将 OpenVPN 与 systemd 结合使用

Ror*_*raΖ 28 debian configuration systemd openvpn

好的,所以我一直在网上搜索此问题的解决方案,但似乎没有任何答案对我有用。希望有人可以帮助我。我只是想配置 OpenVPN 客户端。

我正在跑步CrunchBang Linux 3.2.0-4-amd64 Debian 3.2.60-1+deb7u1 x86_64 GNU/Linux,我刚刚切换到使用systemd. 转换进行得足够顺利,但现在我无法使用 systemd 启动我的 OpenVPN 客户端,我尝试按照这些配置教程进行操作,但没有任何效果。

我可以从命令行使用openvpn /etc/openvpn/vpn.conf. 所以我知道配置文件很好,它与 sysvinit 一起工作得很好,所以我并不感到惊讶。然后我尝试只做一个状态,systemctl status openvpn@vpn.service结果是:

$ sudo systemctl status openvpn@vpn.service
  openvpn@vpn.service
Loaded: error (Reason: No such file or directory)
Active: inactive (dead)
Run Code Online (Sandbox Code Playgroud)

我意识到我需要为服务做一些设置。我想被提示输入密码,所以我按照本指南创建了一个openvpn@.servicein /etc/systemd/system/. 但是重新启动 OpenVPN 服务仍然不会提示输入密码。

$ sudo service openvpn restart
[ ok ] Restarting openvpn (via systemctl): openvpn.service.
Run Code Online (Sandbox Code Playgroud)

Fedora 教程完成了创建符号链接的步骤,但不会在演练中创建任何 .service 文件。

我错过了什么片段?我需要创建一个 openvpn@vpn.service 吗?如果是这样,我应该把它放在哪里?我觉得这不应该这么困难,但我似乎找不到任何适合我的解决方案。我很乐意提供更多需要的信息。

解决方案

-rw-r--r--  1 root root   319 Aug  7 10:42 openvpn@.service

[Unit]
Description=OpenVPN connection to %i
After=network.target

[Service]
Type=forking
ExecStart=/usr/sbin/openvpn --daemon ovpn-%i --status /run/openvpn/%i.status 10 --cd /etc/openvpn --config /etc/openvpn/%i.conf
ExecReload=/bin/kill -HUP $MAINPID
WorkingDirectory=/etc/openvpn

[Install]
WantedBy=multi-user.target
openvpn@.service (END)
Run Code Online (Sandbox Code Playgroud)

符号链接:

lrwxrwxrwx  1 root root   36 Aug  7 10:47 openvpn@vpn.service -> /lib/systemd/system/openvpn@.service
Run Code Online (Sandbox Code Playgroud)

提示输入密码

现在一切正常,除了提示输入密码进行连接。我已经尝试过这个解决方案。我稍微调整了上面的文件,并添加了一个像示例中那样的Expect 脚本。像魅力一样工作!我的文件在下面。

从上面修改的行 /lib/systemd/system/openvpn@.service

ExecStart=/usr/sbin/openvpn --daemon ovpn-%i --status /run/openvpn/%i.status 10 --cd /etc/openvpn --management localhost 5559 --management-query-passwords --management-forget-disconnect --config /etc/openvpn/%i.conf
ExecStartPost=/usr/bin/expect /lib/systemd/system/openvpn_pw.exp
Run Code Online (Sandbox Code Playgroud)

期待脚本/lib/systemd/system/openvpn_pw.exp。确保执行以下操作:

  • chmod +x 在剧本上。
  • 已telnet安装

期望脚本的代码:

#!/usr/bin/expect
set pass [exec /bin/systemd-ask-password "Please insert Private Key password: "]

spawn telnet 127.0.0.1 5559
expect "Enter Private Key Password:"
send "password 'Private Key' $pass\r"
expect "SUCCESS: 'Private Key' password entered, but not yet verified"
send "exit\r"
expect eof
Run Code Online (Sandbox Code Playgroud)

需要注意的是,上面的解决方案确实会记录您在以下登录中以明文形式输入的密码/var/log/syslog和/var/log/daemon.log

der*_*ert 13

我认为使用 systemd 的 Debian OpenVPN 设置目前有点坏。为了让它在我的机器上工作,我必须:

  1. 创建/etc/systemd/system/openvpn@.service.d(目录),并在其中放置一个新文件:

    [单元]
    需要=networking.service
    After=networking.service
    我打电话给我的文件local-after-ifup.conf。它需要以.conf. (这是目前有点坏的位。)

  2. 在/etc/tmpfiles.d(我称之为我的local-openvpn.conf)中创建一个包含以下内容的文件:

    # 输入路径模式 UID GID 年龄参数
    d /run/openvpn 0755 root root - -
    这是Debian 错误 741938(已在 2.3.3-1 中修复)。

  3. 创建一个符号链接到multi-user.target.wants(最简单的方法是systemctl enable openvpn@CONF_NAME.service) 例如,如果你有/etc/openvpn/foo.conf,你会使用openvpn@foo.service.

  4. 如果您在 systemd 中还显示了 SysV init 脚本,请将其禁用。这是Debian 错误 700888(已在 2.3.3-1 中修复)。

注意:2.3.3-1 或更高版本尚未在测试中,尽管它处于不稳定状态。


gar*_*Red 8

这种类型的单元文件是一个实例化服务——更多细节在这里可用

以下是openvpnCentOS 7 上的单元文件:

[Unit]
Description=OpenVPN Robust And Highly Flexible Tunneling Application On %I
After=syslog.target network.target

[Service]
PrivateTmp=true
Type=forking
PIDFile=/var/run/openvpn/%i.pid
ExecStart=/usr/sbin/openvpn --daemon --writepid /var/run/openvpn/%i.pid --cd /etc/openvpn/ --config %i.conf

[Install]
WantedBy=multi-user.target
Run Code Online (Sandbox Code Playgroud)

它作为/usr/lib/systemd/system/openvpn@service. 该%i文件中被替换后的字符串@中的单位名称。

由于配置文件在/etc/openvpn/myopenvpn.conf然后服务启动:

systemctl start openvpn@myopenvpn.service
Run Code Online (Sandbox Code Playgroud)


小智 8

  1. 将所有 openvpn *.conf 文件放入/etc/openvpn/.
  2. 编辑/etc/default/openvpn。取消注释:

    AUTOSTART="all"
    
    Run Code Online (Sandbox Code Playgroud)
  3. 运行systemctl daemon-reload。

  4. 运行service openvpn start。


Kar*_*rlo 7

您需要通过启用openvpn@<configuration>.service.

例如,如果配置文件为/etc/openvpn/client.conf,则服务名称为openvpn@client.service。

来自 Arch 维基