Re: [Openvpn-users] A few questions about revoking keys

2024-02-05 Thread Jochen Bern
On 04.02.24 16:32, Bo Berglund wrote: It took a week after revoking him until I could no longer access the site myself (I live about 6000 km away from the site and rely on OpenVPN for access). We once apparently had someone think that it'd be "neat and tidy" to have a root CA cert's validity e

Re: [Openvpn-users] A few questions about revoking keys

2024-02-04 Thread Gert Doering
Hi, On Sun, Feb 04, 2024 at 05:51:08PM +, Peter Davis wrote: > 1- Suppose I have two clients with the same name (Peter). I have generated > the keys for one and not for the other. Now I revoke Peter's keys and > generate new keys again with Peter's name. Because new keys with the same > nam

Re: [Openvpn-users] A few questions about revoking keys

2024-02-04 Thread Peter Davis via Openvpn-users
>On Sunday, February 4th, 2024 at 3:41 PM, Gert Doering >wrote: > Hi, > > On Sun, Feb 04, 2024 at 10:31:20AM +, Peter Davis via Openvpn-users wrote: > > > I want to revoke a user's key and I have a few questions: > > 1- If I revoke a key and create a new key with the same name as before, c

Re: [Openvpn-users] A few questions about revoking keys

2024-02-04 Thread Gert Doering
Hi, On Sun, Feb 04, 2024 at 04:32:42PM +0100, Bo Berglund wrote: > You are right about different use cases, but I wanted to share my > panic-stricken > experience when trying to block an ex-employee with the key revoke method not > understanding that that system relies on a constant server side r

Re: [Openvpn-users] A few questions about revoking keys

2024-02-04 Thread Bo Berglund
On Sun, 4 Feb 2024 15:38:41 +0100, Gert Doering wrote: >Hi, > >On Sun, Feb 04, 2024 at 02:17:35PM +0100, Bo Berglund wrote: >> 2) But if you have actually taken the advice then making a user unable to >> connect is very simple to manage by NOT revoking any key: >> Just create a file with the Comm

Re: [Openvpn-users] A few questions about revoking keys

2024-02-04 Thread Gert Doering
Hi, On Sun, Feb 04, 2024 at 02:17:35PM +0100, Bo Berglund wrote: > 2) But if you have actually taken the advice then making a user unable to > connect is very simple to manage by NOT revoking any key: > Just create a file with the Common Name of tyhat user in the ssd directory on > the server and

Re: [Openvpn-users] A few questions about revoking keys

2024-02-04 Thread Bo Berglund
On Sun, 04 Feb 2024 10:31:20 +, Peter Davis via Openvpn-users wrote: >Hello, >I want to revoke a user's key and I have a few questions: >1- If I revoke a key and create a new key with the same name as before, >can the previous user connect to the server? In what way is he "previous" if all y

Re: [Openvpn-users] A few questions about revoking keys

2024-02-04 Thread Gert Doering
Hi, On Sun, Feb 04, 2024 at 10:31:20AM +, Peter Davis via Openvpn-users wrote: > I want to revoke a user's key and I have a few questions: > 1- If I revoke a key and create a new key with the same name as before, can > the previous user connect to the server? I don't know about "users". The

[Openvpn-users] A few questions about revoking keys

2024-02-04 Thread Peter Davis via Openvpn-users
Hello, I want to revoke a user's key and I have a few questions: 1- If I revoke a key and create a new key with the same name as before, can the previous user connect to the server? 2- If I use the ./revoke-full "Client_Name" command to revoke a key, do I need to add a line to the server configu