centos7安装openv皮n

作者:小小傻瓜牙能上网的机器

我的centos7的ip 是192.168.10.88

 

先看看服务器时间,不能比现实的时间快

yum -y install epel-release 安装epel扩展源 (不行就reboot一下)

 

安装openvpn和easy-rsa

1 yum -y install openvpn easy-rsa

 

 

 

复制easy-rsa文件

 1 [root@server ~]# cp -r /usr/share/easy-rsa/ /etc/openvpn/easy-rsa
 2 
 3 [root@server ~]# cd /etc/openvpn/easy-rsa/
 4 
 5 [root@server easy-rsa]# ls
 6 
 7 3 3.0 3.0.6
 8 
 9 [root@server easy-rsa]# \rm 3 3.0
10 
11 [root@server easy-rsa]# ls
12 
13 3.0.3
14 
15 [root@server easy-rsa]# cd 3.0.6/
16 
17 [root@server 3.0.6]# find / -type f -name "vars.example" | xargs -i cp {} . && mv vars.example vars

 

1 [root@server 3.0.6]# ls
2 
3 easyrsa openssl-1.0.cnf vars x509-types

 

 

 

生成CA证书

创建一个新的 PKI 和 CA

1 [root@server 3.0.6]# ./easyrsa init-pki

 

 

Note: using Easy-RSA configuration from: ./vars

 

init-pki complete; you may now create a CA or requests.

Your newly created PKI dir is: /etc/openvpn/easy-rsa/3.0.6/pki

 

创建新的CA,不使用密码

1 [root@server 3.0.6]# ./easyrsa build-ca nopass

 

 

Note: using Easy-RSA configuration from: ./vars

Generating a 2048 bit RSA private key

.......................+++

...........+++

writing new private key to '/etc/openvpn/easy-rsa/3.0.6/pki/private/ca.key.KPmAlNfnU3'

-----

You are about to be asked to enter information that will be incorporated

into your certificate request.

What you are about to enter is what is called a Distinguished Name or a DN.

There are quite a few fields but you can leave some blank

For some fields there will be a default value,

If you enter '.', the field will be left blank.

-----

Common Name (eg: your user, host, or server name) [Easy-RSA CA]:回车

 

CA creation complete and you may now import and sign cert requests.

Your new CA certificate file for publishing is at:

/etc/openvpn/easy-rsa/3.0.6/pki/ca.crt

 

创建服务端证书

1 [root@server 3.0.6]# ./easyrsa gen-req server nopass

 

 

Note: using Easy-RSA configuration from: ./vars

Generating a 2048 bit RSA private key

...........................................+++

................................................................................................................................................................................+++

writing new private key to '/etc/openvpn/easy-rsa/3.0.6/pki/private/server.key.NH1k6T6KaF'

-----

You are about to be asked to enter information that will be incorporated

into your certificate request.

What you are about to enter is what is called a Distinguished Name or a DN.

There are quite a few fields but you can leave some blank

For some fields there will be a default value,

If you enter '.', the field will be left blank.

-----

Common Name (eg: your user, host, or server name) [server]:回车

 

Keypair and certificate request completed. Your files are:

req: /etc/openvpn/easy-rsa/3.0.6/pki/reqs/server.req

key: /etc/openvpn/easy-rsa/3.0.6/pki/private/server.key

 

 

 

 

 

签约服务端证书

1 [root@server 3.0.6]# ./easyrsa sign server server

 

 

Note: using Easy-RSA configuration from: ./vars

 

 

You are about to sign the following certificate.

Please check over the details shown below for accuracy. Note that this request

has not been cryptographically verified. Please be sure it came from a trusted

source or that you have verified the request checksum with the sender.

 

Request subject, to be signed as a server certificate for 3650 days:

 

subject=

commonName = server

 

 

Type the word 'yes' to continue, or any other input to abort.

Confirm request details: yes

Using configuration from ./openssl-1.0.cnf

Check that the request matches the signature

Signature ok

The Subject's Distinguished Name is as follows

commonName :ASN.1 12:'server'

Certificate is to be certified until Apr 16 16:35:35 2029 GMT (3650 days)

 

Write out database with 1 new entries

Data Base Updated

 

Certificate created at: /etc/openvpn/easy-rsa/3.0.6/pki/issued/server.crt

 

 

创建Diffie-Hellman,确保key穿越不安全网络的命令,回车后,等的时间稍微长一点

 

1 [root@server 3.0.6]# ./easyrsa gen-dh

 

 

............................++*++*

 

DH parameters of size 2048 created at /etc/openvpn/easy-rsa/3.0.6/pki/dh.pem

生成ta密钥文件

 

1 openvpn --genkey --secret /etc/openvpn/easy-rsa/ta.key

 

不执行此命令,会报错

 

 

 

整理证书

 1 [root@server 3.0.6]# cd /etc/openvpn
 2 
 3 [root@server openvpn]# cp easy-rsa/3.0.6/pki/dh.pem .
 4 
 5 [root@server openvpn]# cp easy-rsa/3.0.6/pki/ca.crt .
 6 
 7 [root@server openvpn]# cp easy-rsa/3.0.6/pki/issued/server.crt .
 8 
 9 [root@server openvpn]# cp easy-rsa/3.0.6/pki/private/server.key .
10 
11 [root@server openvpn]# cp easy-rsa/ta.key .
12 
13 [root@server openvpn]# ll
16 
17 -rw------- 1 root root 1172 Apr 20 00:41 ca.crt
18 
19 drwxr-x--- 2 root openvpn 6 Feb 20 23:23 client
20 
21 -rw------- 1 root root 424 Apr 20 00:41 dh.pem
22 
23 drwxr-xr-x 3 root root 33 Apr 20 00:39 easy-rsa
24 
25 drwxr-x--- 2 root openvpn 6 Feb 20 23:23 server
26 
27 -rw------- 1 root root 4552 Apr 20 00:41 server.crt
28 
29 -rw------- 1 root root 1704 Apr 20 00:42 server.key
30 
31 -rw------- 1 root root 636 Apr 20 00:42 ta.key

 

 

 

 

创建客户端证书

复制文件

1 [root@server ~]# cp -r /usr/share/easy-rsa/ /etc/openvpn/client
2 
3 [root@server ~]# cd /etc/openvpn/client/easy-rsa/
4 
5 [root@server easy-rsa]# \rm 3 3.0
6 
7 [root@server easy-rsa]# cd 3.0.6/
8 
9 [root@server 3.0.6]# find / -type f -name "vars.example" | xargs -i cp {} . && mv vars.example vars

 

 

 

生成客户端证书

1 [root@server 3.0.6]# pwd
2 
3 /etc/openvpn/client/easy-rsa/3.0.6
4 
5 [root@server 3.0.6]# ./easyrsa init-pki 创建新的pki

 

 

Note: using Easy-RSA configuration from: ./vars

 

init-pki complete; you may now create a CA or requests.

Your newly created PKI dir is: /etc/openvpn/client/easy-rsa/3.0.6/pki

 

 

 

1 [root@server 3.0.6]# ./easyrsa gen-req client nopass 客户证书名,无密码

 

 

Note: using Easy-RSA configuration from: ./vars

Generating a 2048 bit RSA private key

............................................+++

.....................+++

writing new private key to '/etc/openvpn/client/easy-rsa/3.0.6/pki/private/client.key.FO8om8Ji9T'

-----

You are about to be asked to enter information that will be incorporated

into your certificate request.

What you are about to enter is what is called a Distinguished Name or a DN.

There are quite a few fields but you can leave some blank

For some fields there will be a default value,

If you enter '.', the field will be left blank.

-----

Common Name (eg: your user, host, or server name) [client]:回车

 

Keypair and certificate request completed. Your files are:

req: /etc/openvpn/client/easy-rsa/3.0.6/pki/reqs/client.req

key: /etc/openvpn/client/easy-rsa/3.0.6/pki/private/client.key

 

 

签约客户端证书

1 [root@server 3.0.6]# cd /etc/openvpn/easy-rsa/3.0.6/
2 
3 [root@server 3.0.6]# pwd
4 
5 /etc/openvpn/easy-rsa/3.0.6
6 
7 [root@server 3.0.6]# ./easyrsa import-req /etc/openvpn/client/easy-rsa/3.0.6/pki/reqs/client.req client

 

 

Note: using Easy-RSA configuration from: ./vars

 

The request has been successfully imported with a short name of: client

You may now use this name to perform signing operations on this request.

 

[root@server 3.0.6]# ./easyrsa sign client client

 

Note: using Easy-RSA configuration from: ./vars

 

 

You are about to sign the following certificate.

Please check over the details shown below for accuracy. Note that this request

has not been cryptographically verified. Please be sure it came from a trusted

source or that you have verified the request checksum with the sender.

 

Request subject, to be signed as a client certificate for 3650 days:

 

subject=

commonName = client

 

 

Type the word 'yes' to continue, or any other input to abort.

Confirm request details: yes

Using configuration from ./openssl-1.0.cnf

Check that the request matches the signature

Signature ok

The Subject's Distinguished Name is as follows

commonName :ASN.1 12:'client'

Certificate is to be certified until Apr 16 16:50:25 2029 GMT (3650 days)

 

Write out database with 1 new entries

Data Base Updated

 

Certificate created at: /etc/openvpn/easy-rsa/3.0.6/pki/issued/client.crt

 

 

 

 

 

整理证书

 1 [root@server 3.0.6]# cd /etc/openvpn/client
 2 
 3 [root@server client]# ls
 4 
 5 easy-rsa
 6 
 7 [root@server client]# cp /etc/openvpn/easy-rsa/3.0.6/pki/ca.crt .
 8 
 9 [root@serverclient]# cp /etc/openvpn/easy-rsa/3.0.6/pki/issued/client.crt .
10 
11 [root@serverclient]# cp /etc/openvpn/client/easy-rsa/3.0.6/pki/private/client.key .
12 
13 [root@server client]# cp /etc/openvpn/easy-rsa/ta.key .

 

 

配置文件

 1 [root@server client]# cd /etc/openvpn/
 2 
 3 [root@server openvpn]# vim server.conf (内容如下)
 4 
 5 port 11194
 7 proto tcp
 9 dev tun
11 ca /etc/openvpn/ca.crt
13 cert /etc/openvpn/server.crt
15 key /etc/openvpn/server.key
17 dh /etc/openvpn/dh.pem
19 server 10.8.0.0 255.255.255.0
21 ifconfig-pool-persist ipp.txt
23 push "route 192.168.10.0 255.255.255.0"
25 push "route 192.168.20.0 255.255.255.0"
27 push "route 127.11.170.0 255.255.255.0"
29 push "route 10.8.0.0 255.255.255.0"
31 push "dhcp-option DNS 8.8.8.8"
33 push "dhcp-option DNS 8.8.4.4"
35 keepalive 10 120
37 tls-auth /etc/openvpn/ta.key 0 #服务器是0,客户端是1
39 client-to-client
41 comp-lzo
43 user nobody
45 group nobody
47 persist-key
49 persist-tun
51 status openvpn-status.log
53 verb 3

 

 

 

 

 

 

开启转发

说的是centos7的/etc/sysctl.conf不能用

要用/usr/lib/sysctl.d/50-default.conf

我是两个都写了(云服务器我只写了第一个)

[root@server ~]# vim /etc/sysctl.conf

加一行 net.ipv4.ip_forward = 1

vim /usr/lib/sysctl.d/50-default.conf

net.ipv4.ip_forward = 1

[root@server ~]# sysctl -p

net.ipv4.ip_forward = 1

 

 

开机启动VPN

在centos7中,/etc/rc.d/rc.local的权限被降低了,赋予其可执行权限,建议777

[root@server ~]# chmod 777 /etc/rc.d/rc.local

vim /etc/rc.d/rc.local

加入

openvpn /etc/openvpn/server.conf &

 

 

 

 

客户端(我是桥接模式)如果不能上网 这包很难按

 

安装 epel yum 源

rpm -ivh http://mirrors.sohu.com/fedora-epel/6/x86_64/epel-release-6-8.noarch.rpm

 

 

yum 安装 openvpn

yum -y install openvpn

 

把服务器上创建的客户端证书文件上传到客户机的/etc/openvpn/里

ca.crt client.crt client.key ta.key

 

创建文件

 1 cd /etc/openvpn/
 2 
 3 vim client.conf
 4 
 5 内容如下
 6 
 7 client
 9 dev tun 
11 proto tcp 
13 remote 域名IP地址指向的ip:诊断域名后的端口 
15 resolv-retry infinite
17 nobind
19 user nobody
21 group nobody
23 persist-key
25 persist-tun
27 ca /etc/openvpn/ca.crt
29 cert /etc/openvpn/client.crt 
31 key /etc/openvpn/client.key 
33 remote-cert-tls server
35 tls-auth /etc/openvpn/ta.key 1 #(服务器0 客户机1)
37 comp-lzo
39 verb 3

 

 

 

 

 

 

启动VPN如果是

openvpn /etc/openvpn/client.conf &

 

最后可以将上述命令加到/etc/rc.d/rc.local里开机启动

 

在centos7中,/etc/rc.d/rc.local文件的权限被降低了,没有执行权限,需要给它添加可执行权限(最好777)。

chmod 777 /etc/rc.d/rc.local

然后就可以在里面添加你要开机自启的命令了

openvpn /etc/openvpn/client.conf &

posted @ 2020-01-13 09:41  小小傻瓜牙  阅读(435)  评论(0)    收藏  举报