openvpn/README.polarssl
Adriaan de Jong 7dd8bbf574 Disabled X.509 track and username selection for PolarSSL
Signed-off-by: Adriaan de Jong <dejong@fox-it.com>
Acked-by: James Yonan <james@openvpn.net>
Signed-off-by: David Sommerseth <davids@redhat.com>
2011-10-22 16:00:49 +02:00

29 lines
861 B
Plaintext

This version of OpenVPN has PolarSSL support. To enable follow the following
instructions:
To Build and Install,
./configure --with-ssl-type=polarssl
make
make install
This version depends on at least PolarSSL v0.99.
*************************************************************************
Due to limitations in the PolarSSL library, the following features are missing
in the PolarSSL version of OpenVPN:
* PKCS#12 file support
* --capath support - Loading certificate authorities from a directory
* Windows CryptoAPI support
* Management external key support
* X.509 alternative username fields (must be "CN")
Plugin/Script features:
* X.509 Serial number is in hex, not decimal as with OpenSSL
* X.509 subject line has a different format than the OpenSSL subject line
* X.509 certificate export does not work
* X.509 certificate tracking