Commit Graph
459 Commits
Author SHA1 Message Date
patlolandGitHub 58a5282e17 Update openvpn-install.sh 2017-07-22 21:08:06 +02:00
patlolandGitHub 3c5c87b031 Update openvpn-install.sh 2017-07-22 20:18:46 +02:00
patlolandGitHub 5787c45a03 Update openvpn-install.sh 2017-07-22 19:40:29 +02:00
patlol 031afd587e fix #8 Client files not beeing created in the right folder when using sudo 2017-07-22 19:30:36 +02:00
DrXala b5c624eb76 Adjust indents + change iptables.service 2017-07-20 17:12:40 +02:00
DrXala 8f28593112 Fix iptables.service 2017-07-16 16:01:05 +02:00
DrXala 23222fd59f Fix syntax error... 2017-07-16 15:39:14 +02:00
DrXala d3d7d18ab1 Removing the use of rc.local file 2017-07-16 14:11:29 +02:00
DrXala 1be7733c0b Install iptables systemd service for Debian, Ubuntu and Centos. Fix iptables install for ArchLinux. 2017-07-16 12:55:09 +02:00
AngristanandGitHub c703d41795 Fix for Debian 9 on OpenVZ 2017-07-14 17:15:07 +02:00
AngristanandGitHub 276284458f Fix DNS choice 2017-07-08 13:30:58 +02:00
jackdwyer d1f665c458 fixes last case statement for SEED-CBC 2017-07-03 14:14:39 -04:00
AngristanandGitHub cd01329585 Add support for Debian 9 Stretch 2017-06-26 02:41:40 +02:00
AngristanandGitHub e185698445 Use current system resolvers as default
That makes more sense that putting French servers.

What is in /etc/resolv.conf is not always good, but most of the time it's the hoster's or something nearby. Thus it makes more sense for the user to use them by default.
2017-06-26 02:37:41 +02:00
AngristanandGitHub 6800ef35f7 Typo
It's late.
2017-06-26 02:20:38 +02:00
AngristanandGitHub 19fe6626f1 Implements OpenVPN 2.4 changes for Arch Linux (kind of)
Since OpenVPN 2.4 is out on Arch, the script wasn't working completely because of this : https://www.archlinux.org/news/openvpn-240-update-requires-administrative-interaction/

There is a new path for OpenVPN server config. This is just needed on Arch for now, and you're probably not going to run an OpenVPN client on an OpenVPN server. 

Thus I modified the systemd script to use `/etc/openvpn/` and `server.conf` instead of the new `/etc/openvpn/server/` and `openvpn.conf`.

By using the same paths as the other distros, I avoid to rewrite the entire script to change the paths...

It's not 100% clean, but it works pretty well. If you have any objection please leave a comment.

Also, I updated the new service name.

As far as I tested, it's working fine on Arch Linux for now.

Fixes #63 and #61
2017-06-26 02:17:14 +02:00
AngristanandGitHub ac203dd5ee Fix iptables rules on reboot for some OS
Thanks a lot to Nyr for the fix : https://github.com/Nyr/openvpn-install/commit/a31aaf82f3664e5854c617752a5493011ede731f

Fixes https://github.com/Angristan/OpenVPN-install/issues/6.

On Ubuntu 17.04, 16.10 and Debian 9, the iptables rules were not applied because of rc.local
2017-06-25 22:01:05 +02:00
AngristanandGitHub 10351305e3 Google Compute Engine support
Merge pull request #57 and close issue #46
2017-06-25 20:21:36 +02:00
AngristanandGitHub 8c66c8e684 Fix client revocation
A client revocation would make crl.pem unreadable and thus blocking any other client to connect.

Fixes https://github.com/Angristan/OpenVPN-install/pull/47, https://github.com/Angristan/OpenVPN-install/issues/25 and https://github.com/Angristan/OpenVPN-install/issues/49.
2017-06-25 19:58:41 +02:00
Kenneth Zhao d74318562d adding support for debian 9 stretch 2017-06-25 09:38:52 -07:00
AngristanandGitHub a2a3bfc605 Added Yandex Basic DNS resolvers
https://dns.yandex.com/

Nice for Russia.
2017-06-23 14:30:57 +02:00
AngristanandGitHub d712e15795 Support OpenSSL 1.1.0 DH generation
Fixes dh.pem gen on Debian 9 and Arch Linux

https://github.com/Angristan/OpenVPN-install/issues/64
https://github.com/Angristan/OpenVPN-install/issues/74

https://www.debian.org/releases/stretch/amd64/release-notes/ch-information.en.html#openssl-issues
2017-06-18 21:12:25 +02:00
AngristanandGitHub 5d40c041dd More proper remove
openvpn-blacklist isn't installed with Debian 9.
2017-06-18 21:07:15 +02:00
AngristanandGitHub 823ff21fcc Add support for Ubuntu 17.04 2017-05-07 23:56:19 +02:00
DrXalaandGitHub fa9e5235f9 Close Angristan/OpenVPN-install#46
This patch is for Angristan/OpenVPN-install#46
2017-04-23 12:43:33 +02:00
Seeder101andGitHub 89925cbbe8 Update openvpn-install.sh
change sould to should and correct adress to address in line 195
2016-12-11 16:03:40 +03:00
Seeder101andGitHub e548a61dcc Update openvpn-install.sh
change sould to should
2016-12-11 15:58:06 +03:00
AngristanandGitHub 316ecfe7f4 Use SHA-256 instead of SHA-384
Following https://github.com/Angristan/OpenVPN-install/commit/693bd13fa723b8d5077539a7208f759c51c04a06
2016-12-11 12:11:11 +01:00
AngristanandGitHub 7a5bb93cbe AES-256 is not necessarily the most secure cipher
Indeed, it it most vulnerable to Timing Attacks : https://en.wikipedia.org/wiki/Length_extension_attack

Also, AES 128 is secure enough for every one, so it's still the recommended cipher.
2016-12-04 17:21:41 +01:00
AngristanandGitHub 56477bba34 The crypto update 🔐
- Removed "fast" and "slow" mode (not a good idea, I prefer to give the choice for the parameters directly)
- Corrected some confusion between the cipher for the data channel and the control channel, my bad.
- using TLS-DHE-RSA-WITH-AES-256-GCM-SHA384 by default for the control channel
- using SHA384 by default for HMAC auth and RSA certificate
- giving the choice for the cipher of the data channel, the size of the DH key and the RSA Key

I will explain all my choices here : https://github.com/Angristan/OpenVPN-install#encryption (likely tomorrow)
2016-11-28 22:13:32 +01:00
AngristanandGitHub c03a55f11f Making sure a correct DNS option is selected 2016-11-27 14:31:25 +01:00
TheKinrar f76db9f589 Merge branch 'master' of https://github.com/TheKinrar/OpenVPN-install into TheKinrar-master 2016-11-26 16:13:02 +01:00
TheKinrarandGitHub f3ff29d6c7 rc.local fix 2016-11-25 18:25:37 +01:00
AngristanandGitHub 17a9d76ae9 Remove ufw and MASQUERADE support
Not useful, badly implemented.
2016-11-25 00:59:03 +01:00
AngristanandGitHub 218e474f85 Add logs
Can be useful.
2016-11-24 23:34:15 +01:00
AngristanandGitHub 98ca79a9de Move rc.local and sysctl installation after the confirmation 2016-11-24 20:28:49 +01:00
TheKinrar 358e80b5a6 sysctl fix, again. 2016-11-24 19:37:45 +01:00
TheKinrar cc657fa459 Fixed rc.local and sysctl.conf files on ArchLinux 2016-11-24 18:07:23 +01:00
TheKinrar 9b261809eb Automatically enable and start iptables on ArchLinux. 2016-11-22 19:55:17 +01:00
TheKinrar 6e2b5cb439 Added ArchLinux support. 2016-11-21 20:59:00 +01:00
AngristanandGitHub 80dbca6e63 Add TCP support
There is now the choice to use TCP or UDP for OpenVPN protocol. You should always use UDP, but TCP can be useful sometimes : on lossy networks or to bypass some blockage
2016-11-21 19:57:52 +01:00
AngristanandGitHub 662fe26f5b I don't know why it wasn't like this from the beginning 2016-11-20 23:09:42 +01:00
AngristanandGitHub 552709059e Fix my previous commit
My bad.
2016-11-20 22:50:51 +01:00
AngristanandGitHub a09ef4868a The user can choose to continue the installer even if its OS is not supported
At its own risk of course. But usefull if using Ubuntu beta or Debian unstable/testing
2016-11-20 22:47:23 +01:00
AngristanandGitHub 903270be4b Remove OpenNIC servers
Not consistant and can't really be trusted
2016-11-20 15:01:42 +01:00
AngristanandGitHub b0f271bc5f Specify the location of the DNS servers 2016-11-20 14:52:47 +01:00
AngristanandGitHub 3f58eb781c Some cleanup 2016-11-20 14:22:08 +01:00
AngristanandGitHub 7295627e67 Removing support for Ubuntu 15.10
Ubuntu 15.10 is not supported anymore since july 2016 : not safe to use it now
2016-10-20 14:33:16 +02:00
AngristanandGitHub fce638b552 Add support for Ubuntu 16.10 Yakketi Yak 2016-10-13 22:55:04 +02:00
AngristanandGitHub 2c9701d477 Better way to enable IP forwarding
https://github.com/Nyr/openvpn-install/commit/791c54786c2cb2f6500e20f931b33fbb234a8ce4?diff=unified
2016-10-04 17:34:11 +02:00