Code: Select all
● openvpn.service - OpenVPN service
Loaded: loaded (/lib/systemd/system/openvpn.service; enabled; vendor preset: enabled)
Active: active (exited) since Thu 2019-08-22 10:16:10 UTC; 1 day 4h ago
Main PID: 549 (code=exited, status=0/SUCCESS)
Memory: 0B
CGroup: /system.slice/openvpn.service
Warning: Journal has been rotated since unit was started. Log output is incomplete or unavailable.
● openvpn@apollo.service - OpenVPN connection to apollo
Loaded: loaded (/lib/systemd/system/openvpn@.service; enabled; vendor preset: enabled)
Active: active (running) since Thu 2019-08-22 10:16:13 UTC; 1 day 4h ago
Docs: man:openvpn(8)
https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage
https://community.openvpn.net/openvpn/wiki/HOWTO
Main PID: 570 (openvpn)
Status: "Initialization Sequence Completed"
Memory: 1.1M
CGroup: /system.slice/system-openvpn.slice/openvpn@apollo.service
└─570 /usr/sbin/openvpn --daemon ovpn-apollo --status /run/openvpn/apollo.status 10 --cd /etc/openvpn --config /etc/openvpn/apollo.conf --writepid /run/openvpn/apollo.pid
Warning: Journal has been rotated since unit was started. Log output is incomplete or unavailable.
Hi Dougie,DougieLawson wrote: ↑Wed Aug 21, 2019 7:21 amThere's some arcane incantations needed for openvpn with systemd.
With a /etc/openvpn/foobar.conf
sudo systemctl enable openvpn@foobar gets it running.
It's a bit quirky that you have to enable the config name like that.
Code: Select all
sudo openvpn --config /etc/openvpn/client/BosseB_local95.ovpn --daemonCode: Select all
sudo systemctl enable openvpn@BosseB_local95I tried the removal but got:DougieLawson wrote: ↑Fri Dec 20, 2019 3:19 amThere's no password on any of my certificates or private keys.
openssl rsa -in /etc/openvpn/mypasswordprotected.key -out /etc/openvpn/mykeywithoutapassword.key
Code: Select all
pi@rpi4-gui:/etc/openvpn $ sudo ssl -in BosseB_RPi_local95.ovpn -out BosseB_RPi_local95_NP.ovpn
sudo: ssl: command not found
pi@rpi4-gui:/etc/openvpn $ which ssl
pi@rpi4-gui:/etc/openvpn $
Code: Select all
pi@rpi4-gui:/etc/openvpn $ sudo openssl -in BosseB_RPi_local95.ovpn -out BosseB_RPi_local95-NP.ovpn
Invalid command '-in'; type "help" for a list.
pi@rpi4-gui:/etc/openvpn $ openssl help
Standard commands
asn1parse ca ciphers cms
crl crl2pkcs7 dgst dhparam
dsa dsaparam ec ecparam
enc engine errstr gendsa
genpkey genrsa help list
nseq ocsp passwd pkcs12
pkcs7 pkcs8 pkey pkeyparam
pkeyutl prime rand rehash
req rsa rsautl s_client
s_server s_time sess_id smime
speed spkac srp storeutl
ts verify version x509
Message Digest commands (see the `dgst' command for more details)
blake2b512 blake2s256 gost md4
md5 rmd160 sha1 sha224
sha256 sha3-224 sha3-256 sha3-384
sha3-512 sha384 sha512 sha512-224
sha512-256 shake128 shake256 sm3
Cipher commands (see the `enc' command for more details)
aes-128-cbc aes-128-ecb aes-192-cbc aes-192-ecb
aes-256-cbc aes-256-ecb aria-128-cbc aria-128-cfb
aria-128-cfb1 aria-128-cfb8 aria-128-ctr aria-128-ecb
aria-128-ofb aria-192-cbc aria-192-cfb aria-192-cfb1
aria-192-cfb8 aria-192-ctr aria-192-ecb aria-192-ofb
aria-256-cbc aria-256-cfb aria-256-cfb1 aria-256-cfb8
aria-256-ctr aria-256-ecb aria-256-ofb base64
bf bf-cbc bf-cfb bf-ecb
bf-ofb camellia-128-cbc camellia-128-ecb camellia-192-cbc
camellia-192-ecb camellia-256-cbc camellia-256-ecb cast
cast-cbc cast5-cbc cast5-cfb cast5-ecb
cast5-ofb des des-cbc des-cfb
des-ecb des-ede des-ede-cbc des-ede-cfb
des-ede-ofb des-ede3 des-ede3-cbc des-ede3-cfb
des-ede3-ofb des-ofb des3 desx
rc2 rc2-40-cbc rc2-64-cbc rc2-cbc
rc2-cfb rc2-ecb rc2-ofb rc4
rc4-40 seed seed-cbc seed-cfb
seed-ecb seed-ofb sm4-cbc sm4-cfb
sm4-ctr sm4-ecb sm4-ofb
I am blushing in humiliation!!!
Code: Select all
pi@rpi4-gui:/etc/openvpn $ sudo openvpn --config /etc/openvpn/BosseB_RPi_local95_NP.ovpn
Sat Dec 21 00:50:31 2019 OpenVPN 2.4.7 arm-unknown-linux-gnueabihf [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Feb 20 2019
Sat Dec 21 00:50:31 2019 library versions: OpenSSL 1.1.1d 10 Sep 2019, LZO 2.10
Sat Dec 21 00:50:31 2019 TCP/UDP: Preserving recently used remote address: [AF_INET]209.xx.xx.36:1195
Sat Dec 21 00:50:31 2019 UDP link local: (not bound)
Sat Dec 21 00:50:31 2019 UDP link remote: [AF_INET]209.xx.xx.36:1195
Sat Dec 21 00:50:32 2019 [AGIVPN] Peer Connection Initiated with [AF_INET]209.xx.xx.36:1195
Sat Dec 21 00:50:33 2019 TUN/TAP device tun0 opened
Sat Dec 21 00:50:33 2019 /sbin/ip link set dev tun0 up mtu 1500
Sat Dec 21 00:50:33 2019 /sbin/ip addr add dev tun0 10.8.1.5/24 broadcast 10.8.1.255
Sat Dec 21 00:50:33 2019 Initialization Sequence Completed
--- here terminal blocks inside openvpn until I use Ctrl-C ----
^C
Sat Dec 21 00:51:48 2019 event_wait : Interrupted system call (code=4)
Sat Dec 21 00:51:48 2019 /sbin/ip addr del dev tun0 10.8.1.5/24
Sat Dec 21 00:51:48 2019 SIGINT[hard,] received, process exiting
pi@rpi4-gui:/etc/openvpn $