OPVN Server: Difference between revisions

From AbahDoku Wiki
No edit summary
No edit summary
Line 7: Line 7:
  /certificate
  /certificate
  add name=CA common-name=CA days-valid=3650 key-size=2048 key-usage=crl-sign,key-cert-sign
  add name=CA common-name=CA days-valid=3650 key-size=2048 key-usage=crl-sign,key-cert-sign
[[[File:Ovpn1.png|400px|New Certificate]]|center|[[File:Ovpn2.png|400px|Key Usage]]]
[[File:Ovpn1.png,Ovpn2.png|center|400px|New Certificate]]
  add name=server-template common-name=*.example.com days-valid=3650 key-size=2048 key-usage=digital-signature,key-encipherment,tls-server
  add name=server-template common-name=*.example.com days-valid=3650 key-size=2048 key-usage=digital-signature,key-encipherment,tls-server
  add name=client common-name=client days-valid=3650 key-size=2048 key-usage=tls-client
  add name=client common-name=client days-valid=3650 key-size=2048 key-usage=tls-client

Revision as of 09:38, 16 January 2024

Syarat :

1. Memiliki IP Publik
2. Membuat Certificate di Mikrotik.

Jika syarat 1 sudah dipenuhi, lanjut ke syarat 2.

Membuat Certificate

/certificate
add name=CA common-name=CA days-valid=3650 key-size=2048 key-usage=crl-sign,key-cert-sign
New Certificate
New Certificate
add name=server-template common-name=*.example.com days-valid=3650 key-size=2048 key-usage=digital-signature,key-encipherment,tls-server
add name=client common-name=client days-valid=3650 key-size=2048 key-usage=tls-client

Untuk client dapat dibuat beberapa certificate yang berbeda untuk tiap client (sesuaikan dengan jumlah client).

add name=client1 common-name=client days-valid=3650 key-size=2048 key-usage=tls-client

Sign Certificate