Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ##############################################
- # Sample client-side OpenVPN 2.0 config file #
- # for connecting to multi-client server. #
- # #
- # This configuration can be used by multiple #
- # clients, however each client should have #
- # its own cert and key files. #
- # #
- # On Windows, you might want to rename this #
- # file so it has a .ovpn extension #
- ##############################################
- # Specify that we are a client and that we
- # will be pulling certain config file directives
- # from the server.
- client
- # Use the same setting as you are using on
- # the server.
- # On most systems, the VPN will not function
- # unless you partially or fully disable
- # the firewall for the TUN/TAP interface.
- ;dev tap
- dev tun
- # Windows needs the TAP-Win32 adapter name
- # from the Network Connections panel
- # if you have more than one. On XP SP2,
- # you may need to disable the firewall
- # for the TAP adapter.
- ;dev-node MyTap
- # Are we connecting to a TCP or
- # UDP server? Use the same setting as
- # on the server.
- ;proto tcp
- proto udp
- # The hostname/IP and port of the server.
- # You can have multiple remote entries
- # to load balance between the servers.
- remote 74.91.122.204 1194
- ;remote my-server-2 1194
- # Choose a random host from the remote
- # list for load-balancing. Otherwise
- # try hosts in the order specified.
- ;remote-random
- # Keep trying indefinitely to resolve the
- # host name of the OpenVPN server. Very useful
- # on machines which are not permanently connected
- # to the internet such as laptops.
- resolv-retry infinite
- # Most clients don't need to bind to
- # a specific local port number.
- nobind
- # Downgrade privileges after initialization (non-Windows only)
- ;user nobody
- ;group nogroup
- # Try to preserve some state across restarts.
- persist-key
- persist-tun
- # If you are connecting through an
- # HTTP proxy to reach the actual OpenVPN
- # server, put the proxy server/IP and
- # port number here. See the man page
- # if your proxy server requires
- # authentication.
- ;http-proxy-retry # retry on connection failures
- ;http-proxy [proxy server] [proxy port #]
- # Wireless networks often produce a lot
- # of duplicate packets. Set this flag
- # to silence duplicate packet warnings.
- ;mute-replay-warnings
- # SSL/TLS parms.
- # See the server config file for more
- # description. It's best to use
- # a separate .crt/.key file pair
- # for each client. A single ca
- # file can be used for all clients.
- # Verify server certificate by checking
- # that the certicate has the nsCertType
- # field set to "server". This is an
- # important precaution to protect against
- # a potential attack discussed here:
- # http://openvpn.net/howto.html#mitm
- #
- # To use this feature, you will need to generate
- # your server certificates with the nsCertType
- # field set to "server". The build-key-server
- # script in the easy-rsa folder will do this.
- ns-cert-type server
- # If a tls-auth key is used on the server
- # then every client must also have the key.
- ;tls-auth ta.key 1
- # Select a cryptographic cipher.
- # If the cipher option is used on the server
- # then you must also specify it here.
- ;cipher x
- # Enable compression on the VPN link.
- # Don't enable this unless it is also
- # enabled in the server config file.
- comp-lzo
- # Set log file verbosity.
- verb 3
- # Silence repeating messages
- ;mute 20
- <ca>
- -----BEGIN CERTIFICATE-----
- MIIFEjCCA/qgAwIBAgIJAKvUnRwXj5ZMMA0GCSqGSIb3DQEBCwUAMIG2MQswCQYD
- VQQGEwJVUzELMAkGA1UECBMCQ0ExFTATBgNVBAcTDFNhbkZyYW5jaXNjbzEVMBMG
- A1UEChMMRm9ydC1GdW5zdG9uMR0wGwYDVQQLExRNeU9yZ2FuaXphdGlvbmFsVW5p
- dDEYMBYGA1UEAxMPRm9ydC1GdW5zdG9uIENBMRAwDgYDVQQpEwdFYXN5UlNBMSEw
- HwYJKoZIhvcNAQkBFhJtZUBteWhvc3QubXlkb21haW4wHhcNMTUwNDA0MDk1ODI2
- WhcNMjUwNDAxMDk1ODI2WjCBtjELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAkNBMRUw
- EwYDVQQHEwxTYW5GcmFuY2lzY28xFTATBgNVBAoTDEZvcnQtRnVuc3RvbjEdMBsG
- A1UECxMUTXlPcmdhbml6YXRpb25hbFVuaXQxGDAWBgNVBAMTD0ZvcnQtRnVuc3Rv
- biBDQTEQMA4GA1UEKRMHRWFzeVJTQTEhMB8GCSqGSIb3DQEJARYSbWVAbXlob3N0
- Lm15ZG9tYWluMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAur4bHBnu
- KYqC06L6YfnPSjhFxVfG5O76y0j6TB8nBcvzABBQ/bHzXP36BmE/bhX1+EdTl2cL
- B3LFGubRfqP3vET0CkvRxdLwwtvdj8HkbR4VZDL4UIBnQLpRJu9oeA7TW9Az3u8i
- k4/JB//rScFPqnXQCDag89K5VrUFDJawRlgR2hucb7m2eiYrdXfDTUov3m4bXE/8
- 0YR9FpenCZDuaqUobgpxW1qTC+VKP33qAgnSLDJtKjdePxW7nUOybyjIwkwk07bq
- 1kKqoVHpuAR16DYD1QyYxSAE1fbTSswe6oU6B2oZcZz7owIUlKJFPuy2ipqOQSTv
- eALnjm/DGLt6mQIDAQABo4IBHzCCARswHQYDVR0OBBYEFMfOnhesErQGkRpoVQGm
- nWfLPRgoMIHrBgNVHSMEgeMwgeCAFMfOnhesErQGkRpoVQGmnWfLPRgooYG8pIG5
- MIG2MQswCQYDVQQGEwJVUzELMAkGA1UECBMCQ0ExFTATBgNVBAcTDFNhbkZyYW5j
- aXNjbzEVMBMGA1UEChMMRm9ydC1GdW5zdG9uMR0wGwYDVQQLExRNeU9yZ2FuaXph
- dGlvbmFsVW5pdDEYMBYGA1UEAxMPRm9ydC1GdW5zdG9uIENBMRAwDgYDVQQpEwdF
- YXN5UlNBMSEwHwYJKoZIhvcNAQkBFhJtZUBteWhvc3QubXlkb21haW6CCQCr1J0c
- F4+WTDAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQAsPJUzBBYJ1+rA
- CAt5Tgz/8eyUsmeGBswa/Pap2gH3jbIAo3GjJxx4C7vhAi0S/8LhTV5TrVOPdFeZ
- Cv+t/jnPL5oI2o6z0uTHwC2z9O8TxE0k0sCwOCuB6aJ1rpXx/EESmKEc0aFRj957
- O4/6BrZRRPe8CqCSp9+/oN98Nx+FjXzQxKyZhCZVfvQ/sid/83ymmmPoUL5WFYNh
- gd6jpQ2fSA5nSVH7YXiDpqhUfcCGFQgE90ReAtmWMp7TbeMwZfYroZu2a56wxsWo
- qzN8DDHwNcYiM+5cDHDvz4DoYFqC2NbBiXAfE4VMmB86+CM24xDS9yAv71K0QynJ
- 60GBl3OC
- -----END CERTIFICATE-----
- </ca>
- <cert>
- Certificate:
- Data:
- Version: 3 (0x2)
- Serial Number: 3 (0x3)
- Signature Algorithm: sha256WithRSAEncryption
- Issuer: C=US, ST=CA, L=SanFrancisco, O=Fort-Funston, OU=MyOrganizationalUnit, CN=Fort-Funston CA/name=EasyRSA/[email protected]
- Validity
- Not Before: Apr 4 10:36:31 2015 GMT
- Not After : Apr 1 10:36:31 2025 GMT
- Subject: C=US, ST=CA, L=SanFrancisco, O=Fort-Funston, OU=MyOrganizationalUnit, CN=client/name=EasyRSA/[email protected]
- Subject Public Key Info:
- Public Key Algorithm: rsaEncryption
- Public-Key: (2048 bit)
- Modulus:
- 00:b7:ab:5b:03:7a:8e:f5:b7:1e:34:b3:83:bf:ac:
- ca:61:aa:63:6b:e5:9e:90:7d:eb:b7:16:f2:a8:1f:
- 73:e0:3d:e8:45:c4:73:1a:7e:92:48:c6:92:40:a1:
- 7b:e3:32:0f:7e:d1:65:ad:07:a5:29:6b:f9:aa:a2:
- 4a:49:4f:1f:de:08:2c:cf:8e:76:4a:73:c2:a7:53:
- 00:09:65:ac:ad:e0:d1:8f:c7:14:c8:0f:b1:55:df:
- 75:11:6a:2d:94:94:7b:76:e8:6d:5b:b7:06:05:e8:
- c7:f6:17:67:d9:89:aa:76:12:70:68:33:7a:1b:94:
- 15:1a:1e:95:d9:dc:23:93:11:21:00:d5:b0:ab:2f:
- 3d:6e:a6:f7:e0:0b:6f:f3:7e:94:43:ca:02:fc:fd:
- 3b:18:23:c6:16:55:3a:6d:ff:96:08:da:c7:3f:22:
- 95:3e:da:7b:e2:c7:38:a9:e6:2c:64:9f:f0:21:49:
- 3b:62:d1:50:b6:d6:7f:44:4f:15:20:24:81:2f:f4:
- 46:cd:a0:73:eb:23:c7:f6:5c:84:4e:5e:7e:cf:dd:
- 30:f9:73:24:89:9d:8d:fb:46:6c:24:7f:91:39:83:
- 67:58:17:39:e7:5d:28:59:5d:16:df:15:3f:d1:46:
- 56:b5:50:a4:71:0a:8e:27:51:bd:11:b1:75:6e:de:
- 4b:5f
- Exponent: 65537 (0x10001)
- X509v3 extensions:
- X509v3 Basic Constraints:
- CA:FALSE
- Netscape Comment:
- Easy-RSA Generated Certificate
- X509v3 Subject Key Identifier:
- B6:7B:DE:C1:BC:13:28:06:D1:BC:F5:18:9C:60:1D:5B:48:36:01:11
- X509v3 Authority Key Identifier:
- keyid:C7:CE:9E:17:AC:12:B4:06:91:1A:68:55:01:A6:9D:67:CB:3D:18:28
- DirName:/C=US/ST=CA/L=SanFrancisco/O=Fort-Funston/OU=MyOrganizationalUnit/CN=Fort-Funston CA/name=EasyRSA/[email protected]
- serial:AB:D4:9D:1C:17:8F:96:4C
- X509v3 Extended Key Usage:
- TLS Web Client Authentication
- X509v3 Key Usage:
- Digital Signature
- Signature Algorithm: sha256WithRSAEncryption
- 71:60:70:bb:02:04:71:13:38:64:ee:d5:8c:6a:86:b4:21:40:
- b1:95:4c:22:fd:38:25:e5:d6:4e:2e:76:a2:46:cd:6f:1b:a0:
- d0:c7:66:9a:cb:36:44:f8:58:14:c4:e5:63:f5:3c:69:22:e8:
- a2:67:54:aa:0f:97:c0:52:93:ac:48:df:21:a3:91:e3:48:bf:
- 57:9b:7f:63:bf:ac:92:5e:74:ed:0f:c1:6c:94:f3:ce:71:e9:
- 17:fb:91:d8:16:f9:2a:65:fd:f6:b5:cf:d3:6f:9d:cb:34:45:
- 39:05:35:65:05:c9:e4:c5:f3:08:fd:c1:8e:8c:48:e4:b3:35:
- 23:15:32:52:4a:ee:59:a2:80:31:83:04:64:cf:a6:49:95:ac:
- 47:41:2b:39:d0:86:5d:ee:3b:20:3f:9d:ec:41:d5:1c:d7:31:
- 55:ea:db:7f:48:bc:ca:fd:10:07:c8:a5:2a:27:b6:69:9e:10:
- 70:6d:c7:05:d0:92:33:a3:80:c4:5b:3c:d3:88:46:f1:7f:4e:
- fa:c3:3d:1a:19:56:58:d8:2e:c1:f0:29:84:2b:58:96:c6:bd:
- 6a:60:d3:41:7e:8e:e8:92:53:07:d4:6f:7f:72:2c:e6:ea:33:
- b8:9c:ff:4e:c7:32:40:b5:e2:46:db:02:35:e8:38:9b:77:aa:
- f9:b3:b1:46
- -----BEGIN CERTIFICATE-----
- MIIFTzCCBDegAwIBAgIBAzANBgkqhkiG9w0BAQsFADCBtjELMAkGA1UEBhMCVVMx
- CzAJBgNVBAgTAkNBMRUwEwYDVQQHEwxTYW5GcmFuY2lzY28xFTATBgNVBAoTDEZv
- cnQtRnVuc3RvbjEdMBsGA1UECxMUTXlPcmdhbml6YXRpb25hbFVuaXQxGDAWBgNV
- BAMTD0ZvcnQtRnVuc3RvbiBDQTEQMA4GA1UEKRMHRWFzeVJTQTEhMB8GCSqGSIb3
- DQEJARYSbWVAbXlob3N0Lm15ZG9tYWluMB4XDTE1MDQwNDEwMzYzMVoXDTI1MDQw
- MTEwMzYzMVowga0xCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJDQTEVMBMGA1UEBxMM
- U2FuRnJhbmNpc2NvMRUwEwYDVQQKEwxGb3J0LUZ1bnN0b24xHTAbBgNVBAsTFE15
- T3JnYW5pemF0aW9uYWxVbml0MQ8wDQYDVQQDEwZjbGllbnQxEDAOBgNVBCkTB0Vh
- c3lSU0ExITAfBgkqhkiG9w0BCQEWEm1lQG15aG9zdC5teWRvbWFpbjCCASIwDQYJ
- KoZIhvcNAQEBBQADggEPADCCAQoCggEBALerWwN6jvW3HjSzg7+symGqY2vlnpB9
- 67cW8qgfc+A96EXEcxp+kkjGkkChe+MyD37RZa0HpSlr+aqiSklPH94ILM+Odkpz
- wqdTAAllrK3g0Y/HFMgPsVXfdRFqLZSUe3bobVu3BgXox/YXZ9mJqnYScGgzehuU
- FRoeldncI5MRIQDVsKsvPW6m9+ALb/N+lEPKAvz9OxgjxhZVOm3/lgjaxz8ilT7a
- e+LHOKnmLGSf8CFJO2LRULbWf0RPFSAkgS/0Rs2gc+sjx/ZchE5efs/dMPlzJImd
- jftGbCR/kTmDZ1gXOeddKFldFt8VP9FGVrVQpHEKjidRvRGxdW7eS18CAwEAAaOC
- AW0wggFpMAkGA1UdEwQCMAAwLQYJYIZIAYb4QgENBCAWHkVhc3ktUlNBIEdlbmVy
- YXRlZCBDZXJ0aWZpY2F0ZTAdBgNVHQ4EFgQUtnvewbwTKAbRvPUYnGAdW0g2AREw
- gesGA1UdIwSB4zCB4IAUx86eF6wStAaRGmhVAaadZ8s9GCihgbykgbkwgbYxCzAJ
- BgNVBAYTAlVTMQswCQYDVQQIEwJDQTEVMBMGA1UEBxMMU2FuRnJhbmNpc2NvMRUw
- EwYDVQQKEwxGb3J0LUZ1bnN0b24xHTAbBgNVBAsTFE15T3JnYW5pemF0aW9uYWxV
- bml0MRgwFgYDVQQDEw9Gb3J0LUZ1bnN0b24gQ0ExEDAOBgNVBCkTB0Vhc3lSU0Ex
- ITAfBgkqhkiG9w0BCQEWEm1lQG15aG9zdC5teWRvbWFpboIJAKvUnRwXj5ZMMBMG
- A1UdJQQMMAoGCCsGAQUFBwMCMAsGA1UdDwQEAwIHgDANBgkqhkiG9w0BAQsFAAOC
- AQEAcWBwuwIEcRM4ZO7VjGqGtCFAsZVMIv04JeXWTi52okbNbxug0Mdmmss2RPhY
- FMTlY/U8aSLoomdUqg+XwFKTrEjfIaOR40i/V5t/Y7+skl507Q/BbJTzznHpF/uR
- 2Bb5KmX99rXP02+dyzRFOQU1ZQXJ5MXzCP3BjoxI5LM1IxUyUkruWaKAMYMEZM+m
- SZWsR0ErOdCGXe47ID+d7EHVHNcxVerbf0i8yv0QB8ilKie2aZ4QcG3HBdCSM6OA
- xFs804hG8X9O+sM9GhlWWNguwfAphCtYlsa9amDTQX6O6JJTB9Rvf3Is5uozuJz/
- TscyQLXiRtsCNeg4m3eq+bOxRg==
- -----END CERTIFICATE-----
- </cert>
- <key>
- -----BEGIN PRIVATE KEY-----
- MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQC3q1sDeo71tx40
- s4O/rMphqmNr5Z6Qfeu3FvKoH3PgPehFxHMafpJIxpJAoXvjMg9+0WWtB6Upa/mq
- okpJTx/eCCzPjnZKc8KnUwAJZayt4NGPxxTID7FV33URai2UlHt26G1btwYF6Mf2
- F2fZiap2EnBoM3oblBUaHpXZ3COTESEA1bCrLz1upvfgC2/zfpRDygL8/TsYI8YW
- VTpt/5YI2sc/IpU+2nvixzip5ixkn/AhSTti0VC21n9ETxUgJIEv9EbNoHPrI8f2
- XIROXn7P3TD5cySJnY37Rmwkf5E5g2dYFznnXShZXRbfFT/RRla1UKRxCo4nUb0R
- sXVu3ktfAgMBAAECggEADOcg0bG+cUyX9qPV0ZVV8l6B9YaACS6PbKFUErOC9HHk
- 62HNpELYC/zHMXsmtONDa2lSd0FePPa052PXTCce2f5BB6O+c6SGPDL8gax+4Qg2
- MJ+Pui5ACwRTuRF4ekOkGMpjRForNicQRR2H0iR1sS3Cb8+N+HoCsX8Mj+2DIkWn
- LYN/jx4wx+W7Mq0hoNSrxk3J/Lqaa09NcVSXDihokiivXSe0Mm1hqvQgZw2ulVgy
- seu8ewmq713/DlJG0FyAXwa2TRnIxtEdodgiXHgU/1ojCxsjKTdybQh/QaSvxr+O
- 8SvfIMMmpsocrmK+na7iS5nurjaXnT7r9Hxjy+Ua4QKBgQDuWyvNn4jub3ES0/Ba
- GBMdckdDHeO6d/G+X4vB2QI9qx52XVgeSCsDm/UsH/T2+mytKeGkqSLYhFGcECTh
- KwatRFZ7sA23aCQKfM6PqtrEXGokXjUimESNJJfaXlJC3UL9aT9KJjDRI0IlR/lg
- /tPGvn+RJqSzeZMaAfijvJmphQKBgQDFQ9/fyUXJNZAF8SzcllfboSjgpiDjt3QL
- rqrBmpRvk7ZyzyjqgEXROWA1SVNs2bK0DthxNI7G3/OD/gs5XwY2CCLyRWF6a8M3
- 3G5ceR6rlKMuHzxTGstYOJrCJEMGG1flVThyuNEu2KX7kj9msatHinzgIINVdf/1
- 1TUiMeJkkwKBgQC9+xUy05HE2jZ6F0tfxAiYU9nQ+SXmHmwknOs8Gsfad2XUWho+
- KK+ANPJ5tQ7/PCMa8mLTZ6xKf0y843FBt5WezPVRqMWGBg+T/F53zGqKUE6Zpi0b
- 4dnh1eTjPIK8oLcgXJ8BbudCCqRSKsfuM66Anp33B6IHG0PQWvnfKBgiMQKBgFJm
- t+3TNcOHDFJvHD5Izwp/l4O/4Z091MvMeqfE2pyBJ4Vt47mRO5jaTsXzi1W82lk8
- mk0vlzSb+Cz6wdWFTCLl4zMwqDdrLHD5M2CNd7JUtJVfluNgHfEMNBlE7HpwkZbK
- snm5mifnd+5OeQ18yf9oaiF1c2cPk4wtM7TFAbzhAoGBANWbgCQrW9fMgZbl14QO
- Ns0PG3Z3+j9nvM9D4/Ks81S1Mm0XttOuo0aCuQihu801Dxcd2euVNj+q5jZiQeOz
- BtL+serZx7hPHEZG/LmqKUf/ys8a5tNnmZnqZwkNI/ZMRas21Oe2ariroKNfzqsT
- jM/Rr7/jz91XkusW1F7VAhGT
- -----END PRIVATE KEY-----
- </key>
Advertisement
Add Comment
Please, Sign In to add comment