -y openvpn iptables openssl wget ca-certificates curl tar 'policycoreutils-python*'
2021-03-22 10:48:15 +01:00
elif [ [ $OS = = 'oracle' ] ] ; then
2021-10-18 10:41:06 +02:00
yum install -y oracle-epel-release-el8
yum-config-manager --enable ol8_developer_EPEL
yum install -y openvpn iptables openssl wget ca-certificates curl tar policycoreutils-python-utils
2020-04-27 14:59:19 +02:00
elif [ [ $OS = = 'amzn' ] ] ; then
2020-04-27 13:56:34 +02:00
amazon-linux-extras install -y epel
yum install -y openvpn iptables openssl wget ca-certificates curl
2020-04-27 14:59:19 +02:00
elif [ [ $OS = = 'fedora' ] ] ; then
2020-04-27 16:19:09 +02:00
dnf install -y openvpn iptables openssl wget ca-certificates curl policycoreutils-python-utils
2020-04-27 14:59:19 +02:00
elif [ [ $OS = = 'arch' ] ] ; then
2020-04-27 13:56:34 +02:00
# Install required dependencies and upgrade the system
pacman --needed --noconfirm -Syu openvpn iptables openssl wget ca-certificates curl
2017-11-12 22:51:54 +01:00
fi
2020-04-27 13:56:34 +02:00
# An old version of easy-rsa was available by default in some openvpn packages
if [ [ -d /etc/openvpn/easy-rsa/ ] ] ; then
rm -rf /etc/openvpn/easy-rsa/
2018-09-23 12:47:52 +02:00
fi
2018-09-17 01:11:30 +02:00
fi
2017-11-12 22:51:54 +01:00
# Find out if the machine uses nogroup or nobody for the permissionless group
if grep -qs "^nogroup:" /etc/group; then
2017-11-12 22:56:02 +01:00
NOGROUP = nogroup
2017-11-12 22:51:54 +01:00
else
2017-11-12 22:56:02 +01:00
NOGROUP = nobody
2017-11-12 22:51:54 +01:00
fi
2022-09-16 16:00:44 +02:00
# Create the specific openvpn server directory
mkdir /etc/openvpn/$SERVER_ID
2020-04-27 19:20:40 +02:00
# Install the latest version of easy-rsa from source, if not already installed.
2020-04-27 13:56:34 +02:00
if [ [ ! -d /etc/openvpn/easy-rsa/ ] ] ; then
2020-04-27 19:10:49 +02:00
local version = "3.0.7"
2020-04-27 19:20:40 +02:00
wget -O ~/easy-rsa.tgz https://github.com/OpenVPN/easy-rsa/releases/download/v${ version } /EasyRSA-${ version } .tgz
2020-06-30 09:14:19 +02:00
mkdir -p /etc/openvpn/easy-rsa
2020-04-27 19:20:40 +02:00
tar xzf ~/easy-rsa.tgz --strip-components= 1 --directory /etc/openvpn/easy-rsa
rm -f ~/easy-rsa.tgz
2020-04-27 13:56:34 +02:00
cd /etc/openvpn/easy-rsa/ || return
case $CERT_TYPE in
2020-04-27 14:59:19 +02:00
1)
echo "set_var EASYRSA_ALGO ec" >vars
echo " set_var EASYRSA_CURVE $CERT_CURVE " >>vars
2020-04-27 13:56:34 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
echo " set_var EASYRSA_KEY_SIZE $RSA_KEY_SIZE " >vars
2020-04-27 13:56:34 +02:00
; ;
esac
2018-09-20 00:05:02 +02:00
2020-04-27 13:56:34 +02:00
# Generate a random, alphanumeric identifier of 16 characters for CN and one for server name
2022-09-16 16:00:44 +02:00
SERVER_CN = " cn_ ${ SERVER_ID } _ $( head /dev/urandom | tr -dc 'a-zA-Z0-9' | fold -w 16 | head -n 1) "
2020-04-27 14:59:19 +02:00
echo " $SERVER_CN " >SERVER_CN_GENERATED
2022-09-16 16:00:44 +02:00
SERVER_NAME = " server_ ${ SERVER_ID } _ $( head /dev/urandom | tr -dc 'a-zA-Z0-9' | fold -w 16 | head -n 1) "
2020-04-27 14:59:19 +02:00
echo " $SERVER_NAME " >SERVER_NAME_GENERATED
2018-09-23 16:27:36 +02:00
2020-04-27 14:59:19 +02:00
echo " set_var EASYRSA_REQ_CN $SERVER_CN " >>vars
2019-08-20 21:02:05 +02:00
2020-04-27 13:56:34 +02:00
# Create the PKI, set up the CA, the DH params and the server certificate
./easyrsa init-pki
./easyrsa --batch build-ca nopass
2018-09-23 16:27:36 +02:00
2020-04-27 13:56:34 +02:00
if [ [ $DH_TYPE = = "2" ] ] ; then
# ECDH keys are generated on-the-fly so we don't need to generate them beforehand
openssl dhparam -out dh.pem $DH_KEY_SIZE
fi
2019-06-30 23:06:33 +02:00
2020-04-27 13:56:34 +02:00
./easyrsa build-server-full " $SERVER_NAME " nopass
EASYRSA_CRL_DAYS = 3650 ./easyrsa gen-crl
2019-06-30 23:06:33 +02:00
2020-04-27 13:56:34 +02:00
case $TLS_SIG in
2020-04-27 14:59:19 +02:00
1)
# Generate tls-crypt key
2022-09-16 16:00:44 +02:00
openvpn --genkey --secret /etc/openvpn/$SERVER_ID /tls-crypt.key
2020-04-27 13:56:34 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
# Generate tls-auth key
2022-09-16 16:00:44 +02:00
openvpn --genkey --secret /etc/openvpn/$SERVER_ID /tls-auth.key
2020-04-27 13:56:34 +02:00
; ;
esac
else
# If easy-rsa is already installed, grab the generated SERVER_NAME
# for client configs
cd /etc/openvpn/easy-rsa/ || return
SERVER_NAME = $( cat SERVER_NAME_GENERATED)
fi
2019-06-30 23:06:33 +02:00
2017-11-12 22:51:54 +01:00
# Move all the generated files
2022-09-16 16:00:44 +02:00
cp pki/ca.crt pki/private/ca.key " pki/issued/ $SERVER_NAME .crt " " pki/private/ $SERVER_NAME .key " /etc/openvpn/easy-rsa/pki/crl.pem /etc/openvpn/$SERVER_ID /
2018-09-22 16:41:28 +02:00
if [ [ $DH_TYPE = = "2" ] ] ; then
2022-09-16 16:00:44 +02:00
cp dh.pem /etc/openvpn/$SERVER_ID /
2018-09-22 16:41:28 +02:00
fi
2019-06-30 23:06:33 +02:00
2017-11-12 22:51:54 +01:00
# Make cert revocation list readable for non-root
2022-09-16 16:00:44 +02:00
chmod 644 /etc/openvpn/$SERVER_ID /crl.pem
2017-11-12 22:51:54 +01:00
# Generate server.conf
2022-09-16 16:00:44 +02:00
echo " port $PORT " >/etc/openvpn/$SERVER_ID .conf
2020-04-27 14:59:19 +02:00
if [ [ $IPV6_SUPPORT = = 'n' ] ] ; then
2022-09-16 16:00:44 +02:00
echo " proto $PROTOCOL " >>/etc/openvpn/$SERVER_ID .conf
2020-04-27 14:59:19 +02:00
elif [ [ $IPV6_SUPPORT = = 'y' ] ] ; then
2022-09-16 16:00:44 +02:00
echo " proto ${ PROTOCOL } 6 " >>/etc/openvpn/$SERVER_ID .conf
2018-09-16 17:55:50 +02:00
fi
2018-09-20 00:05:02 +02:00
2017-11-12 22:51:54 +01:00
echo " dev tun
2016-04-10 18:36:15 +02:00
user nobody
2016-05-07 22:58:18 +02:00
group $NOGROUP
2016-11-28 22:13:32 +01:00
persist-key
persist-tun
keepalive 10 120
2015-09-12 21:48:08 +02:00
topology subnet
2022-09-16 16:00:44 +02:00
server 10.${ SERVER_SUBNET } .0.0 255.255.255.0
ifconfig-pool-persist $SERVER_ID /ipp.txt" >>/etc/openvpn/ $SERVER_ID .conf
2018-09-22 14:21:20 +02:00
2017-11-12 22:51:54 +01:00
# DNS resolvers
case $DNS in
2020-04-27 14:59:19 +02:00
1) # Current system resolvers
# Locate the proper resolv.conf
# Needed for systems running systemd-resolved
if grep -q "127.0.0.53" "/etc/resolv.conf" ; then
RESOLVCONF = '/run/systemd/resolve/resolv.conf'
else
RESOLVCONF = '/etc/resolv.conf'
fi
# Obtain the resolvers from resolv.conf and use them for OpenVPN
2020-04-27 18:04:18 +02:00
sed -ne 's/^nameserver[[:space:]]\+\([^[:space:]]\+\).*$/\1/p' $RESOLVCONF | while read -r line; do
# Copy, if it's a IPv4 |or| if IPv6 is enabled, IPv4/IPv6 does not matter
if [ [ $line = ~ ^[ 0-9.] *$ ] ] || [ [ $IPV6_SUPPORT = = 'y' ] ] ; then
2022-09-16 16:00:44 +02:00
echo " push \"dhcp-option DNS $line \" " >>/etc/openvpn/$SERVER_ID .conf
2020-04-27 18:04:18 +02:00
fi
2020-04-27 14:59:19 +02:00
done
2017-11-12 22:51:54 +01:00
; ;
2020-05-01 00:10:11 +02:00
2) # Self-hosted DNS resolver (Unbound)
2022-09-16 16:00:44 +02:00
echo " push \"dhcp-option DNS 10. ${ SERVER_SUBNET } .0.1\" " >>/etc/openvpn/$SERVER_ID .conf
2020-05-01 00:10:11 +02:00
if [ [ $IPV6_SUPPORT = = 'y' ] ] ; then
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS fd42:42:42:42::1"' >>/etc/openvpn/$SERVER_ID .conf
2020-05-01 00:10:11 +02:00
fi
2018-09-16 00:53:33 +02:00
; ;
2020-04-27 14:59:19 +02:00
3) # Cloudflare
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS 1.0.0.1"' >>/etc/openvpn/$SERVER_ID .conf
echo 'push "dhcp-option DNS 1.1.1.1"' >>/etc/openvpn/$SERVER_ID .conf
2018-04-01 23:12:05 +02:00
; ;
2020-04-27 14:59:19 +02:00
4) # Quad9
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS 9.9.9.9"' >>/etc/openvpn/$SERVER_ID .conf
echo 'push "dhcp-option DNS 149.112.112.112"' >>/etc/openvpn/$SERVER_ID .conf
2017-11-29 11:21:33 +01:00
; ;
2020-04-27 14:59:19 +02:00
5) # Quad9 uncensored
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS 9.9.9.10"' >>/etc/openvpn/$SERVER_ID .conf
echo 'push "dhcp-option DNS 149.112.112.10"' >>/etc/openvpn/$SERVER_ID .conf
2018-09-24 11:42:29 +02:00
; ;
2020-04-27 14:59:19 +02:00
6) # FDN
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS 80.67.169.40"' >>/etc/openvpn/$SERVER_ID .conf
echo 'push "dhcp-option DNS 80.67.169.12"' >>/etc/openvpn/$SERVER_ID .conf
2017-11-12 22:51:54 +01:00
; ;
2020-04-27 14:59:19 +02:00
7) # DNS.WATCH
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS 84.200.69.80"' >>/etc/openvpn/$SERVER_ID .conf
echo 'push "dhcp-option DNS 84.200.70.40"' >>/etc/openvpn/$SERVER_ID .conf
2017-11-12 22:51:54 +01:00
; ;
2020-04-27 14:59:19 +02:00
8) # OpenDNS
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS 208.67.222.222"' >>/etc/openvpn/$SERVER_ID .conf
echo 'push "dhcp-option DNS 208.67.220.220"' >>/etc/openvpn/$SERVER_ID .conf
2017-11-12 22:51:54 +01:00
; ;
2020-04-27 14:59:19 +02:00
9) # Google
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS 8.8.8.8"' >>/etc/openvpn/$SERVER_ID .conf
echo 'push "dhcp-option DNS 8.8.4.4"' >>/etc/openvpn/$SERVER_ID .conf
2017-11-12 22:51:54 +01:00
; ;
2020-04-27 14:59:19 +02:00
10) # Yandex Basic
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS 77.88.8.8"' >>/etc/openvpn/$SERVER_ID .conf
echo 'push "dhcp-option DNS 77.88.8.1"' >>/etc/openvpn/$SERVER_ID .conf
2017-11-12 22:51:54 +01:00
; ;
2020-04-27 14:59:19 +02:00
11) # AdGuard DNS
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS 94.140.14.14"' >>/etc/openvpn/$SERVER_ID .conf
echo 'push "dhcp-option DNS 94.140.15.15"' >>/etc/openvpn/$SERVER_ID .conf
2017-11-12 22:51:54 +01:00
; ;
2020-04-27 14:59:19 +02:00
12) # NextDNS
2022-09-16 16:00:44 +02:00
echo 'push "dhcp-option DNS 45.90.28.167"' >>/etc/openvpn/$SERVER_ID .conf
echo 'push "dhcp-option DNS 45.90.30.167"' >>/etc/openvpn/$SERVER_ID .conf
2020-03-03 23:04:18 +01:00
; ;
2020-04-27 14:59:19 +02:00
13) # Custom DNS
2022-09-16 16:00:44 +02:00
echo " push \"dhcp-option DNS $DNS1 \" " >>/etc/openvpn/$SERVER_ID .conf
2020-04-27 14:59:19 +02:00
if [ [ $DNS2 != "" ] ] ; then
2022-09-16 16:00:44 +02:00
echo " push \"dhcp-option DNS $DNS2 \" " >>/etc/openvpn/$SERVER_ID .conf
2019-08-20 21:02:47 +02:00
fi
; ;
2017-11-12 22:51:54 +01:00
esac
2022-09-16 16:00:44 +02:00
echo 'push "redirect-gateway def1 bypass-dhcp"' >>/etc/openvpn/$SERVER_ID .conf
2018-09-16 17:55:50 +02:00
2018-09-20 00:05:02 +02:00
# IPv6 network settings if needed
2020-04-27 14:59:19 +02:00
if [ [ $IPV6_SUPPORT = = 'y' ] ] ; then
2018-09-16 17:55:50 +02:00
echo ' server-ipv6 fd42:42:42:42::/112
tun-ipv6
push tun-ipv6
push "route-ipv6 2000::/3"
2022-09-16 16:00:44 +02:00
push "redirect-gateway ipv6" ' >>/etc/openvpn/$SERVER_ID .conf
2018-09-16 17:55:50 +02:00
fi
2020-04-27 14:59:19 +02:00
if [ [ $COMPRESSION_ENABLED = = "y" ] ] ; then
2022-09-16 16:00:44 +02:00
echo " compress $COMPRESSION_ALG " >>/etc/openvpn/$SERVER_ID .conf
2018-09-22 16:41:28 +02:00
fi
if [ [ $DH_TYPE = = "1" ] ] ; then
2022-09-16 16:00:44 +02:00
echo "dh none" >>/etc/openvpn/$SERVER_ID .conf
echo " ecdh-curve $DH_CURVE " >>/etc/openvpn/$SERVER_ID .conf
2018-09-22 16:41:28 +02:00
elif [ [ $DH_TYPE = = "2" ] ] ; then
2022-09-16 16:00:44 +02:00
echo " dh $SERVER_ID /dh.pem " >>/etc/openvpn/$SERVER_ID .conf
2018-09-22 16:41:28 +02:00
fi
2018-09-22 14:07:51 +02:00
2018-09-22 22:34:10 +02:00
case $TLS_SIG in
2020-04-27 14:59:19 +02:00
1)
2022-09-16 16:00:44 +02:00
echo " tls-crypt $SERVER_ID /tls-crypt.key " >>/etc/openvpn/$SERVER_ID .conf
2018-09-22 22:34:10 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
2022-09-16 16:00:44 +02:00
echo " tls-auth $SERVER_ID /tls-auth.key 0 " >>/etc/openvpn/$SERVER_ID .conf
2018-09-22 22:34:10 +02:00
; ;
esac
2022-09-16 16:00:44 +02:00
echo " crl-verify $SERVER_ID /crl.pem
ca $SERVER_ID /ca.crt
cert $SERVER_ID /$SERVER_NAME .crt
key $SERVER_ID /$SERVER_NAME .key
2018-09-22 17:51:38 +02:00
auth $HMAC_ALG
2018-09-22 18:18:36 +02:00
cipher $CIPHER
ncp-ciphers $CIPHER
2016-11-28 22:13:32 +01:00
tls-server
tls-version-min 1.2
2018-09-22 15:11:15 +02:00
tls-cipher $CC_CIPHER
2020-04-10 17:49:07 +02:00
client-config-dir /etc/openvpn/ccd
2022-09-16 16:00:44 +02:00
status /var/log/openvpn/$SERVER_ID .status.log
verb 3" >>/etc/openvpn/ $SERVER_ID .conf
2016-11-24 20:28:49 +01:00
2020-04-10 17:49:07 +02:00
# Create client-config-dir dir
mkdir -p /etc/openvpn/ccd
2018-09-16 22:45:04 +02:00
# Create log dir
mkdir -p /var/log/openvpn
2017-11-12 22:51:54 +01:00
2018-09-16 17:55:50 +02:00
# Enable routing
2020-10-20 23:44:52 +02:00
echo 'net.ipv4.ip_forward=1' >/etc/sysctl.d/99-openvpn.conf
2020-04-27 14:59:19 +02:00
if [ [ $IPV6_SUPPORT = = 'y' ] ] ; then
2020-10-20 23:44:52 +02:00
echo 'net.ipv6.conf.all.forwarding=1' >>/etc/sysctl.d/99-openvpn.conf
2017-11-12 22:51:54 +01:00
fi
2019-08-20 17:58:51 +02:00
# Apply sysctl rules
2018-09-16 17:55:50 +02:00
sysctl --system
2018-07-15 11:25:59 +02:00
2017-11-12 22:51:54 +01:00
# If SELinux is enabled and a custom port was selected, we need this
if hash sestatus 2>/dev/null; then
if sestatus | grep "Current mode" | grep -qs "enforcing" ; then
2020-04-27 14:59:19 +02:00
if [ [ $PORT != '1194' ] ] ; then
2018-09-21 23:48:11 +02:00
semanage port -a -t openvpn_port_t -p " $PROTOCOL " " $PORT "
2017-11-12 22:51:54 +01:00
fi
fi
fi
2018-07-15 11:25:59 +02:00
2018-09-18 14:55:00 +02:00
# Finally, restart and enable OpenVPN
2021-03-22 10:48:15 +01:00
if [ [ $OS = = 'arch' || $OS = = 'fedora' || $OS = = 'centos' || $OS = = 'oracle' ] ] ; then
2018-09-24 14:26:41 +02:00
# Don't modify package-provided service
cp /usr/lib/systemd/system/openvpn-server@.service /etc/systemd/system/openvpn-server@.service
2019-06-30 23:06:33 +02:00
2018-09-18 14:55:00 +02:00
# Workaround to fix OpenVPN service on OpenVZ
2018-09-24 14:26:41 +02:00
sed -i 's|LimitNPROC|#LimitNPROC|' /etc/systemd/system/openvpn-server@.service
2018-09-18 14:55:00 +02:00
# Another workaround to keep using /etc/openvpn/
2018-09-24 14:26:41 +02:00
sed -i 's|/etc/openvpn/server|/etc/openvpn|' /etc/systemd/system/openvpn-server@.service
2018-09-24 14:33:08 +02:00
2018-09-18 14:55:00 +02:00
systemctl daemon-reload
2022-09-16 16:00:44 +02:00
systemctl enable openvpn-server@$SERVER_ID
systemctl restart openvpn-server@$SERVER_ID
2020-04-27 14:59:19 +02:00
elif [ [ $OS = = "ubuntu" ] ] && [ [ $VERSION_ID = = "16.04" ] ] ; then
2018-09-23 14:25:18 +02:00
# On Ubuntu 16.04, we use the package from the OpenVPN repo
# This package uses a sysvinit service
systemctl enable openvpn
systemctl start openvpn
2017-11-12 22:51:54 +01:00
else
2018-09-24 14:26:41 +02:00
# Don't modify package-provided service
cp /lib/systemd/system/openvpn\@ .service /etc/systemd/system/openvpn\@ .service
2019-06-30 23:06:33 +02:00
2018-09-18 14:55:00 +02:00
# Workaround to fix OpenVPN service on OpenVZ
2018-09-24 14:26:41 +02:00
sed -i 's|LimitNPROC|#LimitNPROC|' /etc/systemd/system/openvpn\@ .service
2018-09-18 14:55:00 +02:00
# Another workaround to keep using /etc/openvpn/
2018-09-24 14:26:41 +02:00
sed -i 's|/etc/openvpn/server|/etc/openvpn|' /etc/systemd/system/openvpn\@ .service
2019-06-30 23:06:33 +02:00
2018-09-18 14:55:00 +02:00
systemctl daemon-reload
2022-09-16 16:00:44 +02:00
systemctl enable openvpn@$SERVER_ID
systemctl restart openvpn@$SERVER_ID
2017-11-12 22:51:54 +01:00
fi
2018-07-15 11:25:59 +02:00
2020-04-27 14:59:19 +02:00
if [ [ $DNS = = 2 ] ] ; then
2018-09-20 00:05:02 +02:00
installUnbound
fi
# Add iptables rules in two scripts
2020-03-26 21:24:50 +01:00
mkdir -p /etc/iptables
2018-09-20 00:05:02 +02:00
# Script to add rules
echo " #!/bin/sh
2022-09-16 16:00:44 +02:00
iptables -t nat -I POSTROUTING 1 -s 10.${ SERVER_SUBNET } .0.0/24 -o $NIC -j MASQUERADE
2019-08-20 11:55:43 +02:00
iptables -I INPUT 1 -i tun0 -j ACCEPT
iptables -I FORWARD 1 -i $NIC -o tun0 -j ACCEPT
iptables -I FORWARD 1 -i tun0 -o $NIC -j ACCEPT
2022-09-16 16:00:44 +02:00
iptables -I INPUT 1 -i $NIC -p $PROTOCOL --dport $PORT -j ACCEPT" >/etc/iptables/add-openvpn-rules- $SERVER_ID .sh
2018-09-20 00:05:02 +02:00
2020-04-27 14:59:19 +02:00
if [ [ $IPV6_SUPPORT = = 'y' ] ] ; then
2019-08-20 11:55:43 +02:00
echo " ip6tables -t nat -I POSTROUTING 1 -s fd42:42:42:42::/112 -o $NIC -j MASQUERADE
ip6tables -I INPUT 1 -i tun0 -j ACCEPT
ip6tables -I FORWARD 1 -i $NIC -o tun0 -j ACCEPT
2020-04-30 23:42:09 +02:00
ip6tables -I FORWARD 1 -i tun0 -o $NIC -j ACCEPT
2022-09-16 16:00:44 +02:00
ip6tables -I INPUT 1 -i $NIC -p $PROTOCOL --dport $PORT -j ACCEPT" >>/etc/iptables/add-openvpn-rules- $SERVER_ID .sh
2018-09-20 00:05:02 +02:00
fi
# Script to remove rules
echo " #!/bin/sh
2022-09-16 16:00:44 +02:00
iptables -t nat -D POSTROUTING -s 10.${ SERVER_SUBNET } .0.0/24 -o $NIC -j MASQUERADE
2018-09-20 00:05:02 +02:00
iptables -D INPUT -i tun0 -j ACCEPT
2019-08-20 11:20:24 +02:00
iptables -D FORWARD -i $NIC -o tun0 -j ACCEPT
iptables -D FORWARD -i tun0 -o $NIC -j ACCEPT
2022-09-16 16:00:44 +02:00
iptables -D INPUT -i $NIC -p $PROTOCOL --dport $PORT -j ACCEPT" >/etc/iptables/rm-openvpn-rules- $SERVER_ID .sh
2018-09-20 00:05:02 +02:00
2020-04-27 14:59:19 +02:00
if [ [ $IPV6_SUPPORT = = 'y' ] ] ; then
2018-09-20 00:05:02 +02:00
echo " ip6tables -t nat -D POSTROUTING -s fd42:42:42:42::/112 -o $NIC -j MASQUERADE
ip6tables -D INPUT -i tun0 -j ACCEPT
2019-08-20 11:20:24 +02:00
ip6tables -D FORWARD -i $NIC -o tun0 -j ACCEPT
2020-04-30 23:42:09 +02:00
ip6tables -D FORWARD -i tun0 -o $NIC -j ACCEPT
2022-09-16 16:00:44 +02:00
ip6tables -D INPUT -i $NIC -p $PROTOCOL --dport $PORT -j ACCEPT" >>/etc/iptables/rm-openvpn-rules- $SERVER_ID .sh
2018-09-20 00:05:02 +02:00
fi
2022-09-16 16:00:44 +02:00
chmod +x /etc/iptables/add-openvpn-rules-$SERVER_ID .sh
chmod +x /etc/iptables/rm-openvpn-rules-$SERVER_ID .sh
2018-09-20 00:05:02 +02:00
# Handle the rules via a systemd script
echo " [Unit]
2022-09-16 16:00:44 +02:00
Description = iptables rules for $SERVER_ID OpenVPN
2018-10-08 21:11:30 +02:00
Before = network-online.target
Wants = network-online.target
2018-09-20 00:05:02 +02:00
[ Service]
Type = oneshot
2022-09-16 16:00:44 +02:00
ExecStart = /etc/iptables/add-openvpn-rules-$SERVER_ID .sh
ExecStop = /etc/iptables/rm-openvpn-rules-$SERVER_ID .sh
2018-09-20 00:05:02 +02:00
RemainAfterExit = yes
[ Install]
2022-09-16 16:00:44 +02:00
WantedBy = multi-user.target" >/etc/systemd/system/iptables-openvpn- $SERVER_ID .service
2018-09-20 00:05:02 +02:00
# Enable service and apply rules
systemctl daemon-reload
2022-09-16 16:00:44 +02:00
systemctl enable iptables-openvpn-$SERVER_ID
systemctl start iptables-openvpn-$SERVER_ID
2018-09-20 00:05:02 +02:00
# If the server is behind a NAT, use the correct IP address for the clients to connect to
2020-04-27 14:59:19 +02:00
if [ [ $ENDPOINT != "" ] ] ; then
2019-02-25 21:30:46 +01:00
IP = $ENDPOINT
2017-11-12 22:51:54 +01:00
fi
2018-09-22 14:21:20 +02:00
2017-11-12 22:51:54 +01:00
# client-template.txt is created so we have a template to add further users later
2022-09-16 16:00:44 +02:00
echo "client" >/etc/openvpn/$SERVER_ID /client-template.txt
2020-04-27 14:59:19 +02:00
if [ [ $PROTOCOL = = 'udp' ] ] ; then
2022-09-16 16:00:44 +02:00
echo "proto udp" >>/etc/openvpn/$SERVER_ID /client-template.txt
echo "explicit-exit-notify" >>/etc/openvpn/$SERVER_ID /client-template.txt
2020-04-27 14:59:19 +02:00
elif [ [ $PROTOCOL = = 'tcp' ] ] ; then
2022-09-16 16:00:44 +02:00
echo "proto tcp-client" >>/etc/openvpn/$SERVER_ID /client-template.txt
2017-11-12 22:51:54 +01:00
fi
echo " remote $IP $PORT
2015-09-12 21:48:08 +02:00
dev tun
resolv-retry infinite
nobind
persist-key
persist-tun
remote-cert-tls server
2018-01-18 17:36:31 +01:00
verify-x509-name $SERVER_NAME name
2018-09-22 17:51:38 +02:00
auth $HMAC_ALG
2017-08-27 20:59:08 +02:00
auth-nocache
2018-09-22 18:18:36 +02:00
cipher $CIPHER
2016-11-28 22:13:32 +01:00
tls-client
2016-04-10 18:53:29 +02:00
tls-version-min 1.2
2018-09-22 15:11:15 +02:00
tls-cipher $CC_CIPHER
2020-04-27 14:19:25 +02:00
ignore-unknown-option block-outside-dns
2018-09-20 17:16:04 +02:00
setenv opt block-outside-dns # Prevent Windows 10 DNS leak
2022-09-16 16:00:44 +02:00
verb 3" >>/etc/openvpn/ $SERVER_ID /client-template.txt
2016-11-28 22:13:32 +01:00
2020-04-27 14:59:19 +02:00
if [ [ $COMPRESSION_ENABLED = = "y" ] ] ; then
2022-09-16 16:00:44 +02:00
echo " compress $COMPRESSION_ALG " >>/etc/openvpn/$SERVER_ID /client-template.txt
2020-04-27 14:59:19 +02:00
fi
2018-09-22 14:07:51 +02:00
2017-11-12 22:51:54 +01:00
# Generate the custom client.ovpn
2018-09-20 00:05:02 +02:00
newClient
echo "If you want to add more clients, you simply need to run this script another time!"
}
2020-04-27 14:59:19 +02:00
function newClient( ) {
2017-11-12 22:51:54 +01:00
echo ""
2018-09-20 00:05:02 +02:00
echo "Tell me a name for the client."
2020-07-17 21:10:31 +02:00
echo "The name must consist of alphanumeric character. It may also include an underscore or a dash."
2018-09-20 00:05:02 +02:00
2020-07-17 21:10:31 +02:00
until [ [ $CLIENT = ~ ^[ a-zA-Z0-9_-] +$ ] ] ; do
2018-09-20 00:05:02 +02:00
read -rp "Client name: " -e CLIENT
done
2017-11-12 22:51:54 +01:00
echo ""
2018-09-20 00:05:02 +02:00
echo "Do you want to protect the configuration file with a password?"
echo "(e.g. encrypt the private key with a password)"
echo " 1) Add a passwordless client"
echo " 2) Use a password for the client"
2020-04-27 14:59:19 +02:00
until [ [ $PASS = ~ ^[ 1-2] $ ] ] ; do
2018-09-20 00:05:02 +02:00
read -rp "Select an option [1-2]: " -e -i 1 PASS
done
2020-04-27 13:56:34 +02:00
CLIENTEXISTS = $( tail -n +2 /etc/openvpn/easy-rsa/pki/index.txt | grep -c -E " /CN= $CLIENT \$ " )
2020-04-27 14:59:19 +02:00
if [ [ $CLIENTEXISTS = = '1' ] ] ; then
2020-04-27 13:56:34 +02:00
echo ""
2020-04-27 17:45:58 +02:00
echo "The specified client CN was already found in easy-rsa, please choose another name."
exit
2020-04-27 13:56:34 +02:00
else
cd /etc/openvpn/easy-rsa/ || return
case $PASS in
2020-04-27 14:59:19 +02:00
1)
./easyrsa build-client-full " $CLIENT " nopass
2020-04-27 13:56:34 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
2020-04-27 13:56:34 +02:00
echo "⚠️ You will be asked for the client password below ⚠️"
2020-04-27 14:59:19 +02:00
./easyrsa build-client-full " $CLIENT "
2020-04-27 13:56:34 +02:00
; ;
esac
echo " Client $CLIENT added. "
fi
2018-09-20 00:05:02 +02:00
2021-03-10 22:16:16 +01:00
# Home directory of the user, where the client configuration will be written
2021-03-11 18:59:45 +01:00
if [ -e " /home/ ${ CLIENT } " ] ; then
2021-03-10 22:16:16 +01:00
# if $1 is a user name
2021-03-11 18:59:45 +01:00
homeDir = " /home/ ${ CLIENT } "
2021-03-10 22:16:16 +01:00
elif [ " ${ SUDO_USER } " ] ; then
# if not, use SUDO_USER
if [ " ${ SUDO_USER } " = = "root" ] ; then
# If running sudo as root
homeDir = "/root"
else
homeDir = " /home/ ${ SUDO_USER } "
fi
else
# if not SUDO_USER, use /root
2018-09-20 00:05:02 +02:00
homeDir = "/root"
fi
2018-09-22 22:34:10 +02:00
# Determine if we use tls-auth or tls-crypt
2022-09-16 16:00:44 +02:00
if grep -qs "^tls-crypt" /etc/openvpn/$SERVER_ID .conf; then
2018-09-22 22:34:10 +02:00
TLS_SIG = "1"
2022-09-16 16:00:44 +02:00
elif grep -qs "^tls-auth" /etc/openvpn/$SERVER_ID .conf; then
2018-09-22 22:34:10 +02:00
TLS_SIG = "2"
fi
2018-09-20 00:05:02 +02:00
# Generates the custom client.ovpn
2022-09-16 16:00:44 +02:00
cp /etc/openvpn/$SERVER_ID /client-template.txt " $homeDir / $CLIENT .ovpn "
2018-09-20 00:05:02 +02:00
{
echo "<ca>"
cat "/etc/openvpn/easy-rsa/pki/ca.crt"
echo "</ca>"
echo "<cert>"
2018-09-24 11:37:13 +02:00
awk '/BEGIN/,/END/' " /etc/openvpn/easy-rsa/pki/issued/ $CLIENT .crt "
2018-09-20 00:05:02 +02:00
echo "</cert>"
echo "<key>"
cat " /etc/openvpn/easy-rsa/pki/private/ $CLIENT .key "
echo "</key>"
2018-09-22 22:34:10 +02:00
case $TLS_SIG in
2020-04-27 14:59:19 +02:00
1)
echo "<tls-crypt>"
2022-09-16 16:00:44 +02:00
cat /etc/openvpn/$SERVER_ID /tls-crypt.key
2020-04-27 14:59:19 +02:00
echo "</tls-crypt>"
2018-09-22 22:34:10 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
echo "key-direction 1"
echo "<tls-auth>"
2022-09-16 16:00:44 +02:00
cat /etc/openvpn/$SERVER_ID /tls-auth.key
2020-04-27 14:59:19 +02:00
echo "</tls-auth>"
2018-09-22 22:34:10 +02:00
; ;
esac
2020-04-27 14:59:19 +02:00
} >>" $homeDir / $CLIENT .ovpn "
2018-09-20 00:05:02 +02:00
echo ""
2020-04-27 13:56:34 +02:00
echo " The configuration file has been written to $homeDir / $CLIENT .ovpn. "
2018-09-20 00:05:02 +02:00
echo "Download the .ovpn file and import it in your OpenVPN client."
2019-02-25 21:54:36 +01:00
exit 0
2018-09-20 00:05:02 +02:00
}
2020-04-27 14:59:19 +02:00
function revokeClient( ) {
2018-09-20 00:05:02 +02:00
NUMBEROFCLIENTS = $( tail -n +2 /etc/openvpn/easy-rsa/pki/index.txt | grep -c "^V" )
2020-04-27 14:59:19 +02:00
if [ [ $NUMBEROFCLIENTS = = '0' ] ] ; then
2018-09-20 00:05:02 +02:00
echo ""
echo "You have no existing clients!"
exit 1
fi
echo ""
echo "Select the existing client certificate you want to revoke"
tail -n +2 /etc/openvpn/easy-rsa/pki/index.txt | grep "^V" | cut -d '=' -f 2 | nl -s ') '
2020-04-27 17:35:30 +02:00
until [ [ $CLIENTNUMBER -ge 1 && $CLIENTNUMBER -le $NUMBEROFCLIENTS ] ] ; do
if [ [ $CLIENTNUMBER = = '1' ] ] ; then
read -rp "Select one client [1]: " CLIENTNUMBER
else
read -rp " Select one client [1- $NUMBEROFCLIENTS ]: " CLIENTNUMBER
fi
done
2018-09-20 00:05:02 +02:00
CLIENT = $( tail -n +2 /etc/openvpn/easy-rsa/pki/index.txt | grep "^V" | cut -d '=' -f 2 | sed -n " $CLIENTNUMBER " p)
2019-11-11 07:37:09 +01:00
cd /etc/openvpn/easy-rsa/ || return
2018-09-21 23:48:11 +02:00
./easyrsa --batch revoke " $CLIENT "
2018-09-20 00:05:02 +02:00
EASYRSA_CRL_DAYS = 3650 ./easyrsa gen-crl
2022-09-16 16:00:44 +02:00
rm -f /etc/openvpn/$SERVER_ID /crl.pem
cp /etc/openvpn/easy-rsa/pki/crl.pem /etc/openvpn/$SERVER_ID /crl.pem
chmod 644 /etc/openvpn/$SERVER_ID /crl.pem
2018-09-21 23:48:11 +02:00
find /home/ -maxdepth 2 -name " $CLIENT .ovpn " -delete
rm -f " /root/ $CLIENT .ovpn "
2022-09-16 16:00:44 +02:00
sed -i " /^ $CLIENT ,.*/d " /etc/openvpn/$SERVER_ID /ipp.txt
2021-10-18 10:43:36 +02:00
cp /etc/openvpn/easy-rsa/pki/index.txt{ ,.bk}
2018-09-20 00:05:02 +02:00
echo ""
echo " Certificate for client $CLIENT revoked. "
}
2020-04-27 14:59:19 +02:00
function removeUnbound( ) {
2018-09-20 00:05:02 +02:00
# Remove OpenVPN-related config
2020-04-10 11:42:57 +02:00
sed -i '/include: \/etc\/unbound\/openvpn.conf/d' /etc/unbound/unbound.conf
2018-09-20 00:05:02 +02:00
rm /etc/unbound/openvpn.conf
2018-09-22 15:23:01 +02:00
until [ [ $REMOVE_UNBOUND = ~ ( y| n) ] ] ; do
2018-09-20 00:05:02 +02:00
echo ""
echo "If you were already using Unbound before installing OpenVPN, I removed the configuration related to OpenVPN."
read -rp "Do you want to completely remove Unbound? [y/n]: " -e REMOVE_UNBOUND
done
2020-04-27 14:59:19 +02:00
if [ [ $REMOVE_UNBOUND = = 'y' ] ] ; then
2018-09-20 00:05:02 +02:00
# Stop Unbound
systemctl stop unbound
2020-04-27 14:59:19 +02:00
if [ [ $OS = ~ ( debian| ubuntu) ] ] ; then
2021-03-10 21:46:52 +01:00
apt-get remove --purge -y unbound
2020-04-27 14:59:19 +02:00
elif [ [ $OS = = 'arch' ] ] ; then
2018-09-23 16:27:36 +02:00
pacman --noconfirm -R unbound
2021-03-22 10:48:15 +01:00
elif [ [ $OS = ~ ( centos| amzn| oracle) ] ] ; then
2018-09-27 22:23:40 +02:00
yum remove -y unbound
2020-04-27 14:59:19 +02:00
elif [ [ $OS = = 'fedora' ] ] ; then
2018-09-27 22:23:40 +02:00
dnf remove -y unbound
2018-09-20 00:05:02 +02:00
fi
rm -rf /etc/unbound/
echo ""
echo "Unbound removed!"
else
2020-04-06 14:41:10 +02:00
systemctl restart unbound
2018-09-20 00:05:02 +02:00
echo ""
echo "Unbound wasn't removed."
fi
}
2020-04-27 14:59:19 +02:00
function removeOpenVPN( ) {
2018-09-20 00:05:02 +02:00
echo ""
read -rp "Do you really want to remove OpenVPN? [y/n]: " -e -i n REMOVE
2020-04-27 14:59:19 +02:00
if [ [ $REMOVE = = 'y' ] ] ; then
2018-09-20 00:05:02 +02:00
# Get OpenVPN port from the configuration
2022-09-16 16:00:44 +02:00
PORT = $( grep '^port ' /etc/openvpn/${ SERVER_ID } .conf | cut -d " " -f 2)
PROTOCOL = $( grep '^proto ' /etc/openvpn/${ SERVER_ID } .conf | cut -d " " -f 2)
OTHER_SERVER_CONFS = $( ls /etc/openvpn/*.conf | grep -v $SERVER_ID .conf | wc -l)
[ [ $OTHER_SERVER_CONFS -lt 1 ] ] && LAST_SERVER = 1
2018-09-20 00:05:02 +02:00
# Stop OpenVPN
2021-03-22 10:48:15 +01:00
if [ [ $OS = ~ ( fedora| arch| centos| oracle) ] ] ; then
2022-09-16 16:00:44 +02:00
systemctl disable openvpn-server@${ SERVER_ID }
systemctl stop openvpn-server@${ SERVER_ID }
2018-09-24 14:26:41 +02:00
# Remove customised service
2022-09-16 16:00:44 +02:00
test $LAST_SERVER && rm /etc/systemd/system/openvpn-server@.service
2020-04-27 14:59:19 +02:00
elif [ [ $OS = = "ubuntu" ] ] && [ [ $VERSION_ID = = "16.04" ] ] ; then
2022-09-16 16:00:44 +02:00
test $LAST_SERVER && systemctl disable openvpn
test $LAST_SERVER && systemctl stop openvpn
2018-09-20 00:05:02 +02:00
else
2022-09-16 16:00:44 +02:00
systemctl disable openvpn@$SERVER_ID
systemctl stop openvpn@$SERVER_ID
2018-09-24 14:26:41 +02:00
# Remove customised service
2022-09-16 16:00:44 +02:00
test $LAST_SERVER && rm /etc/systemd/system/openvpn\@ .service
2018-09-20 00:05:02 +02:00
fi
# Remove the iptables rules related to the script
2022-09-16 16:00:44 +02:00
systemctl stop iptables-openvpn-$SERVER_ID
2018-09-20 00:05:02 +02:00
# Cleanup
2022-09-16 16:00:44 +02:00
systemctl disable iptables-openvpn-$SERVER_ID
rm /etc/systemd/system/iptables-openvpn-$SERVER_ID .service
2018-09-20 00:05:02 +02:00
systemctl daemon-reload
2022-09-16 16:00:44 +02:00
rm /etc/iptables/add-openvpn-rules-$SERVER_ID .sh
rm /etc/iptables/rm-openvpn-rules-$SERVER_ID .sh
2018-09-20 00:05:02 +02:00
# SELinux
if hash sestatus 2>/dev/null; then
if sestatus | grep "Current mode" | grep -qs "enforcing" ; then
2020-04-27 16:05:51 +02:00
if [ [ $PORT != '1194' ] ] ; then
2020-04-27 16:03:55 +02:00
semanage port -d -t openvpn_port_t -p " $PROTOCOL " " $PORT "
2018-09-20 00:05:02 +02:00
fi
fi
fi
2022-09-16 16:00:44 +02:00
if [ [ $OS = ~ ( debian| ubuntu) && $LAST_SERVER ] ] ; then
2021-03-10 21:46:52 +01:00
apt-get remove --purge -y openvpn
2020-04-27 14:59:19 +02:00
if [ [ -e /etc/apt/sources.list.d/openvpn.list ] ] ; then
2018-09-22 11:41:26 +02:00
rm /etc/apt/sources.list.d/openvpn.list
apt-get update
fi
2022-09-16 16:00:44 +02:00
elif [ [ $OS = = 'arch' && $LAST_SERVER ] ] ; then
2018-09-23 16:27:36 +02:00
pacman --noconfirm -R openvpn
2022-09-16 16:00:44 +02:00
elif [ [ $OS = ~ ( centos| amzn| oracle) && $LAST_SERVER ] ] ; then
2018-09-27 22:23:40 +02:00
yum remove -y openvpn
2022-09-16 16:00:44 +02:00
elif [ [ $OS = = 'fedora' && $LAST_SERVER ] ] ; then
2018-09-27 22:23:40 +02:00
dnf remove -y openvpn
2018-09-20 00:05:02 +02:00
fi
# Cleanup
2018-09-21 23:48:11 +02:00
find /home/ -maxdepth 2 -name "*.ovpn" -delete
find /root/ -maxdepth 1 -name "*.ovpn" -delete
2022-09-16 16:00:44 +02:00
rm /etc/openvpn/$SERVER_ID .conf
rm -rf /etc/openvpn/$SERVER_ID
test $LAST_SERVER && rm -rf /etc/openvpn
test $LAST_SERVER && rm -rf /usr/share/doc/openvpn*
test $LAST_SERVER && rm -f /etc/sysctl.d/99-openvpn.conf
test $LAST_SERVER && rm -rf /var/log/openvpn
2018-09-20 00:05:02 +02:00
# Unbound
if [ [ -e /etc/unbound/openvpn.conf ] ] ; then
2022-09-16 16:00:44 +02:00
test $LAST_SERVER && removeUnbound
2018-09-20 00:05:02 +02:00
fi
echo ""
2022-09-16 16:00:44 +02:00
echo " OpenVPN $SERVER_ID removed! "
test $LAST_SERVER || echo "There are others openvpn servers configured so not cleaning all openvpn yet"
2018-09-20 00:05:02 +02:00
else
echo ""
echo "Removal aborted!"
fi
}
2020-04-27 14:59:19 +02:00
function manageMenu( ) {
2018-09-20 00:05:02 +02:00
echo "Welcome to OpenVPN-install!"
echo "The git repository is available at: https://github.com/angristan/openvpn-install"
echo ""
2022-09-16 16:00:44 +02:00
echo " It looks like OpenVPN $SERVER_ID is already installed. "
echo ""
echo "(if you want to add or administer another server add \$SERVER_ID to your"
echo "environment)"
2018-09-20 00:05:02 +02:00
echo ""
echo "What do you want to do?"
echo " 1) Add a new user"
echo " 2) Revoke existing user"
echo " 3) Remove OpenVPN"
echo " 4) Exit"
2020-04-27 14:59:19 +02:00
until [ [ $MENU_OPTION = ~ ^[ 1-4] $ ] ] ; do
2018-09-20 00:05:02 +02:00
read -rp "Select an option [1-4]: " MENU_OPTION
done
case $MENU_OPTION in
2020-04-27 14:59:19 +02:00
1)
newClient
2018-09-20 00:05:02 +02:00
; ;
2020-04-27 14:59:19 +02:00
2)
revokeClient
2018-09-20 00:05:02 +02:00
; ;
2020-04-27 14:59:19 +02:00
3)
removeOpenVPN
2018-09-20 00:05:02 +02:00
; ;
2020-04-27 14:59:19 +02:00
4)
exit 0
2018-09-20 00:05:02 +02:00
; ;
esac
}
2022-09-16 16:00:44 +02:00
2018-09-20 00:05:02 +02:00
# Check for root, TUN, OS...
initialCheck
# Check if OpenVPN is already installed
2022-09-16 16:00:44 +02:00
if [ [ -e /etc/openvpn/$SERVER_ID .conf && $AUTO_INSTALL != "y" ] ] ; then
2018-09-20 00:05:02 +02:00
manageMenu
else
installOpenVPN
2013-08-05 00:58:43 +02:00
fi