tls-auth: Enable tls-auth for security

* Enabling tls-auth improves security and helps protect against DDoS.
This commit is contained in:
Kyle Manna 2014-06-04 15:34:42 -07:00
parent 1751d00fc9
commit bc4165e587
2 changed files with 6 additions and 6 deletions

View File

@ -37,10 +37,10 @@ $(cat $EASYRSA_PKI/ca.crt)
<dh> <dh>
$(cat $EASYRSA_PKI/dh.pem) $(cat $EASYRSA_PKI/dh.pem)
</dh> </dh>
#<tls-auth> <tls-auth>
#$(echo cat $EASYRSA_PKI/ta.key) $(cat $EASYRSA_PKI/ta.key)
#</tls-auth> </tls-auth>
#key-direction 1 key-direction 1
<connection> <connection>
remote $servername 1194 udp remote $servername 1194 udp

View File

@ -44,8 +44,8 @@ key $EASYRSA_PKI/private/$cn.key
ca $EASYRSA_PKI/ca.crt ca $EASYRSA_PKI/ca.crt
cert $EASYRSA_PKI/issued/$cn.crt cert $EASYRSA_PKI/issued/$cn.crt
dh $EASYRSA_PKI/dh.pem dh $EASYRSA_PKI/dh.pem
#tls-auth $EASYRSA_PKI/ta.key tls-auth $EASYRSA_PKI/ta.key
#key-direction 0 key-direction 0
keepalive 10 60 keepalive 10 60
persist-key persist-key
persist-tun persist-tun