Commit Graph

737 Commits

Author SHA1 Message Date
Jack Ivanov
79f66b7fda Update README.md. Fixes #259
`python-setuptools` is a recommended packages for which will be installed automatically for `python-pip` on a clean ubuntu 16.04
Updated README in order to avoid skipping the packages with `--no-install-recommends`
2017-02-25 21:17:48 +03:00
Craig
43c2f5c31a Installs the recommended packages with strongswan, because we need the OpenSSL (#260)
plugin from libstrongswan-standard-plugins for ECDH to work.
2017-02-25 21:07:32 +03:00
Jack Ivanov
b8f3d43eee enable some additional debug info 2017-02-23 19:22:18 +03:00
Jack Ivanov
2a7dd88a3c Changed to ECDSA #102 2017-02-23 18:44:30 +03:00
Jack Ivanov
e31f10da6d Fixes #255 2017-02-23 18:25:46 +03:00
Dan Guido
d271b60b6a Update algo 2017-02-20 03:40:40 +01:00
Dan Guido
23d69da528 add warning about os security enhancements 2017-02-20 03:28:32 +01:00
Jack Ivanov
aca036142f AndroidVPNClientProfiles #240 2017-02-17 00:30:21 +03:00
Jacob Wilder
7b468fae79 Fixed the azure role for situations where the user does not use a ~/.azure/credentials file (#242) 2017-02-16 23:43:03 +03:00
Jack Ivanov
9a5801f434 contgrats fix in update-users #243 2017-02-15 18:49:42 +03:00
Jack Ivanov
b11015508f Update README.md (#241) 2017-02-14 18:42:12 +01:00
Jack Ivanov
6cc3598cc6 rewrite congrats 2017-02-14 20:26:04 +03:00
Dan Guido
8bbccc3cb9 Update README.md 2017-02-14 17:42:54 +01:00
Dan Guido
79116f898a Update README.md 2017-02-14 17:39:58 +01:00
Dan Guido
90d56aaea3 remove twitter button :-( 2017-02-13 10:10:50 +01:00
Dan Guido
dd3b9b9a18 twitter badge 2017-02-13 09:57:45 +01:00
Jack Ivanov
20ebd7a595 rename connection 2017-02-12 23:01:29 +03:00
akirilov
05ab1f5feb Modified certificate generation to address issues #234 and #228 (#235)
* Modified certificate generation to address issues #234 and #228

I have made the following modifications to comply with the IKEv2 client certificate requirements:

- Changed client certificate CN to {{ IP_subject_alt_name }}_{{ item }} from {{ item }}
- Changed client certificate SAN to {{IP_subject_alt_name }} from {{ item }}
- Added clientAuth to client certificate EKU

I have made the following changes to address a mismatch in the windows deployment script and file names:

- Changed the client certificate (.p12) filename in config/{{ IP_subject_alt_name }} to {{ IP_subject_alt_name}}_{{ item }}.p12 from {{ item }}.p12 to match the ps1 script

Testing:

I have tested the changes on Windows 10 client, Ubuntu 16.04.1 server (DigitalOcean) - the config described in Issue #234

I apologize for not being able to test on other configurations. I hope that someone else can verify my changes

* fixed iOS issues

* fixed accidentall user change

* simplified changes

* Final iteration. I think that's all I can do to minimize the changes
2017-02-12 22:45:36 +03:00
Dan Guido
0422fe4c9e typo 2017-02-12 13:13:24 -05:00
Dan Guido
d334e42048 explicit pointer to avenues for support 2017-02-12 13:07:13 -05:00
Dan Guido
4567d280f7 Update README.md 2017-02-07 17:31:13 -05:00
Dan Guido
f0d10b200a Update README.md 2017-02-07 17:30:15 -05:00
Dan Guido
013a3ca321 TOC 2017-02-07 17:29:17 -05:00
Dan Guido
a94c427596 Move FAQ to its own doc. 2017-02-07 17:27:13 -05:00
Dan Guido
d9b13cbd45 Update CONTRIBUTING.md 2017-02-07 17:08:44 -05:00
Dan Guido
2f9417e659 Update Troubleshooting.md 2017-02-07 17:02:18 -05:00
Dan Guido
e95ee10c3c slightly better docs 2017-02-07 17:01:31 -05:00
Dan Guido
2559c264c6 Slightly better docs 2017-02-07 16:46:58 -05:00
Dan Guido
26168f10a0 Closes #82, again 2017-02-07 16:35:23 -05:00
Jack Ivanov
35faf4bca7 Local openssl tasks (#169)
* Draft

works with ECDSA

RSA support for Windows

* update-users with local_openssl_tasks

* move prompts to the algo script

* additional directory for SSH keys

* move easyrsa_p12_export_password to pre_tasks

* update-users testing

* Fix hardcoded vars

* Delete the CA key

* Hardcoded IP. Fixes #219

* Some fixes
2017-02-03 14:24:02 -05:00
Jack Ivanov
257be0f395 make the fail message more understandable. Fixes #217 2017-02-01 18:54:47 +03:00
Jack Ivanov
8d21923b70 Additional info in the congrats 2017-01-26 20:01:06 +03:00
Jack Ivanov
569df11088 Prevent ansible and Jinja2 from updates #220 (#221) 2017-01-22 23:06:32 +03:00
Jack Ivanov
2027d23c55 Update README.md 2017-01-22 22:56:17 +03:00
Jack Ivanov
2798f84d3f ensure that apparmor is supported by the kernel #215 2017-01-16 00:19:57 +03:00
Jack Ivanov
1681b98eb2 update the troubleshooting page #146 2017-01-14 20:27:18 +03:00
Jack Ivanov
ea4e82d66d move troubleshooting from the landing readme page 2017-01-14 20:07:52 +03:00
Jack Ivanov
3e852caf04 disable compression #146 2017-01-14 19:56:23 +03:00
Jack Ivanov
c84abee047 increase timeouts 2017-01-14 19:38:21 +03:00
Jack Ivanov
d23c952a4e Add the algo ssh key to any server (prevent fails when a user wants to update-users on a server deployed by algo but not with the algo ssh key) 2017-01-14 19:38:21 +03:00
Tonimir Kisasondi
38914fb827 Updated README.md (#214)
Just added -y to apt-get so it doesn't prompt for prerequisites install.
2017-01-12 21:14:05 -05:00
Jack Ivanov
97dc868d2c Update README.md 2017-01-11 23:35:29 +03:00
Jack Ivanov
35f322aa4a Do your job, travis! 2017-01-11 23:29:30 +03:00
Jack Ivanov
0a4e19a6d2 TravisCI initial. Testing all the components except the cloud roles. #154 2017-01-11 23:20:47 +03:00
Jack Ivanov
cbf59addb3 additional tags 2017-01-11 21:02:41 +03:00
Jack Ivanov
a50a396b94 addtiional fixes 2017-01-11 20:55:44 +03:00
Jack Ivanov
88518240fc Fix for the local installation 2017-01-11 20:55:07 +03:00
Jack Ivanov
d8bd42c18c Merge pull request #209 from trailofbits/ec2encryption #133
EC2 encrypted volume support
2017-01-10 19:26:33 +03:00
Jack Ivanov
2598d58746 Update ADVANCED.md 2017-01-10 19:04:29 +03:00
Jack Ivanov
a93b0a0f44 skip encrypted by default #133 2017-01-10 18:55:59 +03:00