exit 1
fi
+port=$(echo '/^port/ {print $2}' | ssh root@$host awk -f - /etc/openvpn/server/$name.conf | tail -n1)
+
f=/etc/openvpn/client/$name.crt
if ! $shell "test -s $f"; then
client
dev tun
proto udp
-remote $host 1194
+remote $host $port
resolv-retry infinite
nobind
persist-key
persist-tun
-ca $name-ca.crt
+ca ca-$name.crt
cert $name.crt
key $name.key
# disabled for better performance
#comp-lzo
verb 3
-# This script will update local dns
-# to what the server sends, if it sends dns.
-script-security 2
-up "$script"
-down "$script"
-
# matching server config
cipher AES-256-CBC
# The minimum of the client & server config is what is used by openvpn.
reneg-sec 432000
-tls-auth $name-ta.key 1
+tls-auth ta-$name.key 1
EOF
-if [[ $client_host ]] && $custom_script; then
- $shell "dd of=$script" <$script
- $shell "chmod +x $script"
+if [[ $script ]]; then
+ $shell "tee -a /etc/openvpn/client/$name.conf" <<EOF
+# This script will update local dns
+# to what the server sends, if it sends dns.
+script-security 2
+up "$script"
+down "$script"
+EOF
+
+ if [[ $client_host ]] && $custom_script; then
+ $shell "dd of=$script" <$script
+ $shell "chmod +x $script"
+ fi
fi
$shell 'cd /etc/openvpn; for f in client/*; do ln -sf $f .; done'