Skip to content

Commit bce63c2

Browse files
author
Evgeniy Ivanov
committed
ECDSA fixed
1 parent 2efaf97 commit bce63c2

File tree

5 files changed

+8
-5
lines changed

5 files changed

+8
-5
lines changed

config.cfg

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,12 @@
55
# secp384r1
66
# secp521r1
77
easyrsa_dir: /opt/easy-rsa-ipsec
8-
easyrsa_curve: prime256v1
98
easyrsa_ca_expire: 3650
109
easyrsa_cert_expire: 3650
1110
easyrsa_p12_export_password: vpn
1211

1312
# if True re-init all existing certificates. Boolean
14-
easyrsa_reinit_existent: False
13+
easyrsa_reinit_existent: True
1514

1615
# Domain or ip
1716
server_name: www.ivlis.me

configs/.gitinit

Whitespace-only changes.

templates/easy-rsa.vars.j2

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -102,11 +102,11 @@ set_var EASYRSA_DN "cn_only"
102102
# * rsa
103103
# * ec
104104

105-
set_var EASYRSA_ALGO rsa
105+
set_var EASYRSA_ALGO ec
106106

107107
# Define the named curve, used in ec mode only:
108108

109-
set_var EASYRSA_CURVE {{ easyrsa_curve }}
109+
set_var EASYRSA_CURVE prime256v1
110110

111111
# In how many days should the root CA key expire?
112112

templates/ipsec.secrets.j2

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,2 @@
1-
: RSA {{ server_name }}.key
1+
: ECDSA {{ server_name }}.key
22

templates/mobileconfig.j2

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -45,6 +45,10 @@
4545
<string>{{ item.0 }}</string>
4646
<key>PayloadCertificateUUID</key>
4747
<string>1FB2907D-14D3-4BAB-A472-B304F4B7F7D9</string>
48+
<key>CertificateType</key>
49+
<string>ECDSA256</string>
50+
<key>ServerCertificateIssuerCommonName</key>
51+
<string>www.ivlis.me</string>
4852
<key>RemoteAddress</key>
4953
<string>{{ server_name }}</string>
5054
<key>RemoteIdentifier</key>

0 commit comments

Comments
 (0)