|
@@ -0,0 +1,26 @@
|
|
1
|
+# Notes about security: https://blog.g3rt.nl/openvpn-security-tips.html
|
|
2
|
+# Check privacy: http://witch.valdikss.org.ru/
|
|
3
|
+
|
|
4
|
+openvpn_key_country: "US"
|
|
5
|
+openvpn_key_province: "California"
|
|
6
|
+openvpn_key_city: "Beverly Hills"
|
|
7
|
+openvpn_key_org: "ACME CORPORATION"
|
|
8
|
+openvpn_key_ou: "Anvil Department"
|
|
9
|
+openssl_request_subject: "/C={{ openvpn_key_country }}/ST={{ openvpn_key_province }}/L={{ openvpn_key_city }}/O={{ openvpn_key_org }}/OU={{ openvpn_key_ou }}"
|
|
10
|
+
|
|
11
|
+openvpn_days_valid: "1825"
|
|
12
|
+openvpn_key_size: "2048"
|
|
13
|
+openvpn_cipher: "AES-256-CBC"
|
|
14
|
+openvpn_auth_digest: "SHA512"
|
|
15
|
+openvpn_path: "/etc/openvpn"
|
|
16
|
+openvpn_ca: "{{ openvpn_path }}/ca"
|
|
17
|
+openvpn_dhparam: "{{ openvpn_path }}/dh{{ openvpn_key_size }}.pem"
|
|
18
|
+openvpn_hmac_firewall: "{{ openvpn_path }}/ta.key"
|
|
19
|
+openvpn_server: "{{ domain }}"
|
|
20
|
+openvpn_port: "1194"
|
|
21
|
+openvpn_protocol: "udp"
|
|
22
|
+openvpn_mtu: "1300"
|
|
23
|
+openvpn_verb: "3" # "0" for anonymity
|
|
24
|
+openvpn_tls_version_min: "tls-version-min 1.2"
|
|
25
|
+openvpn_tls_cipher: "tls-cipher TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
|
|
26
|
+openvpn_clients: []
|