From: Justin Wind Date: Mon, 23 Oct 2017 17:53:54 +0000 (-0700) Subject: generate dhparam locally rather than on vpn server X-Git-Url: http://git.squeep.com/?p=awsible;a=commitdiff_plain;h=d10a4b69962d07e31bd2be65dc044c0268ec28a6 generate dhparam locally rather than on vpn server --- diff --git a/generate-ansible-vpcaccess-vars.sh b/generate-ansible-vpcaccess-vars.sh index e951308..fcdf8ea 100755 --- a/generate-ansible-vpcaccess-vars.sh +++ b/generate-ansible-vpcaccess-vars.sh @@ -14,6 +14,7 @@ crl_pem="${1}_ca/pki/crl.pem" cert="${1}_ca/pki/issued/${2}.${1}.crt" key="${1}_ca/pki/private/${2}.${1}.key" ta_secret="${1}_ca/pki/ta.key" +dhparam="${1}_ca/pki/dh.pem" # reuse any extant quagga password for v in "${1}"/group_vars/*vpcaccess* @@ -23,11 +24,20 @@ do echo "found multiple potential quagga passwords; the chosen one may not be correct" 1>&2 fi quagga_password=$(awk '/QUAGGA_PASSWORD:/{print $2}' "${v}") + + if [ -n "${quagga_key}" ] + then + echo "found multiple potential quagga keys; the chosen one may not be correct" 1>&2 + fi done if [ -z "${quagga_password}" ] then quagga_password=$(pwgen -y 16) fi +if [ -z "${quagga_key}" ] +then + quagga_key=$(pwgen -y 16) +fi function onlycert(){ sed -n '/-----BEGIN /,/-----END /p' "$@" @@ -38,7 +48,8 @@ function indent(){ cat<