Date: Mon, 16 Nov 2015 17:00:58 -0500 From: Jon Radel <jon@radel.com> To: Dave B <g8kbvdave@gmail.com>, freebsd-questions@freebsd.org Subject: Re: Help/advice request please. Message-ID: <564A521A.90406@radel.com> In-Reply-To: <EB867E94-B658-4E58-91D2-6093888F4EB8@gmail.com> References: <564A4CE3.9663.851BBC@g8kbvdave.googlemail.com> <EB867E94-B658-4E58-91D2-6093888F4EB8@gmail.com>
index | next in thread | previous in thread | raw e-mail
[-- Attachment #1 --] On 11/16/15 4:45 PM, Manas wrote: > Hello Dave, > > I run a few openvpn servers on FreeBSD. I use https://openvpn.net/index.php/open-source/documentation/howto.html as my guide. Feel free to email me directly with any questions. > I was just looking at that one, not having setup OpenVPN from scratch in a while now. Looks perfectly reasonable. > > But there is no guidance as to what the other field values should (or > should > not) be. Such as region/state etc. Ooooo, nobody's let you in on the secret. :-( Those don't matter. Make them whatever makes you happy, and that includes empty. In a private CA world really the only field you have to worry about is the Common Name. It's nice to set the other values to something sensible, particularly if you're doing a private PKI for a large firm, where it's handy to track contact information, etc., etc., as part of the certificate, but that's all to keep the humans from getting confused. Now, if you're getting your certs from another party, they'll want you to either put in real values or leave the values blank, depending on what they're certifying by signing your certificate, but that's out of your scope. --Jon Radel jon@radel.com [-- Attachment #2 --] 0 *H 010 `He 0 *H 00 #SanzTgk!0 *H 0o10 USE10U AddTrust AB1&0$UAddTrust External TTP Network1"0 UAddTrust External CA Root0 141222000000Z 200530104838Z010 UGB10UGreater Manchester10USalford10U COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CA0"0 *H 0 zSNpRV&IQZI`zQBy"aNv# J n=ٺ.CRC|2PȦOZϓ%{0dV*$3DiFK3@@:*S= a<UNv%!)|qvO_T{5R"=,0-1YR73i-C֥wgQ'뼥8v8ߌIs:2:=F:WtaP@?⟢! 00U#0z4&&T$T0UakᢠOg£ 0U0U0 0U%0++0U 00U 0DU=0;09753http://crl.usertrust.com/AddTrustExternalCARoot.crl05+)0'0%+0http://ocsp.usertrust.com0 *H *nU:Uka+ #fjow^a } [jr AX&MX"cR6}Xޫ;cs{B#ʶM>K-ػBKiۦ74{:ǟO4ne6d)5ֱqC>2Svʆ4,Jؙ ␒ZBj#!eջ~ꌅ b:,Yř38zyJ&|00sT<}k `i 0 *H 010 UGB10UGreater Manchester10USalford10U COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CA0 150330000000Z 180329235959Z010 UUS10U2215010 UVA10USpringfield10U 6917 Ridgeway Dr.10U Jon T. Radel1200U)Issued through Jon T. Radel E-PKI Manager10UCorporate Secure Email10U Jon Radel10 *H jon@radel.com0"0 *H 0 aЩ@@g3eGރ͛; d#>q7&Hf :3vL"jV#Xݷ>U-H[$SUڻ{Ϝ,z¶IchO=rcyrn v.Vh7k;%ueYuӬnz6!| !Aȡ+,u+ CAպF-un#vjUJWnk%j] 2JPkl 00U#0akᢠOg£ 0UE|GDp/ʚB0U0U0 0U%0++0FU ?0=0;+10+0)+https://secure.comodo.net/CPS0]UV0T0RPNLhttp://crl.comodoca.com/COMODOSHA256ClientAuthenticationandSecureEmailCA.crl0+00X+0Lhttp://crt.comodoca.com/COMODOSHA256ClientAuthenticationandSecureEmailCA.crt0$+0http://ocsp.comodoca.com0U0 jon@radel.com0 *H KS `?H_D`8G߿VbĘ<tB-Ӈї|{'Ũݹg0Gp$%F(;*MO*gt$@ t6,?0|#ăz,&! {j2i[%b7ߪP+9G㲍["y<?8rZ'[UR6%L̤ w"=:L~Ƨ^jf36 OP1.}(e1A0=0010 UGB10UGreater Manchester10USalford10U COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k `i 0 `He a0 *H 1 *H 0 *H 1 151116220058Z0/ *H 1" 0ģJ;dv}'?ĥr f0l *H 1_0]0 `He*0 `He0 *H 0*H 0 *H @0+0 *H (0 +710010 UGB10UGreater Manchester10USalford10U COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k `i 0*H 1010 UGB10UGreater Manchester10USalford10U COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k `i 0 *H *πyK^ȉ`>7~K"6n_1%~%X)Lg$ַ>*\23?ǞG֭e A%Pai*yl{gK\0֣}wC+Wtt!?{+{G-(u1,, <?aߌ1SWԥ|=[{G7KhXf!/pg|ƕ:34mqJkidthome | help
Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?564A521A.90406>
