From 368de14fc1e64422667f42598897473632f805a4 Mon Sep 17 00:00:00 2001 From: Richard T Bonhomme Date: Tue, 25 Oct 2022 20:51:51 +0100 Subject: [PATCH] vars.example: Remove EASYRSA_REQ_CN and EASYRSA_TEMP_FILE Squashed commit of the following: commit c27825c3bc5dddaeb3749d7a315a77239146ad22 Merge: 02f13f6 93da550 Author: Richard T Bonhomme Date: Tue Oct 25 20:50:44 2022 +0100 Merge branch 'vars-remove-req-cn' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-vars-remove-req-cn Signed-off-by: Richard T Bonhomme commit 93da55003cee29695616d01243aecddcf7954c25 Author: Richard T Bonhomme Date: Fri Oct 21 21:10:08 2022 +0100 vars.example: Minor corrections and formatting Signed-off-by: Richard T Bonhomme commit 9976f3f0d13a73827052f490438b95153a1b7576 Author: Richard T Bonhomme Date: Fri Oct 21 20:57:07 2022 +0100 vars.example: Remove EASYRSA_TEMP_FILE Closes: #729 Signed-off-by: Richard T Bonhomme commit 8a35375f84ab88b6f009e5971ddb7358f6619a03 Author: Richard T Bonhomme Date: Fri Oct 21 20:44:53 2022 +0100 vars.example: Remove EASYRSA_REQ_CN Closes: #730 Signed-off-by: Richard T Bonhomme Signed-off-by: Richard T Bonhomme --- easyrsa3/vars.example | 69 ++++++++++++++++--------------------------- 1 file changed, 26 insertions(+), 43 deletions(-) diff --git a/easyrsa3/vars.example b/easyrsa3/vars.example index ff8af7c..e5407cb 100644 --- a/easyrsa3/vars.example +++ b/easyrsa3/vars.example @@ -46,7 +46,7 @@ fi # The default value of this variable is the location of the easyrsa script # itself, which is also where the configuration files are located in the # easy-rsa tree. - +# #set_var EASYRSA "${0%/*}" # If your OpenSSL command is not in the system PATH, you will need to define the @@ -56,7 +56,7 @@ fi # Windows users, remember to use paths with forward-slashes (or escaped # back-slashes.) Windows users should declare the full path to the openssl # binary here if it is not in their system PATH. - +# #set_var EASYRSA_OPENSSL "openssl" # # This sample is in Windows syntax -- edit it for your path if not using PATH: @@ -68,11 +68,11 @@ fi # # WARNING: init-pki will do a rm -rf on this directory so make sure you define # it correctly! (Interactive mode will prompt before acting.) - +# #set_var EASYRSA_PKI "$PWD/pki" # Define directory for temporary subdirectories. - +# #set_var EASYRSA_TEMP_DIR "$EASYRSA_PKI" # Define X509 DN mode. @@ -83,7 +83,7 @@ fi # Choices are: # cn_only - use just a CN value # org - use the "traditional" Country/Province/City/Org/OU/email/CN format - +# #set_var EASYRSA_DN "cn_only" # Organizational fields (used with "org" mode and ignored in "cn_only" mode.) @@ -91,11 +91,11 @@ fi # certificate. Do not leave any of these fields blank, although interactively # you may omit any specific field by typing the "." symbol (not valid for # email.) - +# # NOTE: The following characters are not supported # in these "Organizational fields" by Easy-RSA: # back-tick (`) - +# #set_var EASYRSA_REQ_COUNTRY "US" #set_var EASYRSA_REQ_PROVINCE "California" #set_var EASYRSA_REQ_CITY "San Francisco" @@ -108,7 +108,7 @@ fi # future. Larger keysizes will slow down TLS negotiation and make key/DH param # generation take much longer. Values up to 4096 should be accepted by most # software. Only used when the crypto alg is rsa (see below.) - +# #set_var EASYRSA_KEY_SIZE 2048 # The default crypto mode is rsa; ec can enable elliptic curve support. @@ -117,19 +117,19 @@ fi # * rsa # * ec # * ed - +# #set_var EASYRSA_ALGO rsa # Define the named curve, used in ec & ed modes: - +# #set_var EASYRSA_CURVE secp384r1 # In how many days should the root CA key expire? - +# #set_var EASYRSA_CA_EXPIRE 3650 # In how many days should certificates expire? - +# #set_var EASYRSA_CERT_EXPIRE 825 # How many days until the next CRL publish date? Note that the CRL can still be @@ -141,6 +141,14 @@ fi # #set_var EASYRSA_RAND_SN "yes" +# Cut-off window for checking expiring certificates. +# +#set_var EASYRSA_CERT_RENEW 90 + +# For fixed certificate start/end dates - Range 1..365 +# +#set_var EASYRSA_FIX_OFFSET 1 + # Support deprecated "Netscape" extensions? (choices "yes" or "no".) The default # is "no" to discourage use of deprecated extensions. If you require this # feature to use with --ns-cert-type, set this to "yes" here. This support @@ -149,20 +157,14 @@ fi # this defined to "no". When set to "yes", server-signed certs get the # nsCertType=server attribute, and also get any NS_COMMENT defined below in the # nsComment field. - +# #set_var EASYRSA_NS_SUPPORT "no" # When NS_SUPPORT is set to "yes", this field is added as the nsComment field. # Set this blank to omit it. With NS_SUPPORT set to "no" this field is ignored. - +# #set_var EASYRSA_NS_COMMENT "Easy-RSA Generated Certificate" -# A temp file used to stage cert extensions during signing. The default should -# be fine for most users; however, some users might want an alternative under a -# RAM-based FS, such as /dev/shm or /tmp on some systems. - -#set_var EASYRSA_TEMP_FILE "$EASYRSA_PKI/extensions.temp" - # !! # NOTE: ADVANCED OPTIONS BELOW THIS POINT # PLAY WITH THEM AT YOUR OWN RISK @@ -189,6 +191,7 @@ fi # #set_var EASYRSA_EXT_DIR "$EASYRSA/x509-types" +# DEPRECATED # If you want to generate KDC certificates, you need to set the realm here. #set_var EASYRSA_KDC_REALM "CHANGEME.EXAMPLE.COM" @@ -198,37 +201,17 @@ fi # EASYRSA_PKI or EASYRSA dir (in that order.) NOTE that this file is Easy-RSA # specific and you cannot just use a standard config file, so this is an # advanced feature. - +# #set_var EASYRSA_SSL_CONF "$EASYRSA_PKI/openssl-easyrsa.cnf" -# Default CN: -# This is best left alone. Interactively you will set this manually, and BATCH -# callers are expected to set this themselves. - -#set_var EASYRSA_REQ_CN "ChangeMe" - # Cryptographic digest to use. # Do not change this default unless you understand the security implications. # Valid choices include: md5, sha1, sha256, sha224, sha384, sha512 - +# #set_var EASYRSA_DIGEST "sha256" # Batch mode. Leave this disabled unless you intend to call Easy-RSA explicitly # in batch mode without any user input, confirmation on dangerous operations, # or most output. Setting this to any non-blank string enables batch mode. - +# #set_var EASYRSA_BATCH "" - -# DISABLED - DO NOT USE -# Ref: https://github.com/OpenVPN/easy-rsa/issues/593 -# How many days before its expiration date a certificate is allowed to be -# renewed? -#set_var EASYRSA_CERT_RENEW 30 - -# DISABLED - DO NOT USE -# Ref: https://github.com/OpenVPN/easy-rsa/issues/593 -# For fixed certificate start/end dates - Range 1..365 -# If set here then command line option is always in effect. -# The day number 183 is either July 2nd or 3rd (leap-year) -# Replace with your chosen day-of-year value: -#set_var EASYRSA_FIX_OFFSET 183