talas-group/04_INFRA_DEPLOIEMENT/Ansible/roles/openvpn/defaults/main.yml
senke 66471934af Initial commit: Talas Group project management & documentation
Knowledge base of ~80+ markdown files across 14 domains (00-13),
Logseq graph, hardware design files (KiCAD), infrastructure configs,
and talas-wiki static site.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-04 20:10:41 +02:00

30 lines
997 B
YAML

---
# file: roles/openvpn/defaults/main.yml
openvpn_port: 443
openvpn_proto: tcp6
openvpn_ssl_root: "/usr/local/etc/tls/openvpn"
openvpn_ca: "{{ openvpn_ssl_root }}/ca.crt"
openvpn_crl: "{{ openvpn_ssl_root }}/crl.pem"
openvpn_cert: "{{ openvpn_ssl_root }}/{{ ansible_hostname }}.crt"
openvpn_key: "{{ openvpn_ssl_root }}/{{ ansible_hostname }}.key"
openvpn_dh: "{{ openvpn_ssl_root }}/dh2048.pem"
openvpn_max_clients: 10
openvpn_ldap_auth: False
openvpn_client2client: False
openvpn_ccd: False
openvpn_client_scripts: False
openvpn_verb: 4
openvpn_ldap_TLSCACertFile: "/usr/local/share/ca-certificates/CosiumRootCA.crt"
openvpn_ldap_BaseDN: "ou=people,dc=cosium,dc=com"
openvpn_ldap_SearchFilter: "(&(uid=%u)(CosStatus=active)(RemoteAccess=OpenVPN:*))"
openvpn_ldap_BindDN: "uid={{ ansible_hostname }},ou=servers,dc=cosium,dc=com"
openvpn_ldap_Password: "{{ ldappass }}"
openvpn_ldap_TLSEnable: True
router_ipv6: False
openvpn_script_debug: "false"
openvpn_force_insecure_compression: False