Skip to content

Commit 915a4ff

Browse files
committed
Move cipher configuration to Dockerfile so the defaults are also
available to the scripts (ie getclient)
1 parent 60d6e9f commit 915a4ff

File tree

2 files changed

+3
-2
lines changed

2 files changed

+3
-2
lines changed

Dockerfile

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,9 @@ ENV OVPN_CRL $OPENVPN/crl/crl.pem
2222
ENV OVPN_CCD $OPENVPN/ccd
2323
ENV OVPN_DEFROUTE 0
2424

25+
ENV OVPN_CIPHER "AES-256-CBC"
26+
ENV OVPN_TLS_CIPHER "TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
27+
2528
ENV EASYRSA /usr/share/easy-rsa
2629
ENV EASYRSA_PKI $OPENVPN/pki
2730

entrypoint.sh

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,8 +22,6 @@ OVPN_PROTO="${OVPN_PROTO:-tcp}"
2222
OVPN_NATDEVICE="${OVPN_NATDEVICE:-eth0}"
2323
OVPN_K8S_DOMAIN="${OVPN_K8S_DOMAIN:-svc.cluster.local}"
2424
OVPN_VERB=${OVPN_VERB:-3}
25-
OVPN_CIPHER=${OVPN_CIPHER:-"AES-256-CBC"}
26-
OVPN_TLS_CIPHER=${OVPN_TLS_CIPHER:-"TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"}
2725

2826
if [ ! -d "${EASYRSA_PKI}" ]; then
2927
echo "PKI directory missing. Did you mount in your Secret?"

0 commit comments

Comments
 (0)