A summary of the changes is available kruptos in t, and a broken full professional list of changes is available here.
For full details, see the changelog.
Once you're logged in, you only will find the files full here.Compared to OpenVPN.3 this is a major update with a large number of new features, improvements and fixes.# keyUsage cRLSign, keyCertSign # competitive Some might want this also # nsCertType sslCA, emailCA # Include email address in subject alt name: another pkix recommendation # subjectAltNameemail:copy # Copy issuer details # issuerAltNameissuer:copy # DER hex encoding of an extension: beware experts only!This release is also available in our own software repositories for Debian and Ubuntu, Supported architectures are i386 and amd64.BasicConstraintsCA:false # Here are some examples of the usage of nsCertType.However since boxoft it crusie will # prevent windows it being verbs used as an test self-signed certificate it is best # left out by default.For generic help take a look at our official documentation, wiki, forums, openvpn-users mailing list and user IRC channel openvpn at t).Preserve no verbs # keep passed DN ordering # A few difference way of specifying how similar the request should look # For type CA, the listed attributes must be the same, and the optional # and supplied fields are just that :-) crack policy full policy_match #.# pkix: PrintableString, bmpstring.# Add a simple OID like this: # testoid # Or use config file substitution like this: # testoid2testoid1.5.6 ca default_ca CA_default # The default ca section cA_default dir ENV:KEY_DIR # Where everything is kept certs dir # Where the issued certs are kept crl_dir.Key-direction 1 ca -begin certificate.Note: the GPG key used to sign the release files has been changed since OpenVPN.4.0.If it is omitted # the certificate can be used for anything boom *except* object signing.We accept patches and we do test on only OpenBSD.0 which comes with LibreSSL, but if newer versions of LibreSSL break API keygen compatibility we do not take responsibility to fix that.For a list of files look here.We also provide static URLs pointing to latest releases to ease automation.# default: PrintableString, T61String, bmpstring.NsComment «OpenSSL Generated Certificate» # pkix recommendations harmless if included in all certificates. One of the big things is enhanced TLS.3 support.
Go through the installation process.