easy-rsa2 was removed from FreeBSD ports tree, see:
switch to easy-rsa 3, tested on FreeBSD 12.0-RELEASE, FreeBSD 13-CURENT
Should manage the service for openvpn client service correctly. Service restart on configuration changes does not work due to dependency cycles I wasn't able to solve.
Only tested on Amazon linux (like RedHat 7).
Fix of deprecation warning:
source_permissions parameter is deprecated. Explicitly set
(file: .../manifests/ca.pp, line: 127)
source_permissions => 'use',
owner => 'root',
mode => '0755',
This is tested on puppet-agent 5.5.7-1 on Ubuntu Xenial, puppetserver 5.3.6-1 Ubuntu Xenial.
See documentation for proto:
Use protocol p for communicating with remote host. p can be udp, tcp-client, or tcp-server.The default protocol is udp when –proto is not specified.
This might be wron implemented as there is also a proto field for the
–remote host [port] [proto]
Remote host name or IP address. On the client, multiple –remote options may be specified for redundancy, each referring to a different OpenVPN server. Specifying multiple –remote options for this purpose is a special case of the more general connection-profile feature. See the documentation below.The OpenVPN client will try to connect to a server at host:port in the order specified by the list of –remote options.
proto indicates the protocol to use when connecting with the remote, and may be “tcp” or “udp”.
For forcing IPv4 or IPv6 connection suffix tcp or udp with 4/6 like udp4/udp6/tcp4/tcp6.
Thank you for contributing to this project!
Replace this comment with a description of your pull request.
Replace this comment with the list of issues or n/a.
If using crlautorenew and the crl is recreated, the service has to be reloaded,
otherwise clients can't connect if crl is getting verified. (seen on centos7)
no issue created, but i can if it helps
I noticed that
openvpn::server may instantiate
crl_days is not configurable. This will cause
crl_days to always be 30 days which can be annoying when not revoking certificates or regenerating the CRL within those 30 days.
Thus I extended this to allow a value for
openvpn::server::crl_days to be set which is then forwarded to