From a6058a1d14160dfd038fed90bd355865bf1b27b8 Mon Sep 17 00:00:00 2001 From: Jelle Dekker Date: Fri, 22 Sep 2017 03:30:14 -0500 Subject: [PATCH] The client config contains the remote-cert-tls option to check for appropriate key usage, let's do this for the server config too. --- server_config.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/server_config.txt b/server_config.txt index 70625e7..dd56b71 100644 --- a/server_config.txt +++ b/server_config.txt @@ -25,6 +25,7 @@ push "redirect-gateway def1" client-to-client duplicate-cn keepalive 10 120 +remote-cert-tls client tls-version-min 1.2 tls-auth /etc/openvpn/easy-rsa/pki/ta.key 0 cipher AES-256-CBC