
| Current Path : /var/mail/etc/o1/client/files/ |
Linux ift1.ift-informatik.de 5.4.0-216-generic #236-Ubuntu SMP Fri Apr 11 19:53:21 UTC 2025 x86_64 |
| Current File : /var/mail/etc/o1/client/files/vgabriel51.ovpn |
# Specify that we are a client and that we
# will be pulling certain config file directives
# from the server.
client
# Use the same setting as you are using on
# the server.
# On most systems, the VPN will not function
# unless you partially or fully disable
# the firewall for the TUN/TAP interface.
dev tap
;dev tun
# Windows needs the TAP-Win32 adapter name
# from the Network Connections panel
# if you have more than one. On XP SP2,
# you may need to disable the firewall
# for the TAP adapter.
;dev-node MyTap
# Are we connecting to a TCP or
# UDP server? Use the same setting as
# on the server.
;proto tcp
proto udp
# The hostname/IP and port of the server.
# You can have multiple remote entries
# to load balance between the servers.
remote ift-intern.de 1194
;remote my-server-2 1194
# Keep trying indefinitely to resolve the
# host name of the OpenVPN server. Very useful
# on machines which are not permanently connected
# to the internet such as laptops.
resolv-retry infinite
# Most clients don't need to bind to
# a specific local port number.
nobind
# Downgrade privileges after initialization (non-Windows only)
;user nobody
;group nogroup
# Try to preserve some state across restarts.
persist-key
persist-tun
# If you are connecting through an
# HTTP proxy to reach the actual OpenVPN
# server, put the proxy server/IP and
# port number here. See the man page
# if your proxy server requires
# authentication.
;http-proxy-retry # retry on connection failures
;http-proxy [proxy server] [proxy port #]
# Wireless networks often produce a lot
# of duplicate packets. Set this flag
# to silence duplicate packet warnings.
;mute-replay-warnings
# SSL/TLS parms.
# See the server config file for more
# description. It's best to use
# a separate .crt/.key file pair
# for each client. A single ca
# file can be used for all clients.
# ca ca.crt
# cert client.crt
# key client.key
# Verify server certificate by checking
# that the certicate has the nsCertType
# field set to "server". This is an
# important precaution to protect against
# a potential attack discussed here:
# http://openvpn.net/howto.html#mitm
#
# To use this feature, you will need to generate
# your server certificates with the nsCertType
# field set to "server". The build-key-server
# script in the easy-rsa folder will do this.
ns-cert-type server
# If a tls-auth key is used on the server
# then every client must also have the key.
tls-auth ta.key 1
key-direction 1
# Select a cryptographic cipher.
# If the cipher option is used on the server
# then you must also specify it here.
cipher AES-128-CBC
auth SHA256
# Enable compression on the VPN link.
# Don't enable this unless it is also
# enabled in the server config file.
comp-lzo
# Set log file verbosity.
verb 3
# Silence repeating messages
;mute 20
route-method exe
route-delay 2
pull
<ca>
-----BEGIN CERTIFICATE-----
MIIDijCCAvOgAwIBAgIJAK32CLIc/KJkMA0GCSqGSIb3DQEBBQUAMIGLMQswCQYD
VQQGEwJERTEPMA0GA1UECBMGQmF5ZXJuMQ8wDQYDVQQHEwZGdWVydGgxDzANBgNV
BAoTBklmVDAwMTESMBAGA1UEAxMJSWZUMDAxIENBMQ8wDQYDVQQpEwZzZXJ2ZXIx
JDAiBgkqhkiG9w0BCQEWFWlmdEBpZnQtaW5mb3JtYXRpay5kZTAeFw0xNzA3MTcw
OTUwMzJaFw0yNzA3MTUwOTUwMzJaMIGLMQswCQYDVQQGEwJERTEPMA0GA1UECBMG
QmF5ZXJuMQ8wDQYDVQQHEwZGdWVydGgxDzANBgNVBAoTBklmVDAwMTESMBAGA1UE
AxMJSWZUMDAxIENBMQ8wDQYDVQQpEwZzZXJ2ZXIxJDAiBgkqhkiG9w0BCQEWFWlm
dEBpZnQtaW5mb3JtYXRpay5kZTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
7Y/24TI5tcSY7bB2Z+sXBcQ36cS0F+Pyw2rgKcK1kF977TmyF40nQsMiAmhZ37nt
GXu+ESbzJ8qRTBlrJ8NcgY1zq9hsGr/1lyyWr6P6NtwOhoSVz+FHd92i3s5bzNSR
LlQlcW1WI9TD7qpyKu2f68fCoTPZCdzq1916X/OUoP0CAwEAAaOB8zCB8DAdBgNV
HQ4EFgQUKfH155Z3fATGDxqf41TWg8PmPz0wgcAGA1UdIwSBuDCBtYAUKfH155Z3
fATGDxqf41TWg8PmPz2hgZGkgY4wgYsxCzAJBgNVBAYTAkRFMQ8wDQYDVQQIEwZC
YXllcm4xDzANBgNVBAcTBkZ1ZXJ0aDEPMA0GA1UEChMGSWZUMDAxMRIwEAYDVQQD
EwlJZlQwMDEgQ0ExDzANBgNVBCkTBnNlcnZlcjEkMCIGCSqGSIb3DQEJARYVaWZ0
QGlmdC1pbmZvcm1hdGlrLmRlggkArfYIshz8omQwDAYDVR0TBAUwAwEB/zANBgkq
hkiG9w0BAQUFAAOBgQCfDJpAncCsf+1tfbwVKlxbCEgKkW9baHiO1w4gI70PcIFz
ooRcS7E7BFGgRWiQmh58f/g1DnPxYX302GTC14XToA1Ri9uKFac+9hOCx9EUvAN7
3vzuKZRc5NITKyjHhZkavn+IfSCr7jc+aoBka+QMFILKgvNwnUZm0xhveruUqQ==
-----END CERTIFICATE-----
</ca>
<cert>
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 49 (0x31)
Signature Algorithm: sha1WithRSAEncryption
Issuer: C=DE, ST=Bayern, L=Fuerth, O=IfT001, CN=IfT001 CA/name=server/emailAddress=ift@ift-informatik.de
Validity
Not Before: Apr 19 08:35:54 2020 GMT
Not After : Apr 17 08:35:54 2030 GMT
Subject: C=DE, ST=Bayern, L=Fuerth, O=IfT001, CN=vgabriel51/name=vgabriel/emailAddress=vgabriel@ift-informatik.de
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (1024 bit)
Modulus:
00:fa:ce:2d:88:fb:b7:2b:af:1a:1e:a8:52:1a:95:
1a:3c:f7:12:73:0a:7d:c2:0d:24:ef:8b:75:1d:87:
52:d4:54:4e:5d:55:b8:61:6c:87:9d:f7:27:c1:bd:
05:5b:7e:d5:1f:fe:fe:d0:c6:bb:68:5a:7b:41:3c:
77:cc:c8:ff:2a:f4:3a:fd:7f:10:8e:3f:bc:61:4a:
b7:23:bb:3f:18:0f:ba:8b:e6:03:dd:14:7a:35:d5:
6d:0d:c9:88:2a:eb:c5:a8:80:e7:94:8f:94:76:e0:
af:0f:ec:e2:bb:dd:49:e4:f7:b2:ac:86:52:b9:69:
84:c2:9b:f3:c3:e6:88:a8:9d
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints:
CA:FALSE
Netscape Comment:
Easy-RSA Generated Certificate
X509v3 Subject Key Identifier:
A1:EB:86:33:7C:38:2D:0A:57:A9:30:2A:8D:09:3E:EA:BB:E1:3C:AC
X509v3 Authority Key Identifier:
keyid:29:F1:F5:E7:96:77:7C:04:C6:0F:1A:9F:E3:54:D6:83:C3:E6:3F:3D
DirName:/C=DE/ST=Bayern/L=Fuerth/O=IfT001/CN=IfT001 CA/name=server/emailAddress=ift@ift-informatik.de
serial:AD:F6:08:B2:1C:FC:A2:64
X509v3 Extended Key Usage:
TLS Web Client Authentication
X509v3 Key Usage:
Digital Signature
Signature Algorithm: sha1WithRSAEncryption
2d:82:4d:82:dc:d5:cf:76:ad:b4:af:70:e9:3a:e7:0f:d9:e6:
f3:e2:0d:3e:27:69:37:d7:35:73:04:b4:3f:01:dd:b4:ec:10:
72:5e:69:cb:a8:da:7d:bd:4e:35:72:86:6b:a7:19:70:3d:9f:
86:a9:23:aa:fd:0f:ba:f4:40:b5:91:27:b2:f9:0d:b1:e1:47:
77:47:98:4e:14:a8:c1:d2:97:a7:3f:b2:01:dd:55:13:a0:09:
bf:56:ba:25:b6:30:74:bb:5e:e6:77:c8:be:e9:f4:5b:cf:f4:
e3:5e:42:35:6f:97:f7:b5:5b:dd:4a:d4:f0:c0:2f:4f:d6:1c:
60:9b
-----BEGIN CERTIFICATE-----
MIID2jCCA0OgAwIBAgIBMTANBgkqhkiG9w0BAQUFADCBizELMAkGA1UEBhMCREUx
DzANBgNVBAgTBkJheWVybjEPMA0GA1UEBxMGRnVlcnRoMQ8wDQYDVQQKEwZJZlQw
MDExEjAQBgNVBAMTCUlmVDAwMSBDQTEPMA0GA1UEKRMGc2VydmVyMSQwIgYJKoZI
hvcNAQkBFhVpZnRAaWZ0LWluZm9ybWF0aWsuZGUwHhcNMjAwNDE5MDgzNTU0WhcN
MzAwNDE3MDgzNTU0WjCBkzELMAkGA1UEBhMCREUxDzANBgNVBAgTBkJheWVybjEP
MA0GA1UEBxMGRnVlcnRoMQ8wDQYDVQQKEwZJZlQwMDExEzARBgNVBAMTCnZnYWJy
aWVsNTExETAPBgNVBCkTCHZnYWJyaWVsMSkwJwYJKoZIhvcNAQkBFhp2Z2Ficmll
bEBpZnQtaW5mb3JtYXRpay5kZTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA
+s4tiPu3K68aHqhSGpUaPPcScwp9wg0k74t1HYdS1FROXVW4YWyHnfcnwb0FW37V
H/7+0Ma7aFp7QTx3zMj/KvQ6/X8Qjj+8YUq3I7s/GA+6i+YD3RR6NdVtDcmIKuvF
qIDnlI+UduCvD+ziu91J5PeyrIZSuWmEwpvzw+aIqJ0CAwEAAaOCAUIwggE+MAkG
A1UdEwQCMAAwLQYJYIZIAYb4QgENBCAWHkVhc3ktUlNBIEdlbmVyYXRlZCBDZXJ0
aWZpY2F0ZTAdBgNVHQ4EFgQUoeuGM3w4LQpXqTAqjQk+6rvhPKwwgcAGA1UdIwSB
uDCBtYAUKfH155Z3fATGDxqf41TWg8PmPz2hgZGkgY4wgYsxCzAJBgNVBAYTAkRF
MQ8wDQYDVQQIEwZCYXllcm4xDzANBgNVBAcTBkZ1ZXJ0aDEPMA0GA1UEChMGSWZU
MDAxMRIwEAYDVQQDEwlJZlQwMDEgQ0ExDzANBgNVBCkTBnNlcnZlcjEkMCIGCSqG
SIb3DQEJARYVaWZ0QGlmdC1pbmZvcm1hdGlrLmRlggkArfYIshz8omQwEwYDVR0l
BAwwCgYIKwYBBQUHAwIwCwYDVR0PBAQDAgeAMA0GCSqGSIb3DQEBBQUAA4GBAC2C
TYLc1c92rbSvcOk65w/Z5vPiDT4naTfXNXMEtD8B3bTsEHJeacuo2n29TjVyhmun
GXA9n4apI6r9D7r0QLWRJ7L5DbHhR3dHmE4UqMHSl6c/sgHdVROgCb9WuiW2MHS7
XuZ3yL7p9FvP9ONeQjVvl/e1W91K1PDAL0/WHGCb
-----END CERTIFICATE-----
</cert>
<key>
-----BEGIN PRIVATE KEY-----
MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBAPrOLYj7tyuvGh6o
UhqVGjz3EnMKfcINJO+LdR2HUtRUTl1VuGFsh533J8G9BVt+1R/+/tDGu2hae0E8
d8zI/yr0Ov1/EI4/vGFKtyO7PxgPuovmA90UejXVbQ3JiCrrxaiA55SPlHbgrw/s
4rvdSeT3sqyGUrlphMKb88PmiKidAgMBAAECgYAqKkOJhhgTZgrUIKQ9B9gza65U
XO0rlJ4jD6UO49NPEyVhl6m5508dhZHPhoHCEh6ulGYun1qefqe+HfZeHWSYdOeK
kL1fAb7GDjy9pLhnwOHhBXlzZJq2PCSdYzdAeByrEgygEtjCx2yWs9MzvgCxWbbt
T7nako7x83BNvXi02QJBAP5i3jUdasmChTl7ML9hjecdefYPrB5TzXQfAaRW4YCm
fjS0ZJ/hyBwXg40DQZj3B2bV6gCENuIkFyXfFuVB4rMCQQD8ZX6XUqOZOPs5jRZn
8721tAc3yNySYLUUy+XD9rI4xNkBh9oG0gMDP1iw3xHGkT4SyMz2j5VW3/AKi2ya
ha9vAkBr3GfzhYGd56Wtdbp5q1eLw0fPOV31jfrzXaJImD4NWorwtfxkfktm/eFd
jR/nR/bvd4w8o9LRmBPojusaUhFZAkEAzv+afBbNj9uYxtF8f9L6UuyMQuccZ3yi
5qR3E2nfLwnahBPb714MFHy+i4jXdkgmZZeD6e9GZpKQtsU0U+KyRwJBALkqXPSK
P7JbEXnqJKaU1LyVns2qUONdIHN7D+Hga8MxWjoUK9iCXDyXq6q/N8fEKnip3sfi
CWODCr5eRp2oj2Y=
-----END PRIVATE KEY-----
</key>
<tls-auth>
#
# 2048 bit OpenVPN static key
#
-----BEGIN OpenVPN Static key V1-----
2bd62930e4ffd4a1279da017f01ffbba
58f3645b4226e1851cae3f4d44e807e9
36ff6f397dcd450dc04c19a6f5d41975
5d402bcba8af7f84d1b65507336ce17d
41aad424a335a7a517f325cfc57f150e
63b177420a2a654818e2cff582a6764d
ebfb48bf0cd40eeaf278bcd8f00e3956
95ce6f9b369f54c6cc596764253c62f6
7c95830bbc62b6067fa49aeab348dcf6
9d74d36194f78379875c7ad7ccc88776
18891b9b69ed864c01c61ed874a121b6
1475a905f635809f7cf07234397034e0
f53666ac55c071153698d2c765b1dbf1
7ac21d37526b55a6fdba6f79e2554f0f
d2bb7674471b08c5e63c948b7e773c14
417093119c5ef39d9cef728143e44093
-----END OpenVPN Static key V1-----
</tls-auth>