Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #199786 > unrolled thread

OpenVPN & Debian Stretch

Started by"Josh W." <joshw8104@gmail.com>
First post2018-09-05 01:10 +0200
Last post2018-09-05 20:00 +0200
Articles 14 — 5 participants

Back to article view | Back to linux.debian.user


Contents

  OpenVPN & Debian Stretch "Josh W." <joshw8104@gmail.com> - 2018-09-05 01:10 +0200
    Re: OpenVPN & Debian Stretch Dan Ritter <dsr@randomstring.org> - 2018-09-05 01:30 +0200
    Re: OpenVPN & Debian Stretch Dan Purgert <dan@djph.net> - 2018-09-05 01:50 +0200
      Re: OpenVPN & Debian Stretch Wayne Sallee <Wayne@WayneSallee.com> - 2018-09-05 02:00 +0200
        Re: OpenVPN & Debian Stretch Dan Ritter <dsr@randomstring.org> - 2018-09-05 02:10 +0200
          Re: OpenVPN & Debian Stretch Dan Purgert <dan@djph.net> - 2018-09-05 02:40 +0200
            Re: OpenVPN & Debian Stretch Dan Ritter <dsr@randomstring.org> - 2018-09-05 12:10 +0200
              Re: OpenVPN & Debian Stretch Dan Purgert <dan@djph.net> - 2018-09-05 12:50 +0200
                Re: OpenVPN & Debian Stretch Wayne Sallee <Wayne@WayneSallee.com> - 2018-09-05 13:00 +0200
                  Re: OpenVPN & Debian Stretch Dan Ritter <dsr@randomstring.org> - 2018-09-05 15:00 +0200
                    Re: OpenVPN & Debian Stretch Wayne Sallee <Wayne@WayneSallee.com> - 2018-09-06 01:10 +0200
                    Re: OpenVPN & Debian Stretch Wayne Sallee <Wayne@WayneSallee.com> - 2018-09-06 17:40 +0200
    Re: OpenVPN & Debian Stretch Wayne Sallee <Wayne@WayneSallee.com> - 2018-09-05 13:00 +0200
      Re: OpenVPN & Debian Stretch deloptes <deloptes@gmail.com> - 2018-09-05 20:00 +0200

#199786 — OpenVPN & Debian Stretch

From"Josh W." <joshw8104@gmail.com>
Date2018-09-05 01:10 +0200
SubjectOpenVPN & Debian Stretch
Message-ID<wusCl-8vj-9@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Debian Users,
         I am having a terrible time setting up a free VPN Service! Could
"Any Body" point me to an UP To Date way. to set up OpenVPN on Debian
Stretch? Your Help is Much Needed!!! Thank you!

Joshua <joshw8104@gmail.com>

[toc] | [next] | [standalone]


#199787

FromDan Ritter <dsr@randomstring.org>
Date2018-09-05 01:30 +0200
Message-ID<wusVH-9v-5@gated-at.bofh.it>
In reply to#199786
On Tue, Sep 04, 2018 at 05:47:37PM -0500, Josh W. wrote:
> Debian Users,
>          I am having a terrible time setting up a free VPN Service! Could
> "Any Body" point me to an UP To Date way. to set up OpenVPN on Debian
> Stretch? Your Help is Much Needed!!! Thank you!

sudo apt install openvpn easy-rsa

Then follow basically any configuration guide.

-dsr-

[toc] | [prev] | [next] | [standalone]


#199788

FromDan Purgert <dan@djph.net>
Date2018-09-05 01:50 +0200
Message-ID<wutf3-fe-1@gated-at.bofh.it>
In reply to#199786
Josh W. wrote:
> Debian Users,
>          I am having a terrible time setting up a free VPN Service! Could
> "Any Body" point me to an UP To Date way. to set up OpenVPN on Debian
> Stretch? Your Help is Much Needed!!! Thank you!
>
> Joshua <joshw8104@gmail.com>
>
apt-get install openvpn-server 

Should be enough to get the server going with bogus certs.  Then you
just have to generate yourself some certs to use (CA, Server, and
Client(s)).

I think the generally easy approach to the cert generation is easy-rsa
(which is a separate package these days).

-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#199789

FromWayne Sallee <Wayne@WayneSallee.com>
Date2018-09-05 02:00 +0200
Message-ID<wutoK-ig-3@gated-at.bofh.it>
In reply to#199788
Has anyone set up OpenVPN with ssh-keygen -t rsa ?

Wayne Sallee
Wayne@WayneSallee.com
http://www.WayneSallee.com


On 09/04/2018 07:34 PM, Dan Purgert wrote:
> Josh W. wrote:
>> Debian Users,
>>           I am having a terrible time setting up a free VPN Service! Could
>> "Any Body" point me to an UP To Date way. to set up OpenVPN on Debian
>> Stretch? Your Help is Much Needed!!! Thank you!
>>
>> Joshua <joshw8104@gmail.com>
>>
> apt-get install openvpn-server
>
> Should be enough to get the server going with bogus certs.  Then you
> just have to generate yourself some certs to use (CA, Server, and
> Client(s)).
>
> I think the generally easy approach to the cert generation is easy-rsa
> (which is a separate package these days).
>

[toc] | [prev] | [next] | [standalone]


#199790

FromDan Ritter <dsr@randomstring.org>
Date2018-09-05 02:10 +0200
Message-ID<wutyp-AG-5@gated-at.bofh.it>
In reply to#199789
On Tue, Sep 04, 2018 at 07:42:58PM -0400, Wayne Sallee wrote:
> Has anyone set up OpenVPN with ssh-keygen -t rsa ?
> 

Technically, you can do that.

In practice, you need to have a CA set up, of which easy-rsa is
the simplest choice.

Why? Revocation.

Let's suppose you have an SSH server. Because you are cautious,
you require SSH key auth. One day your laptop is stolen. It has
an SSH private key on it, so you go over to
~/.ssh/authorized_keys and delete the matching public key. Good, 
you have secured your server against unauthorized use of your
account.

OpenVPN doesn't do that. OpenVPN assumes that any properly
signed certificate is wonderful, and you can't get rid of one
just by removing a cert entry on your side. Instead, you need
to formally revoke the certificate, and keep it revoked until 
it reaches its expiration date.

https://community.openvpn.net/openvpn/wiki/Hardening

-dsr-

[toc] | [prev] | [next] | [standalone]


#199792

FromDan Purgert <dan@djph.net>
Date2018-09-05 02:40 +0200
Message-ID<wuu1r-Jy-1@gated-at.bofh.it>
In reply to#199790
Dan Ritter wrote:
> On Tue, Sep 04, 2018 at 07:42:58PM -0400, Wayne Sallee wrote:
>> Has anyone set up OpenVPN with ssh-keygen -t rsa ?
>> 
>
> Technically, you can do that.

ssh-keygen generates ssh keys, not x.509 certificates ... 


-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#199805

FromDan Ritter <dsr@randomstring.org>
Date2018-09-05 12:10 +0200
Message-ID<wuCV4-693-21@gated-at.bofh.it>
In reply to#199792
On Wed, Sep 05, 2018 at 12:29:02AM -0000, Dan Purgert wrote:
> Dan Ritter wrote:
> > On Tue, Sep 04, 2018 at 07:42:58PM -0400, Wayne Sallee wrote:
> >> Has anyone set up OpenVPN with ssh-keygen -t rsa ?
> >> 
> >
> > Technically, you can do that.
> 
> ssh-keygen generates ssh keys, not x.509 certificates ... 

An x.509 cert contains an RSA key signed by a CA. openssl can do
the signing, at which point you've half-reimplemented easy-rsa.

-dsr-

[toc] | [prev] | [next] | [standalone]


#199808

FromDan Purgert <dan@djph.net>
Date2018-09-05 12:50 +0200
Message-ID<wuDxL-6l6-11@gated-at.bofh.it>
In reply to#199805
Dan Ritter wrote:
> On Wed, Sep 05, 2018 at 12:29:02AM -0000, Dan Purgert wrote:
>> Dan Ritter wrote:
>> > On Tue, Sep 04, 2018 at 07:42:58PM -0400, Wayne Sallee wrote:
>> >> Has anyone set up OpenVPN with ssh-keygen -t rsa ?
>> >> 
>> >
>> > Technically, you can do that.
>> 
>> ssh-keygen generates ssh keys, not x.509 certificates ... 
>
> An x.509 cert contains an RSA key signed by a CA. openssl can do
> the signing, at which point you've half-reimplemented easy-rsa.
>
> -dsr-

Sure - but it just seems silly to use ssh-keygen, then openssl to
convert it to the right format when openssl (or the easy-rsa wrapper
thereto) can do all the work for you in one go.


-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#199810

FromWayne Sallee <Wayne@WayneSallee.com>
Date2018-09-05 13:00 +0200
Message-ID<wuDHr-6og-3@gated-at.bofh.it>
In reply to#199808

On 09/05/2018 06:30 AM, Dan Purgert wrote:
> Dan Ritter wrote:
>> On Wed, Sep 05, 2018 at 12:29:02AM -0000, Dan Purgert wrote:
>>> Dan Ritter wrote:
>>>> On Tue, Sep 04, 2018 at 07:42:58PM -0400, Wayne Sallee wrote:
>>>>> Has anyone set up OpenVPN with ssh-keygen -t rsa ?
>>>>>
>>>> Technically, you can do that.
>>> ssh-keygen generates ssh keys, not x.509 certificates ...
>> An x.509 cert contains an RSA key signed by a CA. openssl can do
>> the signing, at which point you've half-reimplemented easy-rsa.
>>
>> -dsr-
> Sure - but it just seems silly to use ssh-keygen, then openssl to
> convert it to the right format when openssl (or the easy-rsa wrapper
> thereto) can do all the work for you in one go.
>
>
Ok, then it would be better to use openssl instead of ssh-keygen?

I'm looking at putting OpenVPN on an established server, and wondering if it is really nessesary to install easy-rsa 
when I already have established ways of generating ssh keys.

Wayne Sallee
Wayne@WayneSallee.com
http://www.WayneSallee.com

[toc] | [prev] | [next] | [standalone]


#199813

FromDan Ritter <dsr@randomstring.org>
Date2018-09-05 15:00 +0200
Message-ID<wuFzz-7tk-1@gated-at.bofh.it>
In reply to#199810
On Wed, Sep 05, 2018 at 06:56:44AM -0400, Wayne Sallee wrote:
> 
> 
> On 09/05/2018 06:30 AM, Dan Purgert wrote:
> > Dan Ritter wrote:
> > > On Wed, Sep 05, 2018 at 12:29:02AM -0000, Dan Purgert wrote:
> > > > Dan Ritter wrote:
> > > > > On Tue, Sep 04, 2018 at 07:42:58PM -0400, Wayne Sallee wrote:
> > > > > > Has anyone set up OpenVPN with ssh-keygen -t rsa ?
> > > > > > 
> > > > > Technically, you can do that.
> > > > ssh-keygen generates ssh keys, not x.509 certificates ...
> > > An x.509 cert contains an RSA key signed by a CA. openssl can do
> > > the signing, at which point you've half-reimplemented easy-rsa.
> > > 
> > > -dsr-
> > Sure - but it just seems silly to use ssh-keygen, then openssl to
> > convert it to the right format when openssl (or the easy-rsa wrapper
> > thereto) can do all the work for you in one go.
> > 
> > 
> Ok, then it would be better to use openssl instead of ssh-keygen?
> 
> I'm looking at putting OpenVPN on an established server, and wondering if it
> is really nessesary to install easy-rsa when I already have established ways
> of generating ssh keys.

easy-rsa is basically a series of scripts to get openssl to do
the right thing for you, consistently.

Do that.

Alternatively, look into installing wireguard from unstable. (It
won't drag in anything weird.) Wireguard matches your conception
of how a VPN should work -- and is currently being integrated
into the Linux kernel, because practically everybody likes it
better than OpenVPN, and most people prefer it to IPsec.

-dsr-

[toc] | [prev] | [next] | [standalone]


#199820

FromWayne Sallee <Wayne@WayneSallee.com>
Date2018-09-06 01:10 +0200
Message-ID<wuP5T-4V2-7@gated-at.bofh.it>
In reply to#199813

On 09/05/2018 08:51 AM, Dan Ritter wrote:
> On Wed, Sep 05, 2018 at 06:56:44AM -0400, Wayne Sallee wrote:
>>
>> On 09/05/2018 06:30 AM, Dan Purgert wrote:
>>> Dan Ritter wrote:
>>>> On Wed, Sep 05, 2018 at 12:29:02AM -0000, Dan Purgert wrote:
>>>>> Dan Ritter wrote:
>>>>>> On Tue, Sep 04, 2018 at 07:42:58PM -0400, Wayne Sallee wrote:
>>>>>>> Has anyone set up OpenVPN with ssh-keygen -t rsa ?
>>>>>>>
>>>>>> Technically, you can do that.
>>>>> ssh-keygen generates ssh keys, not x.509 certificates ...
>>>> An x.509 cert contains an RSA key signed by a CA. openssl can do
>>>> the signing, at which point you've half-reimplemented easy-rsa.
>>>>
>>>> -dsr-
>>> Sure - but it just seems silly to use ssh-keygen, then openssl to
>>> convert it to the right format when openssl (or the easy-rsa wrapper
>>> thereto) can do all the work for you in one go.
>>>
>>>
>> Ok, then it would be better to use openssl instead of ssh-keygen?
>>
>> I'm looking at putting OpenVPN on an established server, and wondering if it
>> is really nessesary to install easy-rsa when I already have established ways
>> of generating ssh keys.
> easy-rsa is basically a series of scripts to get openssl to do
> the right thing for you, consistently.
>
> Do that.
>
> Alternatively, look into installing wireguard from unstable. (It
> won't drag in anything weird.) Wireguard matches your conception
> of how a VPN should work -- and is currently being integrated
> into the Linux kernel, because practically everybody likes it
> better than OpenVPN, and most people prefer it to IPsec.
>
> -dsr-
>
>

Thanks for the tip about wireguard. It's still beta, but it looks promising.

Wayne Sallee
Wayne@WayneSallee.com
http://www.WayneSallee.com

[toc] | [prev] | [next] | [standalone]


#199835

FromWayne Sallee <Wayne@WayneSallee.com>
Date2018-09-06 17:40 +0200
Message-ID<wv4xY-5pO-13@gated-at.bofh.it>
In reply to#199813
Thanks.

I'll install openvpn, and easy-rsa on a test computer and see what it does, before installing it on my server.

Wayne Sallee
Wayne@WayneSallee.com
http://www.WayneSallee.com

On 09/05/2018 08:51 AM, Dan Ritter wrote:
> easy-rsa is basically a series of scripts to get openssl to do
> the right thing for you, consistently.

[toc] | [prev] | [next] | [standalone]


#199809

FromWayne Sallee <Wayne@WayneSallee.com>
Date2018-09-05 13:00 +0200
Message-ID<wuDHr-6og-1@gated-at.bofh.it>
In reply to#199786

On 09/04/2018 06:47 PM, Josh W. wrote:
> Debian Users,
>          I am having a terrible time setting up a free VPN Service! Could "Any Body" point me to an UP To Date way. to 
> set up OpenVPN on Debian Stretch? Your Help is Much Needed!!! Thank you!
>
> Joshua <joshw8104@gmail.com <mailto:joshw8104@gmail.com>>

I will also be installing OpenVPN on Debian Stretch (Debian 9). What problems are you having?

Wayne Sallee
Wayne@WayneSallee.com
http://www.WayneSallee.com

[toc] | [prev] | [next] | [standalone]


#199816

Fromdeloptes <deloptes@gmail.com>
Date2018-09-05 20:00 +0200
Message-ID<wuKfT-1Lm-3@gated-at.bofh.it>
In reply to#199809
Wayne Sallee wrote:

> I will also be installing OpenVPN on Debian Stretch (Debian 9). What
> problems are you having?

go for installation - there are no problems discussed here - only how one
should generate the certificate for the client.

The easy-rsa is a set of scripts that makes generation of client
certificates really easy. You may need however to read some good how to. I
used the debians howto : https://wiki.debian.org/OpenVPN

it was may be 7 or 8y ago - the how to is now even better

regards

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web