The client config contains the remote-cert-tls option to check for appropriate key usage, let's do this for the server config too.

This commit is contained in:
Jelle Dekker 2017-09-22 03:30:14 -05:00
parent d1652a03b1
commit a6058a1d14

View file

@ -25,6 +25,7 @@ push "redirect-gateway def1"
client-to-client
duplicate-cn
keepalive 10 120
remote-cert-tls client
tls-version-min 1.2
tls-auth /etc/openvpn/easy-rsa/pki/ta.key 0
cipher AES-256-CBC