-source vars # dun care about setting cert cn etc from the non-example values
-./clean-all
-# accept default prompts
-echo -e '\n\n\n\n\n\n\n\n' | ./build-ca
-
-# This builds the server's key/cert. argument is the name of the file,
-# but it also is the default common name of the cert.
-# 'server' is the default name in our conf file for the name of the file
-# and I've seen no reason to change it.
-# Note, this is not idempotent.
-{ echo -e '\n\n\n\n\n\n\n\n\n\n'; sleep 1; echo -e 'y\ny\n'; } | ./build-key-server server
-./build-dh
-cp /usr/share/doc/openvpn/examples/sample-config-files/server.conf.gz /etc/openvpn/
-cp /etc/openvpn/easy-rsa/keys/{ca.crt,server.{crt,key},dh2048.pem} /etc/openvpn
-gzip -df /etc/openvpn/server.conf.gz
-# dh improve security,
-# remove comp-lzo to increase perf
-sed -i --follow-symlinks -f - /etc/openvpn/server.conf <<'EOF'
-s/^dh dh1024.pem/dh dh2048.pem/
-/^comp-lzo.*/d
-EOF
+if [[ -e openssl-1.0.0.cnf && ! -e openssl.cnf ]]; then
+ # there's a debian bug about this.
+ ln -s openssl-1.0.0.cnf openssl.cnf
+fi
+
+keys_exist=true
+keyfiles=(/etc/openvpn/easy-rsa/keys/{ca.crt,server.{crt,key},dh2048.pem,ta.key})
+for f in ${keyfiles[@]}; do
+ if [[ ! -e $f ]]; then
+ keys_exist=false
+ break
+ fi
+done
+
+if ! $keys_exist; then
+ source vars # dun care about setting cert cn etc from the non-example values
+ ./clean-all # note: removes and creates /etc/openvpn/easy-rsa/keys
+ # newer sample configs (post stretch) use ta.key. no harm making it for earlier oses
+ openvpn --genkey --secret /etc/openvpn/easy-rsa/keys/ta.key
+ # accept default prompts
+ echo -e '\n\n\n\n\n\n\n\n' | ./build-ca
+
+ # This builds the server's key/cert. argument is the name of the file,
+ # but it also is the default common name of the cert.
+ # 'server' is the default name in our conf file for the name of the file
+ # and I've seen no reason to change it.
+ # Note, this is not idempotent.
+ { echo -e '\n\n\n\n\n\n\n\n\n\n'; sleep 1; echo -e 'y\ny\n'; } | ./build-key-server server
+ ./build-dh
+fi
+
+server_dir=/etc/openvpn/server
+mkdir -p $server_dir
+chmod 700 $server_dir
+
+cp /usr/share/doc/openvpn/examples/sample-config-files/server.conf.gz $server_dir
+gzip -df $server_dir/server.conf.gz
+
+
+cp ${keyfiles[@]} $server_dir
+# for legacy systems
+for f in ${keyfiles[@]}; do
+ ln -sf server/${f##*/} /etc/openvpn
+done
+
+cat >>$server_dir/server.conf <<'EOF'