fix(openvpn-phone): add <ca> to the client profile for ics-openvpn
lint / yamllint + ansible-lint + syntax-check (push) Canceled after 0s
lint / yamllint + ansible-lint + syntax-check (push) Canceled after 0s
"OpenVPN for Android" fails at "Building configuration" ("Used 101 tries
to get current version of the profile") for a `client`-mode profile with
no <ca> block. The earlier tls-client p2p profile had no CA either but the
app treated it as a custom tunnel; `client` mode makes the CA mandatory in
the app's config builder.
Inline the server's self-signed certificate as <ca> (it is its own trust
anchor); peer-fingerprint still does the actual verification. Server config
unchanged.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KbuZrUoevfBgCpf5DCF4DG
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
203751d874
commit
c5c33986da
@@ -302,6 +302,15 @@
|
||||
state: started
|
||||
enabled: true
|
||||
|
||||
- name: Read the server certificate for the profile CA block
|
||||
# client-режим ics-openvpn отказывается собирать конфиг без <ca>.
|
||||
# Серверный самоподписанный сертификат сам себе trust anchor; реальную
|
||||
# проверку всё равно делает peer-fingerprint.
|
||||
ansible.builtin.slurp:
|
||||
src: "{{ phone_openvpn_server_cert }}"
|
||||
register: phone_openvpn_server_cert_raw
|
||||
no_log: true
|
||||
|
||||
- name: Read the client certificate for the profile
|
||||
ansible.builtin.slurp:
|
||||
src: "{{ phone_openvpn_client_cert }}"
|
||||
@@ -342,6 +351,9 @@
|
||||
resolv-retry infinite
|
||||
nobind
|
||||
verb 3
|
||||
<ca>
|
||||
{{ phone_openvpn_server_cert_raw.content | b64decode | trim }}
|
||||
</ca>
|
||||
<cert>
|
||||
{{ phone_openvpn_client_cert_raw.content | b64decode | trim }}
|
||||
</cert>
|
||||
|
||||
Reference in New Issue
Block a user