mirror of
https://github.com/OpenVPN/openvpn.git
synced 2024-09-20 03:52:28 +02:00
110eee0288
Signed-off-by: Max Fillinger <maximilian.fillinger@foxcrypto.com> Acked-by: Gert Doering <gert@greenie.muc.de> Message-Id: <20220217142756.6581-1-maximilian.fillinger@foxcrypto.com> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg23825.html Signed-off-by: Gert Doering <gert@greenie.muc.de>
45 lines
1.4 KiB
Plaintext
45 lines
1.4 KiB
Plaintext
This version of OpenVPN has mbed TLS support. To enable follow the following
|
|
instructions:
|
|
|
|
To Build and Install,
|
|
|
|
./configure --with-crypto-library=mbedtls
|
|
make
|
|
make install
|
|
|
|
This version depends on mbed TLS 2.0 (and requires at least 2.0.0).
|
|
|
|
*************************************************************************
|
|
|
|
Warning:
|
|
|
|
As of mbed TLS 2.17, it can be licensed *only* under the Apache v2.0 license.
|
|
That license is incompatible with OpenVPN's GPLv2.
|
|
|
|
If you wish to distribute OpenVPN linked with mbed TLS, there are two options:
|
|
|
|
* Ensure that your case falls under the system library exception in GPLv2, or
|
|
|
|
* Use an earlier version of mbed TLS. Version 2.16.12 is the last release
|
|
that may be licensed under GPLv2. Unfortunately, this version is
|
|
unsupported and won't receive any more updates.
|
|
|
|
If nothing changes about the license situation, mbed TLS support may be
|
|
deprecated in a future release of OpenVPN.
|
|
|
|
*************************************************************************
|
|
|
|
Due to limitations in the mbed TLS library, the following features are missing
|
|
in the mbed TLS version of OpenVPN:
|
|
|
|
* PKCS#12 file support
|
|
* --capath support - Loading certificate authorities from a directory
|
|
* Windows CryptoAPI support
|
|
* X.509 alternative username fields (must be "CN")
|
|
|
|
Plugin/Script features:
|
|
|
|
* X.509 subject line has a different format than the OpenSSL subject line
|
|
* X.509 certificate export does not work
|
|
* X.509 certificate tracking
|