2014-06-04 03:35:44 +00:00
|
|
|
# Original credit: https://github.com/jpetazzo/dockvpn
|
|
|
|
|
2016-02-11 17:10:51 +00:00
|
|
|
# Smallest base image
|
2020-01-16 02:50:25 +00:00
|
|
|
FROM ubuntu:18.04@sha256:bc025862c3e8ec4a8754ea4756e33da6c41cba38330d7e324abd25c8e0b93300
|
2014-06-04 03:35:44 +00:00
|
|
|
|
2019-11-16 03:49:39 +00:00
|
|
|
LABEL maintainer="lawtancool"
|
2014-06-04 03:35:44 +00:00
|
|
|
|
2017-05-11 18:19:39 +00:00
|
|
|
# Testing: pamtester
|
2019-06-22 01:26:57 +00:00
|
|
|
#RUN echo "http://dl-cdn.alpinelinux.org/alpine/edge/testing/" >> /etc/apk/repositories && \
|
|
|
|
# apk add --update openvpn iptables bash easy-rsa openvpn-auth-pam google-authenticator pamtester && \
|
|
|
|
# ln -s /usr/share/easy-rsa/easyrsa /usr/local/bin && \
|
|
|
|
# rm -rf /tmp/* /var/tmp/* /var/cache/apk/* /var/cache/distfiles/*
|
|
|
|
|
2019-06-22 04:48:54 +00:00
|
|
|
RUN apt-get update && apt-get install -y wget tar unzip build-essential libssl-dev iproute2 liblz4-dev liblzo2-dev libpam0g-dev libpkcs11-helper1-dev libsystemd-dev easy-rsa iptables pkg-config && \
|
2019-11-16 03:49:14 +00:00
|
|
|
wget http://swupdate.openvpn.org/community/releases/openvpn-2.4.8.tar.gz && tar xvf openvpn-2.4.8.tar.gz && \
|
|
|
|
wget https://github.com/Tunnelblick/Tunnelblick/archive/v3.8.2beta02.zip && unzip v3.8.2beta02.zip && \
|
2019-11-16 04:19:11 +00:00
|
|
|
cp Tunnelblick-3.8.2beta02/third_party/sources/openvpn/openvpn-2.4.8/patches/*.diff openvpn-2.4.8 && \
|
2019-11-16 03:49:14 +00:00
|
|
|
cd openvpn-2.4.8 && \
|
2019-06-22 01:26:57 +00:00
|
|
|
patch -p1 < 02-tunnelblick-openvpn_xorpatch-a.diff && \
|
|
|
|
patch -p1 < 03-tunnelblick-openvpn_xorpatch-b.diff && \
|
|
|
|
patch -p1 < 04-tunnelblick-openvpn_xorpatch-c.diff && \
|
|
|
|
patch -p1 < 05-tunnelblick-openvpn_xorpatch-d.diff && \
|
|
|
|
patch -p1 < 06-tunnelblick-openvpn_xorpatch-e.diff && \
|
2019-06-22 02:06:59 +00:00
|
|
|
./configure --disable-systemd --enable-async-push --enable-iproute2 && \
|
2019-06-22 01:26:57 +00:00
|
|
|
make && make install
|
|
|
|
|
2014-06-04 17:52:59 +00:00
|
|
|
# Needed by scripts
|
|
|
|
ENV OPENVPN /etc/openvpn
|
2016-02-11 17:10:51 +00:00
|
|
|
ENV EASYRSA /usr/share/easy-rsa
|
2014-06-04 17:52:59 +00:00
|
|
|
ENV EASYRSA_PKI $OPENVPN/pki
|
|
|
|
ENV EASYRSA_VARS_FILE $OPENVPN/vars
|
|
|
|
|
2017-06-17 11:01:24 +00:00
|
|
|
# Prevents refused client connection because of an expired CRL
|
|
|
|
ENV EASYRSA_CRL_DAYS 3650
|
|
|
|
|
2014-06-04 04:10:55 +00:00
|
|
|
VOLUME ["/etc/openvpn"]
|
2014-06-04 03:54:47 +00:00
|
|
|
|
2015-06-22 05:55:16 +00:00
|
|
|
# Internally uses port 1194/udp, remap using `docker run -p 443:1194/tcp`
|
2019-06-22 02:01:42 +00:00
|
|
|
EXPOSE 1194
|
2014-06-04 03:54:47 +00:00
|
|
|
|
2014-06-04 18:13:59 +00:00
|
|
|
CMD ["ovpn_run"]
|
|
|
|
|
|
|
|
ADD ./bin /usr/local/bin
|
2015-09-08 02:21:55 +00:00
|
|
|
RUN chmod a+x /usr/local/bin/*
|
2016-02-06 19:23:59 +00:00
|
|
|
|
|
|
|
# Add support for OTP authentication using a PAM module
|
2016-02-07 13:45:28 +00:00
|
|
|
ADD ./otp/openvpn /etc/pam.d/
|