# Specify that we are a client and that we # will be pulling certain config file directives # from the server. client # Use the same setting as you are using on # the server. # On most systems, the VPN will not function # unless you partially or fully disable # the firewall for the TUN/TAP interface. dev tun tun-ipv6 # Windows needs the TAP-Win32 adapter name # from the Network Connections panel # if you have more than one. On XP SP2, # you may need to disable the firewall # for the TAP adapter. ;dev-node MyTap # Are we connecting to a TCP or # UDP server? Use the same setting as # on the server. ;proto tcp proto udp # as of client version 2.5 specify cipher cipher BF-CBC # The hostname/IP and port of the server. # You can have multiple remote entries # to load balance between the servers. remote vpn.fit.vutbr.cz 1194 # Keep trying indefinitely to resolve the # host name of the OpenVPN server. Very useful # on machines which are not permanently connected # to the internet such as laptops. resolv-retry infinite # Most clients don't need to bind to # a specific local port number. nobind # Downgrade privileges after initialization (non-Windows only) ;user nobody ;group nobody # Try to preserve some state across restarts. persist-key persist-tun route-method exe route-delay 2 # Wireless networks often produce a lot # of duplicate packets. Set this flag # to silence duplicate packet warnings. ;mute-replay-warnings # SSL/TLS parms. #ca BUTCA.crt -----BEGIN CERTIFICATE----- MIIHXzCCBUegAwIBAgIJAK20be+vCLsQMA0GCSqGSIb3DQEBBQUAMIGqMQswCQYD VQQGEwJDWjENMAsGA1UEBwwEQnJubzEXMBUGA1UECAwOQ3plY2ggUmVwdWJsaWMx JjAkBgNVBAoMHUJybm8gVW5pdmVyc2l0eSBvZiBUZWNobm9sb2d5MSAwHgYDVQQL DBdDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTEpMCcGA1UEAwwgQnJubyBVbml2ZXJz aXR5IG9mIFRlY2hub2xvZ3kgQ0EwHhcNMDkwNzI4MTYzMTE5WhcNMjkwNzI4MTYz MTE5WjCBqjELMAkGA1UEBhMCQ1oxDTALBgNVBAcMBEJybm8xFzAVBgNVBAgMDkN6 ZWNoIFJlcHVibGljMSYwJAYDVQQKDB1Ccm5vIFVuaXZlcnNpdHkgb2YgVGVjaG5v bG9neTEgMB4GA1UECwwXQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkxKTAnBgNVBAMM IEJybm8gVW5pdmVyc2l0eSBvZiBUZWNobm9sb2d5IENBMIICIjANBgkqhkiG9w0B AQEFAAOCAg8AMIICCgKCAgEAqKVrRFJnGoWXKg/cTV7gNQpnwB9esa5HgE79/7fz vB7bMMUDLhEukVZDESyndfcuuo2E9894POj5iRhS6WXd5lCyQvCYysOXUYDwXpkp WL1F5TjI1Vf09J0oSIo7XxgE6JKR1xY7c7QD0E5VxAg4x56gQUQ0c9oAFVeabHJn 4AE4okC+k2sZHv6kr6AWeTx0CvlWgK9t+n1EmVfmOogyi1KaS1DfHOyQLSKK/M6H IT7nbAcWL3E/vWfpPzWYkN7xnCBtC43kaZqx39MGrSt9ns2bzcaxWC6w7oj7j1th 93lNFkvUPKgHpNZyC6YlAb+7z4NIM0vUPD349OxwyqvqV42YwikThlSf+EIG1W7H pKIsqsyLGqT4YsKV2m/okTgAFoLUORzX2UzbbWp6xBMV49wqMibIwnBRtscxYtn8 DprPRCr2nNh7Z4HWssBzkpY8KI5H9IQf2wcwB4Ezuk1tRIamwmCopjiUBtouAqSZ ynVkpWVEmeZ4hcpApxK4/Yz59hcNBL6aZycyG0wXHR4yvSeN30flniXhy1SQaF38 DgulH2vQNKSPAP+FlKMDC7MGw7xBD6T08gQKXbGY/eq9cn9lvGFPwlkUg9FnoZXz Optcrr6W0fZKE6gub2ztU6Lh0jxQt/FEeAfu5WGL06odGl8BDk/eUeCFnZqdgRcI CKUCAwEAAaOCAYQwggGAMA8GA1UdEwEB/wQFMAMBAf8wHQYDVR0OBBYEFDn5PlLI p8+1JOmYfP9OkHGaX1gGMB8GA1UdIwQYMBaAFDn5PlLIp8+1JOmYfP9OkHGaX1gG MA4GA1UdDwEB/wQEAwIBBjBeBgNVHSUEVzBVBggrBgEFBQcDAgYIKwYBBQUHAwEG CCsGAQUFBwMDBggrBgEFBQcDBAYIKwYBBQUHAwgGCisGAQQBgjcKAwQGCisGAQQB gjcKAwMGCWCGSAGG+EIEATAdBgNVHREEFjAUgRJjYS1hZG1AY2EudnV0YnIuY3ow EQYJYIZIAYb4QgEBBAQDAgAHMFAGCWCGSAGG+EIBDQRDFkFCcm5vIFVuaXZlcnNp dHkgb2YgVGVjaG5vbG9neSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSBDZXJ0aWZp Y2F0ZTA5BgNVHR8EMjAwMC6gLKAqhihodHRwOi8vY2EudnV0YnIuY3ovcGtpL3B1 Yi9jcmwvY2FjcmwuY3JsMA0GCSqGSIb3DQEBBQUAA4ICAQAjNHnF+FT8f7+Tvj/7 OIbKrp2kXsXuY1lp+O7zGkWaARn6jMGbW/cAOpdmDH244NrbHP0imale/fDAn3+7 T7mziWFV+sEoOwM7ohJ0tO2QxVDfG+Wak168rDhFYE4YWlTrw7LSIvHltw3aWdbF 0W/+PiS1A5R/1bP1ctJiQQjIuXagr0BL9F1DTFZeL2C3O6KuumhTeTiT0SIebUy2 oLo6P7RGpteRI3mb/r/zDMkmULkacMC2OMiWq6cWa6ldniqOUM7Tsdfy29nGMorr h8DqEog1ZIepnDoFj88jj6vs9maSRDLMdDnUxM69AeSDXME3O03CObEk6p0Fn0ig PBe9xcFeMFKGq0VwgywnVejcLym6tf7QvWsz+BeuroUMY8u9+WPf9RUtP7z1Tguc hPEpdCSRhXYbe0PXtR5XNCFI41Qfd98IRf1E2VpknpTzrMELAKL+30XUm6TVWJhk M8adgSjh0z+MsRU40mHzS5ZzapKbpOg8wBrp8gIVVNOtGrvOlNvHii1bWONDFHMn fPQ7pE5eQMqdMVnAa3hKyAnTyOPZk+UEas34AfEjAjjYK+5ONDj2ugNnIU1r+3hl thLasiDOmZpw+z0bOdr81ilrdDuUoygDF5MU+lSBv/ikq/cISjXxCJNnd+vhghb2 bY9iY2Rgvmn8UPJrHvACqSkZVQ== -----END CERTIFICATE----- auth-user-pass # Verify server certificate by checking # that the certicate has the nsCertType # field set to "server". ns-cert-type server # Enable compression on the VPN link. # Don't enable this unless it is also # enabled in the server config file. comp-lzo # Set log file verbosity. verb 3 # Silence repeating messages ;mute 20