答案1
openvpn 需要 ssl 证书,即使您不想拥有用于用户身份验证或 tls 防火墙的证书。
从 openvpn 导入 ssl 证书,然后您可以保存配置文件。
openvpn 证书;
ca.crt (must have)
user.crt (optional: user auth)
user.key (optional: user auth)
ta.crt (optional: firewall)
使用所有 3x 证书的示例配置:
client
dev tun
proto udp
remote 192.168.0.2
persist-key
persist-tun
ca ca.crt
cert user.crt
key user.key
auth-user-pass tmp.ovpn
comp-lzo yes
nobind
auth-nocache
script-security 2
reneg-sec 21600
tls-auth ta.key 1
cipher AES-256-CFB8
tls-cipher TLS-DHE-RSA-WITH-AES-256-CBC-SHA
remote-cert-tls server
auth SHA512