OPVN Server: Difference between revisions

From AbahDoku Wiki
No edit summary
No edit summary
Line 8: Line 8:
  add name=CA common-name=CA days-valid=3650 key-size=2048 key-usage=crl-sign,key-cert-sign
  add name=CA common-name=CA days-valid=3650 key-size=2048 key-usage=crl-sign,key-cert-sign
Yang menggunakan WinBox dapat diikuti seperti gambar berikut :
Yang menggunakan WinBox dapat diikuti seperti gambar berikut :
[[File:Ovpn1.png|link=https://drive.google.com/uc?id=1qanQdO5KAFamIbil11r64QkXTRVgbRJl|center|500px|New Certificate - CA|thumb]]
[[File:Ovpn1.png|link=https://drive.google.com/uc?id=1qanQdO5KAFamIbil11r64QkXTRVgbRJl|center|500px|New Certificate > CA|thumb]]
[[File:Ovpn2.png|center|500px|Key Usage - CA|thumb]]
[[File:Ovpn2.png|center|500px|Key Usage > CA|thumb]]
  add name=server-template common-name=*.example.com days-valid=3650 key-size=2048 key-usage=digital-signature,key-encipherment,tls-server
  add name=server-template common-name=*.example.com days-valid=3650 key-size=2048 key-usage=digital-signature,key-encipherment,tls-server
[[File:Ovpn4.png|center|500px|New Certificate - Server|thumb]]
[[File:Ovpn4.png|center|500px|New Certificate > Server|thumb]]
 
[[File:Ovpn5.png|center|500px|Key Usage > Server|thumb]]
[[File:Ovpn5.png|center|500px|Key Usage - Server|thumb]]
  add name=client common-name=client days-valid=3650 key-size=2048 key-usage=tls-client
  add name=client common-name=client days-valid=3650 key-size=2048 key-usage=tls-client
[[File:Ovpn4.png|link=https://drive.google.com/uc?id=1hIFuzv6i26r3nNP6bXxXZuOSx9ZBMQ92|center|500px|New Certificate > Client|thumb]]
[[File:Ovpn4.png|link=https://drive.google.com/uc?id=1hIFuzv6i26r3nNP6bXxXZuOSx9ZBMQ92|center|500px|New Certificate > Client|thumb]]

Revision as of 16:28, 16 January 2024

Syarat :

1. Memiliki IP Publik (contoh : 108.87.62.201)
2. Membuat Certificate di Mikrotik.

Jika syarat 1 sudah dipenuhi, lanjut ke syarat 2.

Membuat Certificate

/certificate
add name=CA common-name=CA days-valid=3650 key-size=2048 key-usage=crl-sign,key-cert-sign

Yang menggunakan WinBox dapat diikuti seperti gambar berikut :

File:Ovpn1.png
New Certificate > CA
File:Ovpn2.png
Key Usage > CA
add name=server-template common-name=*.example.com days-valid=3650 key-size=2048 key-usage=digital-signature,key-encipherment,tls-server
File:Ovpn4.png
New Certificate > Server
File:Ovpn5.png
Key Usage > Server
add name=client common-name=client days-valid=3650 key-size=2048 key-usage=tls-client
File:Ovpn4.png
New Certificate > Client
File:Ovpn7.png
Key Usage Client

Untuk client dapat dibuat beberapa certificate yang berbeda untuk tiap client (sesuaikan dengan jumlah client).

add name=client1 common-name=client days-valid=3650 key-size=2048 key-usage=tls-client

Sign Certificate

/certificate
sign ca ca-crl-host=108.87.62.201 name=ca-certificate
File:Ovpn3.png
Sign > CA
sign server name=server-certificate ca=ca-certificate
File:Opvn6.png
Sign > Server
sign client name=client-certificate ca=ca-certificate

Untuk CA ada beberapa yang menggunakan :

sign ca name=ca-certificate

Untuk diperhatikan progress saat sign sampai berhasil : done