Skip to content

Commit cfcf9e6

Browse files
authored
Update openvpn-client-tun.ovpn
`tls-cipher` options based on latest openvpn
1 parent 46e1f19 commit cfcf9e6

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

openvpn-client-tun.ovpn

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,9 +35,12 @@ MY CERT from ta.key
3535
verify-x509-name 'C=US, O=DomainName, OU=OpenVPN, CN=domainname.tld' subject
3636
;auth-user-pass
3737
;tls-remote server-domainname
38-
auth SHA512
3938
;cipher BF-CBC ; susceptible to SWEET32 attacks
4039
cipher AES-256-CBC
40+
; openvpn --show-tls | grep -e '^TLS' | grep -v 128 | grep -v -e 'SHA$' | grep -v GCM
41+
tls-cipher TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384:TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256:TLS-DHE-DSS-WITH-AES-256-CBC-SHA256:TLS-ECDH-RSA-WITH-AES-256-CBC-SHA384:TLS-ECDH-ECDSA-WITH-AES-256-CBC-SHA384
42+
tls-version-min 1.2
43+
auth SHA512
4144
;client-http-proxy 10.0.1.3 3128
4245
comp-lzo
4346
verb 3

0 commit comments

Comments
 (0)