On Fri, May 06, 2016 at 12:41:27PM -0700, Sean Byrne wrote: > Is it possible to migrate from the open source version of OpenVPN > to another instance running OpenVPN Access Server? I used Easy-RSA > to set up my PIK.
Of course. You simply copy the server key and certificate, with the CA certificate, to the Access Server. Where to place those files would be a matter for OpenVPN-AS support to answer. Alternatively you might choose to generate a new server key and certificate in place of the old one. You should *NOT*, however, do what your subject line implies, and copy the Easy-RSA PKI to the new server. The PKI should be maintained on a separate physical machine, preferably one not participating in the VPN in any manner. (Also resist the urge to use a virtual machine for a PKI, because they lack entropy needed for random number generation.) > And if it's not possible to transfer, is it possible to set up > a PKI with OpenVPN Access Server. Easy-rsa is simply a frontend for OpenSSL's ca(1) utility, but again, specific questions regarding OpenVPN-AS don't belong here. -- http://rob0.nodns4.us/ Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: ------------------------------------------------------------------------------ Find and fix application performance issues faster with Applications Manager Applications Manager provides deep performance insights into multiple tiers of your business applications. It resolves application problems quickly and reduces your MTTR. Get your free trial! https://ad.doubleclick.net/ddm/clk/302982198;130105516;z _______________________________________________ Openvpn-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openvpn-users
