Gentoo Archives: gentoo-user

From: Bill Kenworthy <billk@×××××××××.au>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: openvpn and ipp.txt
Date: Sun, 04 Sep 2016 04:03:01
Message-Id: 37c6db5a-f3a9-b023-f828-445f12a8018c@iinet.net.au
In Reply to: [gentoo-user] Re: openvpn and ipp.txt by Ian Zimmerman
1 On 04/09/16 11:56, Ian Zimmerman wrote:
2 > On 2016-09-04 11:38, Bill Kenworthy wrote:
3 >
4 >> open vpn is set to run under the openvpn user and group (default
5 >> gentoo - drop privileges) It also creates a log file with the same
6 >> privileges as ipp.txt and logging is working ok. I've tried using
7 >> /etc/openvpn/ipp.txt (default, both with and without path specifier)
8 >> and /tmp/ipp.txt.
9 >
10 > Well, in my (working) setup I pre-created an empty ipp.txt file with
11 > permissions such as to allow access by the openvpn user. Not saying
12 > this is certainly the cause of your problem, but it may be.
13 >
14 > The location+name of the file is configurable with the
15 > ifconfig-pool-persist option, btw, so set it explicitly if you want to
16 > be sure it's used.
17 >
18
19 Hi Ian, it wasn’t permissions ... a closer look at detailed logs showed
20 I had duplicate-cn set (from a long time ago when I was testing) which
21 stops the persist method from working.
22
23 This explains why I new it worked at one point and didn’t know it had
24 stopped until recently.
25
26 Thanks,
27 BillK