Przeglądaj źródła

Add openvpn default vars to role

Allen Riddell 8 lat temu
rodzic
commit
9e71d9067f
2 zmienionych plików z 38 dodań i 0 usunięć
  1. 12
    0
      group_vars/sovereign
  2. 26
    0
      roles/vpn/defaults/main.yml

+ 12
- 0
group_vars/sovereign Wyświetl plik

@@ -50,3 +50,15 @@
50 50
 # prosody_accounts:
51 51
 #   - name: "{{ main_user_name }}"
52 52
 #     password: TODO
53
+
54
+# openvpn
55
+# -------
56
+#openvpn_key_country:  "US"
57
+#openvpn_key_province: "California"
58
+#openvpn_key_city: "Beverly Hills"
59
+#openvpn_key_org: "ACME CORPORATION"
60
+#openvpn_key_ou: "Anvil Department"
61
+#openvpn_clients:
62
+#  - laptop
63
+#  - phone
64
+#  - tablet

+ 26
- 0
roles/vpn/defaults/main.yml Wyświetl plik

@@ -0,0 +1,26 @@
1
+# Notes about security: https://blog.g3rt.nl/openvpn-security-tips.html
2
+# Check privacy: http://witch.valdikss.org.ru/
3
+
4
+openvpn_key_country:  "US"
5
+openvpn_key_province: "California"
6
+openvpn_key_city: "Beverly Hills"
7
+openvpn_key_org: "ACME CORPORATION"
8
+openvpn_key_ou: "Anvil Department"
9
+openssl_request_subject: "/C={{ openvpn_key_country }}/ST={{ openvpn_key_province }}/L={{ openvpn_key_city }}/O={{ openvpn_key_org }}/OU={{ openvpn_key_ou }}"
10
+
11
+openvpn_days_valid: "1825"
12
+openvpn_key_size: "2048"
13
+openvpn_cipher: "AES-256-CBC"
14
+openvpn_auth_digest: "SHA512"
15
+openvpn_path: "/etc/openvpn"
16
+openvpn_ca: "{{ openvpn_path }}/ca"
17
+openvpn_dhparam: "{{ openvpn_path }}/dh{{ openvpn_key_size }}.pem"
18
+openvpn_hmac_firewall: "{{ openvpn_path }}/ta.key"
19
+openvpn_server: "{{ domain }}"
20
+openvpn_port: "1194"
21
+openvpn_protocol: "udp"
22
+openvpn_mtu: "1300"
23
+openvpn_verb: "3" # "0" for anonymity
24
+openvpn_tls_version_min: "tls-version-min 1.2"
25
+openvpn_tls_cipher: "tls-cipher TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
26
+openvpn_clients: []

Ładowanie…
Anuluj
Zapisz