]> git.ipfire.org Git - ipfire-2.x.git/commitdiff
OpenVPN: Set default of 730 days for client certificate validity
authorErik Kapfer <erik.kapfer@ipfire.org>
Mon, 18 Jun 2018 14:41:27 +0000 (16:41 +0200)
committerMichael Tremer <michael.tremer@ipfire.org>
Mon, 18 Jun 2018 14:49:24 +0000 (15:49 +0100)
Since OpenSSL 1.1.0x it is required to set a value for the 'valid til (days)' field.
The WUI delivers now a guide value of two years.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
html/cgi-bin/ovpnmain.cgi

index 1c2a810020db1c530c729f7679a696e5fa8ce205..b3122a49c7c1790208bbe03d7234556b92e637e5 100644 (file)
@@ -4451,7 +4451,7 @@ if ($cgiparams{'TYPE'} eq 'net') {
        $cgiparams{'CERT_CITY'}         = $vpnsettings{'ROOTCERT_CITY'};
        $cgiparams{'CERT_STATE'}        = $vpnsettings{'ROOTCERT_STATE'};
        $cgiparams{'CERT_COUNTRY'}      = $vpnsettings{'ROOTCERT_COUNTRY'};
-       $cgiparams{'DAYS_VALID'}        = $vpnsettings{'DAYS_VALID'};
+       $cgiparams{'DAYS_VALID'}        = $vpnsettings{'DAYS_VALID'} = '730';
     }
 
     VPNCONF_ERROR: