RHEL5.4 上部署openvpn 服务(3)
来源:未知 责任编辑:责任编辑 发表时间:2014-01-06 18:19 点击:次
For some fields there will be a default value,
If you enter '.', the field will be left blank.
Country Name (2 letter code) [CN]:
State or Province Name (full name) [SHANGHAI]:
Locality Name (eg, city) [SHANGHAI]:
Organization Name (eg, company) [Frank]:
Organizational Unit Name (eg, section) []:Frank
Common Name (eg, your name or your server's hostname) [frank]:
Name []:frank
Email Address [623195090@qq.com]:
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:
An optional company name []:
Using configuration from /root/openvpn/openvpn-2.1.4/easy-rsa/2.0/openssl.cnf
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
countryName :PRINTABLE:'CN'
stateOrProvinceName :PRINTABLE:'SHANGHAI'
organizationName :PRINTABLE:'Frank'
commonName :PRINTABLE:'frank'
name :PRINTABLE:'frank'
emailAddress :IA5STRING:'623195090@qq.com'
Certificate is to be certified until Aug 9 18:45:05 2021 GMT (3650 days)
Sign the certificate? [y/n]:y
1 out of 1 certificate requests certified, commit? [y/n]
6 创建Dffie Hellman 参数.DiffieHellman 用于增强安全性,在OpenVPN 是必须的,在OpenVPN的主配置文件中,tls-auth指令可以为SSL/TLS协议的handshake 数据包添加HMAC 签名,任何未经过签名验证的UDP包都会被丢弃,这就是SSL/TLS的安全提升了一个级别.他可以为Openvpn 的UDP 提供防止Dos 或端口洪泛攻击,避开对Openvpn 监听端口的扫描及防止缓冲区溢出等
[root@openvpn 2.0]# ./build-dh
Generating DH parameters, 1024 bit long safe prime, generator 2
This is going to take a long time
- 发表评论
- 最新评论 更多>>