{"id":843,"date":"2017-06-30T23:48:45","date_gmt":"2017-07-01T02:48:45","guid":{"rendered":"http:\/\/wordpress.jpcorp.eti.br\/?p=843"},"modified":"2021-12-26T12:31:01","modified_gmt":"2021-12-26T15:31:01","slug":"pfsense-revogando-certificado-ce-para-conexoes-no-openvpn","status":"publish","type":"post","link":"https:\/\/wordpress.jpcorp.eti.br\/?p=843","title":{"rendered":"pfSense &#8211; Revogando certificado (CE) para conex\u00f5es no OpenVPN"},"content":{"rendered":"<p>Voc\u00ea tem um Server de OpenVPN ao qual fecha todas VPNs por chaves com certificado, ai chega a miss\u00e3o de revogar a chave do fulano que foi desligado, eai?<\/p>\n<p>&nbsp;<\/p>\n<h3>1 - Criar a lista de certificados revogados (CRL)<\/h3>\n<p><a href=\"http:\/\/wordpress.jpcorp.eti.br\/?attachment_id=844\" rel=\"attachment wp-att-844\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-844 size-full\" src=\"http:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-01.png\" alt=\"\" width=\"952\" height=\"269\" srcset=\"https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-01.png 952w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-01-300x85.png 300w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-01-768x217.png 768w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-01-644x182.png 644w\" sizes=\"auto, (max-width: 952px) 100vw, 952px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/wordpress.jpcorp.eti.br\/?attachment_id=848\" rel=\"attachment wp-att-848\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-848\" src=\"http:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-02.png\" alt=\"\" width=\"937\" height=\"530\" srcset=\"https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-02.png 937w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-02-300x170.png 300w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-02-768x434.png 768w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-02-644x364.png 644w\" sizes=\"auto, (max-width: 937px) 100vw, 937px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3>2 - Revogar o Certificado (CE)<\/h3>\n<p><a href=\"http:\/\/wordpress.jpcorp.eti.br\/?attachment_id=847\" rel=\"attachment wp-att-847\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-847\" src=\"http:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-03.png\" alt=\"\" width=\"1022\" height=\"328\" srcset=\"https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-03.png 1022w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-03-300x96.png 300w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-03-768x246.png 768w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-03-644x207.png 644w\" sizes=\"auto, (max-width: 1022px) 100vw, 1022px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/wordpress.jpcorp.eti.br\/?attachment_id=846\" rel=\"attachment wp-att-846\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-846\" src=\"http:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-04.png\" alt=\"\" width=\"1013\" height=\"490\" srcset=\"https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-04.png 1013w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-04-300x145.png 300w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-04-768x371.png 768w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-04-644x312.png 644w\" sizes=\"auto, (max-width: 1013px) 100vw, 1013px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3>3 - A cereja do bolo que nego quebra a cabe\u00e7a, \u00e9 necess\u00e1rio amarrar a lista de certificados revogados (CRL) no Server de OpenVPN<\/h3>\n<p><a href=\"http:\/\/wordpress.jpcorp.eti.br\/?attachment_id=845\" rel=\"attachment wp-att-845\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-845\" src=\"http:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-05.png\" alt=\"\" width=\"803\" height=\"491\" srcset=\"https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-05.png 803w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-05-300x183.png 300w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-05-768x470.png 768w, https:\/\/wordpress.jpcorp.eti.br\/wp-content\/uploads\/2017\/06\/ce-revoke-05-644x394.png 644w\" sizes=\"auto, (max-width: 803px) 100vw, 803px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3>4 - E abaixo o log apresentado quando o CE revogado tenta efetuar o handshake<\/h3>\n<pre class=\"lang:sh decode:true\">Jun 30 20:24:56\topenvpn\t22759 XXX.XX.X.X56:55785 OpenSSL: error:140890B2:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned\r\nJun 30 20:24:56\topenvpn\t22759 XXX.XX.X.X56:55785 TLS_ERROR: BIO read tls_read_plaintext error\r\nJun 30 20:24:56\topenvpn\t22759 XXX.XX.X.X56:55785 TLS Error: TLS object -&gt; incoming plaintext read error\r\nJun 30 20:24:56\topenvpn\t22759 XXX.XX.X.X56:55785 TLS Error: TLS handshake failed<\/pre>\n<p>&nbsp;<\/p>\n<p>Refer\u00eancia:<\/p>\n<p><a href=\"https:\/\/doc.pfsense.org\/index.php\/Certificate_Management\">https:\/\/doc.pfsense.org\/index.php\/Certificate_Management<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Voc\u00ea tem um Server de OpenVPN ao qual fecha todas VPNs por chaves com certificado, ai chega a miss\u00e3o de revogar a chave do fulano que foi desligado, eai? &nbsp; 1 &#8211; Criar a lista de certificados revogados (CRL) &nbsp; &nbsp; 2 &#8211; Revogar o Certificado (CE) &nbsp; &nbsp; 3 &#8211; A cereja do bolo&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[43],"tags":[33,44],"class_list":["post-843","post","type-post","status-publish","format-standard","hentry","category-pfsense","tag-openvpn","tag-pfsense"],"_links":{"self":[{"href":"https:\/\/wordpress.jpcorp.eti.br\/index.php?rest_route=\/wp\/v2\/posts\/843","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.jpcorp.eti.br\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.jpcorp.eti.br\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.jpcorp.eti.br\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.jpcorp.eti.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=843"}],"version-history":[{"count":7,"href":"https:\/\/wordpress.jpcorp.eti.br\/index.php?rest_route=\/wp\/v2\/posts\/843\/revisions"}],"predecessor-version":[{"id":855,"href":"https:\/\/wordpress.jpcorp.eti.br\/index.php?rest_route=\/wp\/v2\/posts\/843\/revisions\/855"}],"wp:attachment":[{"href":"https:\/\/wordpress.jpcorp.eti.br\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=843"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.jpcorp.eti.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=843"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.jpcorp.eti.br\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=843"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}