Request for feedback: Unbundling easy-rsa on Windows

This forum is for admins who are looking to build or expand their OpenVPN setup.

Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech

Forum rules
Please use the [oconf] BB tag for openvpn Configurations. See viewtopic.php?f=30&t=21589 for an example.
Post Reply
User avatar
flichtenheld
OpenVPN Inc.
Posts: 23
Joined: Fri Oct 28, 2022 3:25 pm

Request for feedback: Unbundling easy-rsa on Windows

Post by flichtenheld » Mon Feb 19, 2024 2:13 pm

Hi.

This is a request for feedback from OpenVPN Windows users by
the OpenVPN development team.

The Windows installers for OpenVPN 2 provided by the OpenVPN
community (i.e. https://openvpn.net/community-downloads/)
currently include a copy of the Easy-RSA project
(https://github.com/OpenVPN/easy-rsa) which provides a script
to easily manage a Certificate Authority and certificates.
Since Easy-RSA is implemented for POSIX shells it also ships
with its own executables that implement the required
functionality on Windows. This runtime environment is old
and we need to update it since it causes problems on
Windows 11 in some circumstances.

We thought this would be a good opportunity to ask whether
anyone is actually interested in the bundled Easy-RSA. Do
you run OpenVPN as a server on Windows and use the bundled
Easy-RSA for your PKI management? Or you do not use OpenVPN
as a server but you still have a use for the bundled
Easy-RSA? Then we would like to hear from you and learn more
about your use-case.

We assume that in most cases it is much easier to run Easy-RSA
in a native Linux environment like WSL (or other VMs) or use a
much better maintained POSIX environment like Git-Bash. Also
we assume that very few users actually run OpenVPN as a server
on Windows in the first place.

But maybe we're wrong? Please let us know.

Frank Lichtenheld (for the OpenVPN developers)
Frank Lichtenheld
DevOps Engineer
OpenVPN, Inc.

Post Reply