Richard T Bonhomme 1f18f19555
easyrsa_mktemp(): Increase the number of test-temp-files (Squashed)
commit df0a19e7ebaba5cb6fd2787ce4747d6338447a0a
Merge: e3e9f9e a7e58dd
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 8 14:30:46 2023 +0100

    Merge branch 'easyrsa_mktemp-increase-depth' of ssh://github.com/TinCanTech/easy-rsa into TinCanTech-easyrsa_mktemp-increase-depth

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit a7e58dd70cb2aeb06ebee39c6b2c438e9ac76cdc
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 8 02:43:20 2023 +0100

    verify_algo_params(): Edwards Curve, call OpenSSL directly

    This allows the output to be discarded via /dev/null, because
    there is no use of temp-files and verbose messages.

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit d64dfcc16676b1e1b3fda7090667aea76bd718fc
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 8 02:13:29 2023 +0100

    easyrsa_mktemp(): Windows, 'set -o noclobber' to control 'mv.exe'

    Currently, mv.exe will always prompt before over-writing a file.
    When creating temp-files, mv.exe must NEVER prompt but silently
    fail and try again with a new, sequentially numbered, file-name.

    Using 'set -o noclobber' causes mv.exe to behave correctly here.

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

commit 948e1a1fbb338a32cf9b42d6fe9801b0fe7bfde9
Author: Richard T Bonhomme <tincantech@protonmail.com>
Date:   Sat Apr 8 01:22:47 2023 +0100

    easyrsa_mktemp(): Allow nine (9) test files

    Use of easyrsa_openssl() creates temp-files by default
    and is used in subshells.  This requires maximum of (7)
    seven test files to move the shot-file to. (Currently)

    Raise the the number of test-files to maximum nine (9).

    Status reports, read_db(): Recreate temporary session
    directory for each record. 'easyrsa' is designed to run
    one command and then exit, removing the temp session.
    Status reports run 'easyrsa' for the number of records
    in the database, before exiting. Therefore, the temp
    session MUST be reset for eash record read.

    Add verbose output to help debug easyrsa_mktemp problems.

    Improve comments.

    Complete renaming of
    - EASYRSA_CERT_RENEW -to- EASYRSA_PRE_EXPIRY_WINDOW

    Split vars_setup(), add verify_working_env()
    - vars_setup() now only processes vars file.
    - verify_working_env() does the rest.
    The split does not change any of the enclosed code.

    Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>

Signed-off-by: Richard T Bonhomme <tincantech@protonmail.com>
2023-04-08 14:32:41 +01:00
2022-05-30 18:58:03 +01:00
…

CI

Overview

easy-rsa is a CLI utility to build and manage a PKI CA. In laymen's terms, this means to create a root certificate authority, and request and sign certificates, including intermediate CAs and certificate revocation lists (CRL).

Downloads

If you are looking for release downloads, please see the releases section on GitHub. Releases are also available as source checkouts using named tags.

Documentation

For 3.x project documentation and usage, see the README.quickstart.md file or the more detailed docs under the doc/ directory. The .md files are in Markdown format and can be converted to html files as desired for release packages, or read as-is in plaintext.

Getting help using easy-rsa

Currently, Easy-RSA development co-exists with OpenVPN even though they are separate projects. The following resources are good places as of this writing to seek help using Easy-RSA:

The openvpn-users mailing list is a good place to post usage or help questions.

You can also try libera.chat IRC network, in channels #openvpn for general support or #easyrsa for development discussion.

Branch structure

The easy-rsa master branch is currently tracking development for the 3.x release cycle. Please note that, at any given time, master may be broken. Feel free to create issues against master, but have patience when using the master branch. It is recommended to use a release, and priority will be given to bugs identified in the most recent release.

The prior 2.x and 1.x versions are available as release branches for tracking and possible back-porting of relevant fixes. Branch layout is:

master         <- 3.1, at present
v3.x.x            pre-release branches, used for staging branches
release/3.0       v3.0.x bugfix/security/openssl updates
release/2.x
release/1.x

LICENSING info for 3.x is in the COPYING.md file

Code style, standards

We are attempting to adhere to the POSIX standard, which can be found here:

https://pubs.opengroup.org/onlinepubs/9699919799/

Languages
Shell 99.4%
Batchfile 0.6%