IPCop

Creating an OpenVPN Security Certificate

 
In Yamouth ... England, that is.
Creating an OpenVPN Security Certificate
by Lawrence Bean - Monday, 13 October 2008, 8:09 PM
 
1) Connect as an administrator to the IPCop Firewall
PB: https://firewall.phippsburg.u47.k12.me.us:47445
WB: https://firewall.westbath.u47.k12.me.us:47445
WW: https://firewall.woolwich.u47.k12.me.us:47445

2) Go to VPNs->OpenVPN

3) At the bottom in the "Client status and control" section, click "Add"

4) In the next screen, select "Host-to-Net Virtual Private Network (RoadWarrior) and click "Add"

5) In the next screen enter:
name: Serial Number of the Computer
remark: the user's name
Authentication: Generate a certificate
System Hostname: Serial Number of the Computer
Email Address: email address for the user
Department: building name as appropriate
Phippsburg Elementary School
West Bath School
Woolwich Central School
Organization: RSU1
City: Bath
State: Maine
Country: United States
PKCS12 Password: Serial Number of the Computer
Click Save

6) Return to the bottom of the OpenVPN page and find the record with the serial number you just created. To the right, next to the red "CLOSED" box, click the pyramid icon. This should download a .zip file with the certificates called [serialnumber]-TO-IPCOP.zip.

7) If needed, unpack the .zip file to get a folder called [serialnumber]-TO-IPCop

8) Rename the file "[serialnumber]-TO-IPCop.ovpn" to "[school].ovpn" for a Windows user and "[school].conf" for a Macintosh user ... you may get a warning about changing the file extension; just say you want to use the new .conf ... where [school] is a short name for the school (phippsburg, westbath, woolwich)

9) Open the .conf or .ovpn file in TextEdit and remove the line:
ns-cert-type server

10) Attach and send these two files to the user