Commit Graph
529 Commits
Author SHA1 Message Date
randomshellandGitHub 62a4ff3b41 fix(client conf): ignore block-outside-dns if not supported (#628) 2020-04-27 14:19:25 +02:00
randomshellandGitHub 159ab9af6e refactor(revoke client): remove uneeded cleanup (#607)
The deletion of issued files is handled by easy-rsa.
See function move_revoked() https://github.com/OpenVPN/easy-rsa/blob/f0129cfe6222820a85db2d394ab73d3c7759c5be/easyrsa3/easyrsa#L1050
2020-04-27 14:12:23 +02:00
John EandGitHub fe0b995bdf feat(headless): make script idempotent
This set of changes adjusts the script so that you can run it multiple times with the same input and not have any unexpected changes. This makes it appropriate for "enforcing state", as required by automated provisioners like Puppet, Salt, Chef, or Ansible.

 - Unbound, OpenVPN, easy-rsa, and other dependencies are only installed from upstream if they are not already present. This prevents multiple runs of the script from causing unexpected version upgrades.
 - The easy-rsa system is put in a folder called "easy-rsa-auto" so it can't conflict with the "easy-rsa" folder from some older OpenVPN packages
 - The easy-rsa CA is only initialized once
 - SERVER_CN and SERVER_NAME are randomly generated once and saved for future reference
 - File append ('>>') is only done strictly after a file is created with '>' (e.g. /etc/sysctl.d/20-openvpn.conf)
 - Clients are only added to easy-rsa once
 - If AUTO_INSTALL == y, then the script operates in install mode and doesn't enter manageMenu
2020-04-27 13:56:34 +02:00
Stanislas Lange 3b0c2ace90 fix(checkOS): update Ubuntu/Debian compatibility check 2020-04-27 13:37:52 +02:00
Stanislas Lange 957712e73d docs(readme): update compatibility matrix 2020-04-27 13:11:11 +02:00
randomshellandGitHub 0481e10bce Add FAQ for client-to-client (#631) 2020-04-27 10:39:33 +02:00
StanislasandGitHub ecd2b45c9f Delete issue template (blank still available) 2020-04-26 15:50:57 +02:00
randomshellandGitHub 72c99f3e8f Add FAQ for router clients (#629) 2020-04-24 18:00:59 +02:00
Stanislas Lange 0188c442a2 FAQ: Remove obsolete entry
Fix #634
2020-04-23 18:49:26 +02:00
randomshellandGitHub fcc4cc4afd Add FAQ entry for sysctl and iptables changes (#626) 2020-04-22 11:39:42 +02:00
randomshellandGitHub 777bedaa38 Add FAQ for DNS Leaks blocking (#627) 2020-04-22 11:38:31 +02:00
Stanislas Lange 2e17007cb3 Update issue templates 2020-04-22 11:35:24 +02:00
Stanislas Lange 124606468d Update issue templates 2020-04-22 11:33:47 +02:00
StanislasandGitHub 2b9c108232 Delete ISSUE_TEMPLATE.md 2020-04-22 11:27:12 +02:00
StanislasandGitHub 8e9ca3ad10 Update issue templates 2020-04-22 11:26:57 +02:00
StanislasandGitHub c2a4edc714 Re-add SayThanks.io 2020-04-18 21:18:54 +02:00
randomshellandGitHub 6989b0d326 Add support for client-configuration-dir (#609) 2020-04-10 17:49:07 +02:00
randomshellandGitHub 2c9c0ed0c3 Improve sed line deletion (#608) 2020-04-10 11:42:57 +02:00
randomshellandGitHub ef5d5faf30 Change = conditional to == (#591) 2020-04-06 14:51:58 +02:00
Henry NandGitHub 6e8aeb3505 Uninstallation: restart unbound only if not removed (#612) 2020-04-06 14:41:10 +02:00
StanislasandGitHub 7e7a494f59 Remove wiki link 2020-04-04 11:55:08 +02:00
StanislasandGitHub d31efe9e7b Move FAQ from wiki to git to allow contributions (#611)
Signed-off-by: Stanislas Lange <angristan@pm.me>
2020-04-04 11:54:17 +02:00
StanislasandGitHub d958c15909 🤦‍♂️ 2020-04-03 11:13:57 +02:00
Henry NandGitHub e123635e7c Add comments to some DNS options in code (#598) 2020-04-02 16:30:50 +02:00
randomshellandGitHub 7ed9cac8d7 Change Adguard DNS to Anycast (#596)
See map at https://adguard.com/en/adguard-dns/overview.html
2020-03-31 23:05:44 +02:00
Henry NandStanislas Lange 44105eb060 Fix systemd unit issue on Debian 9 (#585)
On Debian 9 the copy of unit file `/etc/systemd/system/openvpn@.service` has no effect, see #583.
Same problem as #129 and #378, unit can not start on OpenVZ.

It must execute `systemctl enable` before `systemctl restart`.
So the new link to `/etc/systemd/system/openvpn@.service` was created before `systemctl restart`.

Fix https://github.com/angristan/openvpn-install/issues/583
2020-03-28 15:41:37 +01:00
Henry NandGitHub 3d075c8708 Print warning about empty public interface (#581)
Warning, if cannot detect public interface, and give user a choice to continue or abord.
2020-03-26 21:27:16 +01:00
Henry NandGitHub 23e533431a Fix error messag mkdir /etc/iptables (#580)
Fix this error message:
mkdir: cannot create directory ‘/etc/iptables’: File exists
2020-03-26 21:24:50 +01:00
Henry NandGitHub 130659b003 Add explicit-exit-notify for UDP (#579)
For faster reconnects with UDP is better to send the the explicit-exit-notify to server. With this the server can directly see, that the client will exit.
2020-03-26 21:24:20 +01:00
StanislasandGitHub 14bcfbd531 Run action on PRs (#582) 2020-03-26 21:22:48 +01:00
Henry NandGitHub aab5e7b2ff Fix getting pulic interface in IPv6 only (#578)
In a IPv6 only environment, the variable $NIC would be empty and iptables in add-openvpn-rules.sh will fail by missing argument.
2020-03-26 21:22:22 +01:00
randomshellandGitHub 6bb87ae716 Install semanage command on CentoOS (#554)
CentOS has selinux enabled by default but it hasn't the `semanage` command required to run OpenVPN on another port.
'policycoreutils-python*' match `policycoreutils-python' in CentOS 7 and `policycoreutils-python-utils` in Centos 8.
2020-03-14 20:25:22 +01:00
xPakrikxandGitHub 3f2ad88cbf Custom DNS option wrong value fix (#559)
Custom DNS option wrong value fix
2020-03-10 10:43:13 +01:00
Stanislas Lange 7a4f9278e7 Add new DNS option: NextDNS 2020-03-03 23:04:18 +01:00
StanislasandGitHub 006167b3c7 Doc: Add Viscosity as a supported macOS client 2020-02-20 23:57:43 +01:00
angristan 4b0f47b534 Fix Fedora detection 2020-01-27 18:08:06 +01:00
StanislasandGitHub 69c4751236 Remove saythanks.io :(
RIP https://github.com/BlitzKraft/saythanks.io/issues/60
2020-01-27 17:40:40 +01:00
StanislasandGitHub caa571f768 Fix GitHub action (#515) 2019-11-11 15:37:09 +09:00
Safa BayarandStanislas 12ba1a9d9a Add Centos 8 Support (#506) 2019-11-11 15:18:34 +09:00
Dominic DumraufandStanislas 40a9fb975a Documenting One-Stop Solution for AWS (#490) 2019-10-02 11:40:49 +09:00
Rhys PerryandStanislas a3ed51df0c Update supported architectures (#492) 2019-09-23 16:41:58 +09:00
Dominic DumraufandStanislas 7e8fd767aa Updating documentation around existing headless user addition feature (#488)
This closes #422
2019-09-19 16:59:20 +09:00
bc109db04f Add support for custom DNS input (#470)
Close #258 #260

Co-authored-by: Sayem Chowdhury <sayem314@gmail.com>
2019-08-20 21:02:47 +02:00
StanislasandGitHub 4080585ab5 Workaround to remove unharmful easy-rsa error (#469)
Until easy-rsa 3.0.7.

https://github.com/OpenVPN/easy-rsa/issues/261

Fix #454
2019-08-20 21:02:05 +02:00
StanislasandGitHub 04141c6c91 Support Raspbian (#462)
Fix #382
2019-08-20 21:01:35 +02:00
angristan 0e3e7f2705 Update sysctl comment 2019-08-20 17:58:51 +02:00
StanislasandGitHub cee02eb803 Fix CentOS detection during install (#468)
Fix #463
2019-08-20 13:36:16 +02:00
StanislasandGitHub 1acab15a26 Insert iptables rules at the top (#466)
Fix #346 #465
2019-08-20 11:55:43 +02:00
Stanislas Lange f207302334 Revert "Insert iptables rules at the top (#461)"
This reverts commit de021b67d5.
2019-08-20 11:20:24 +02:00
StanislasandGitHub de021b67d5 Insert iptables rules at the top (#461)
Fix #346
2019-08-20 00:24:01 +02:00