No Description
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

main.yml 1.1KB

12345678910111213141516171819202122232425262728
  1. # Notes about security: https://blog.g3rt.nl/openvpn-security-tips.html
  2. # Check privacy: http://witch.valdikss.org.ru/
  3. openvpn_ip_start: "10.8.0"
  4. openvpn_key_country: "US"
  5. openvpn_key_province: "California"
  6. openvpn_key_city: "Beverly Hills"
  7. openvpn_key_org: "{{ domain }}"
  8. openvpn_key_ou: "{{ server_name }}"
  9. openssl_request_subject: "/C={{ openvpn_key_country }}/ST={{ openvpn_key_province }}/L={{ openvpn_key_city }}/O={{ openvpn_key_org }}/OU={{ openvpn_key_ou }}"
  10. openvpn_days_valid: "1825"
  11. openvpn_key_size: "2048"
  12. openvpn_cipher: "AES-256-CBC"
  13. openvpn_auth_digest: "SHA512"
  14. openvpn_path: "/etc/openvpn"
  15. openvpn_ca: "{{ openvpn_path }}/ca"
  16. openvpn_dhparam: "{{ openvpn_path }}/dh{{ openvpn_key_size }}.pem"
  17. openvpn_hmac_firewall: "{{ openvpn_path }}/ta.key"
  18. openvpn_server: "{{ domain }}"
  19. openvpn_port: "1194"
  20. openvpn_protocol: "udp"
  21. openvpn_mtu: "1300"
  22. openvpn_verb: "3" # "0" for anonymity
  23. openvpn_tls_version_min: "tls-version-min 1.2"
  24. openvpn_tls_cipher: "tls-cipher TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
  25. openvpn_clients: []