On Fri, May 06, 2016 at 12:41:27PM -0700, Sean Byrne wrote:
> Is it possible to migrate from the open source version of OpenVPN 
> to another instance running OpenVPN Access Server? I used Easy-RSA 
> to set up my PIK.

Of course.  You simply copy the server key and certificate, with the 
CA certificate, to the Access Server.  Where to place those files 
would be a matter for OpenVPN-AS support to answer.

Alternatively you might choose to generate a new server key and 
certificate in place of the old one.

You should *NOT*, however, do what your subject line implies, and 
copy the Easy-RSA PKI to the new server.  The PKI should be 
maintained on a separate physical machine, preferably one not 
participating in the VPN in any manner.

(Also resist the urge to use a virtual machine for a PKI, because 
they lack entropy needed for random number generation.)

> And if it's not possible to transfer, is it possible to set up
> a PKI with OpenVPN Access Server.

Easy-rsa is simply a frontend for OpenSSL's ca(1) utility, but again, 
specific questions regarding OpenVPN-AS don't belong here.
-- 
  http://rob0.nodns4.us/
  Offlist GMX mail is seen only if "/dev/rob0" is in the Subject:

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to