mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-09 10:35:53 +02:00
Core Updatr 172: Properly replace DH parameter in /var/ipfire/ovpn/n2nconf/*/*.conf
https://lists.ipfire.org/pipermail/development/2022-December/015001.html Reported-by: Michael Tremer <michael.tremer@ipfire.org> Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
This commit is contained in:
@@ -155,13 +155,7 @@ done
|
||||
chown -Rv root:root /var/ipfire/connscheduler/lib.pl /var/ipfire/updatexlrator/updxlrator-lib.pl /var/ipfire/menu.d/*
|
||||
|
||||
# Replace existing OpenVPN Diffie-Hellman parameter by ffdhe4096, as specified in RFC 7919
|
||||
if [ -f /var/ipfire/ovpn/server.conf ]; then
|
||||
sed -i 's|/var/ipfire/ovpn/ca/dh1024.pem|/etc/ssl/ffdhe4096.pem|' /var/ipfire/ovpn/server.conf
|
||||
fi
|
||||
|
||||
if [ -f "/var/ipfire/ovpn/n2nconf/*/*.conf" ]; then
|
||||
sed -i 's|/var/ipfire/ovpn/ca/dh1024.pem|/etc/ssl/ffdhe4096.pem|' /var/ipfire/ovpn/n2nconf/*/*.conf
|
||||
fi
|
||||
sed -i 's|/var/ipfire/ovpn/ca/dh1024.pem|/etc/ssl/ffdhe4096.pem|' /var/ipfire/ovpn/server.conf /var/ipfire/ovpn/n2nconf/*/*.conf
|
||||
|
||||
# Start services
|
||||
if grep -q "ENABLE_IDS=on" /var/ipfire/suricata/settings; then
|
||||
|
||||
Reference in New Issue
Block a user