/srv/irclogs.ubuntu.com/2015/07/02/#ubuntu-us-pa.txt

rmg51Morning09:32
teddy-dbearMorning peoples, critters and everything else12:07
ChinnoDogWhy does setting up OpenVPN server take so many steps?16:56
ChinnoDogIs there no way to set it up with a couple commands?16:56
ChinnoDogOne of the great things about Ubuntu packages is that they provide more defaults than the software they contain would have if you downloaded it and installed it the conventional way. OpenVPN should have a default configuration that just works.16:59
jthanChinnoDog: which distro?17:02
ChinnoDogUbuntu17:03
ChinnoDog14.0417:03
r00t^2ChinnoDog: it takes so many steps because it's so flexible. if you're looking for clicky-clicky high-resource bullshit, use openvpn_as17:03
jedijflol17:10
jedijfmommy, why is security difficult?17:10
ChinnoDogIt isn't difficult, it is needlessly difficult.17:12
ChinnoDogIf it is just complex then I expect to work it out. If there is an opportunity to make things easier then they should be.17:12
jedijfwell, that was provided too, openvpn-as17:13
r00t^2s/-/_/ ;)17:13
jedijfshift_fail17:14
r00t^2ChinnoDog: a.k.a. the thing they try to shill on you *when you go to the openvpn.net homepage*17:14
r00t^2really, it only seems like so many steps because the documentation/howto for the community versions so expansive17:14
r00t^2it's only like, 6 or 7 steps.17:15
jedijfyeah, and i don't recall it being overly cumbersome either17:15
r00t^2and that's assuming you're using the extra security features like diffie-hellman17:15
jedijfhttp://jedijf.blogspot.com/2012/04/openvpn.html17:15
jedijfobviously somne thing may have changed along with the date/year17:16
r00t^2there ya go. i mean, if *jthan* can set it up....17:16
r00t^2jedijf: nah, still the same, only thing that's really changed over the past five? years is an optional new way of defining the listening port/proto/interface and at some point they made the default cipher to be bowfish-cbc17:17
r00t^2s/bow/blow/17:17
jthanChinnoDog: It's really not bad, is true... Just take the sample config and modify it, start service17:18
ChinnoDogI tried openvpn_as didn't work. The irony. I configured the standard one by hand and successfully connected to it.19:38
jthanChinnoDog: that's simplicity that you previously called complexity ;-)19:38
ChinnoDogI know. And, it took forever.19:40
ChinnoDogI should make a PPA with an instant-openvpn package that configures it for you.19:46
jthanLol why did it take forever?!19:50
ChinnoDogBecause there were so many steps20:14
jthanNOooo20:52
r00t^2ChinnoDog: no you shouldn't, because shared keys is how people get compromised21:44
ChinnoDogr00t^2: New keys can be generated as part of setup.22:57
r00t^2and what about subnet? interface? port? protocol? cipher to use?22:58
r00t^2also, for a 4096 bit DH key, it takes more than a couple minutes to generate on average and clean hardware/ENV. you're really going to make users wait that long at a hanging apt-get prompt while you gen that?22:59
r00t^2i'm just saying, if this was a good idea, then linux installers would have had root gen a private ssh key on installation years ago. :P23:00
ChinnoDogJust because it isn't done yet doesn't mean it is a bad idea. It does take some time to generate the key but there are also post install hooks that could be good for that.23:04
r00t^2"not done yet"? you're arguing against not some "new and revolutionary idea" but something that's been *avoided* for more than 20 years.23:07
r00t^2err, arguing for, rather23:09
ChinnoDogI can find no evidence anyone has been avoiding it. I think it simply hasn't been done yet because no one has seen it fit to take their time to do it. In any case, I would never assume something that has not been done has been left undone intentionally. Especially with open source anything.23:41

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!