setup-vpn-client.sh 896 Bytes
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
#!/bin/sh

##
## Setup an OpenVPN client for the management network.  Just saves
## a couple SSH connections from the server driving the setup.
##

set -x

# Gotta know the rules!
if [ $EUID -ne 0 ] ; then
    echo "This script must be run as root" 1>&2
    exit 1
fi

# Grab our libs
. "`dirname $0`/setup-lib.sh"

19
maybe_install_packages openvpn
20 21 22 23

cp -p $OURDIR/$HOSTNAME.crt $OURDIR/$HOSTNAME.key /etc/openvpn/
cp -p $OURDIR/ca.crt /etc/openvpn

David Johnson's avatar
David Johnson committed
24 25
nmfqdn=`getfqdn $NETWORKMANAGER`

26 27 28 29
cat <<EOF > /etc/openvpn/server.conf
client
dev tun
proto udp
David Johnson's avatar
David Johnson committed
30
remote $nmfqdn 1194
31 32 33 34 35 36 37 38 39 40 41 42
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert $HOSTNAME.crt
key $HOSTNAME.key
ns-cert-type server
comp-lzo
verb 3
EOF

David Johnson's avatar
David Johnson committed
43 44 45 46 47 48 49 50 51
#
# Get the server up
#
if [ ${HAVE_SYSTEMD} -eq 1 ]; then
    systemctl enable openvpn@server.service
    systemctl restart openvpn@server.service
else
    service openvpn restart
fi
52 53

exit 0