Files
bpfire/html/cgi-bin
Erik Kapfer b66b02ab73 OpenVPN: Fix for '--ns-cert-type server is deprecated' .
- Added extended key usage based on RFC3280 TLS rules for OpenVPNs OpenSSL configuration,
so '--remote-cert-tls' can be used instead of the old and deprecated '--ns-cert-type'
if the host certificate are newely generated with this options.
Nevertheless both directives (old and new) will work also with old CAs.

- Automatic detection if the host certificate uses the new options.
If it does, '--remote-cert-tls server' will be automatically set into the client
configuration files for Net-to-Net and Roadwarriors connections.

If it does NOT, the old '--ns-cert-type server' directive will be set in the client
configuration file.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2017-10-11 11:55:16 +01:00
..
2008-02-05 19:22:05 +00:00
2014-01-09 16:50:46 +01:00
2017-10-09 14:34:21 +01:00
2015-05-12 20:41:35 +02:00
2015-10-31 21:41:58 +00:00
2016-08-06 19:34:39 +01:00
2017-03-15 13:45:05 +00:00
2017-03-15 13:45:05 +00:00
2017-05-03 17:06:29 +01:00
2015-09-21 16:40:41 +01:00
2014-04-12 12:18:57 +02:00
2017-03-15 13:45:05 +00:00
2016-04-20 16:14:14 +01:00
2017-03-15 13:45:05 +00:00
2016-09-27 19:38:38 +02:00
2014-02-04 16:13:57 +01:00
2017-03-15 13:45:05 +00:00
2016-10-02 15:13:55 +01:00
2017-09-20 22:23:19 +01:00