<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Correct Way to set up OpenVPN Client on Mac OS X</title>
	<atom:link href="http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/</link>
	<description>Thoughts, Projects, Happenings, Ideas</description>
	<lastBuildDate>Thu, 29 Jul 2010 15:36:37 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Wes</title>
		<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/comment-page-1/#comment-1611</link>
		<dc:creator>Wes</dc:creator>
		<pubDate>Wed, 21 Apr 2010 05:02:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/#comment-1611</guid>
		<description>Using Tunnelblick 3.0 (Build 1437).  If you have the &quot;Set nameserver&quot; flag in the UI set then up scripts are not executed.  I added the following line to invoke the standard up script as part of tap-up-down.sh.  You may have Tunnelblick installed in a different directory, so modify, as appropriate.


up)
     # Invoke standard up script before setting tap0 to DHCP
     /Applications/Utilities/Tunnelblick.app/Contents/Resources/client.up.osx.sh $1



I&#039;ve put something in the down) section, but I&#039;m not sure it&#039;s needed.

This is a known issue in the current Tunnelblick builds (http://code.google.com/p/tunnelblick/wiki/KnownIssues).</description>
		<content:encoded><![CDATA[<p>Using Tunnelblick 3.0 (Build 1437).  If you have the &#8220;Set nameserver&#8221; flag in the UI set then up scripts are not executed.  I added the following line to invoke the standard up script as part of tap-up-down.sh.  You may have Tunnelblick installed in a different directory, so modify, as appropriate.</p>
<p>up)<br />
     # Invoke standard up script before setting tap0 to DHCP<br />
     /Applications/Utilities/Tunnelblick.app/Contents/Resources/client.up.osx.sh $1</p>
<p>I&#8217;ve put something in the down) section, but I&#8217;m not sure it&#8217;s needed.</p>
<p>This is a known issue in the current Tunnelblick builds (<a href="http://code.google.com/p/tunnelblick/wiki/KnownIssues" rel="nofollow">http://code.google.com/p/tunnelblick/wiki/KnownIssues</a>).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/comment-page-1/#comment-1587</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 24 Feb 2010 16:18:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/#comment-1587</guid>
		<description>scutil –dns does not work on 10.4</description>
		<content:encoded><![CDATA[<p>scutil –dns does not work on 10.4</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Correct way to set up OpenVPN client on Mac OSX &#124; Nixadmins.net</title>
		<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/comment-page-1/#comment-1499</link>
		<dc:creator>Correct way to set up OpenVPN client on Mac OSX &#124; Nixadmins.net</dc:creator>
		<pubDate>Sat, 24 Oct 2009 13:47:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/#comment-1499</guid>
		<description>[...] So checkout the article at http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/ [...]</description>
		<content:encoded><![CDATA[<p>[...] So checkout the article at <a href="http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/" rel="nofollow">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: brent</title>
		<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/comment-page-1/#comment-1186</link>
		<dc:creator>brent</dc:creator>
		<pubDate>Mon, 07 Jul 2008 18:50:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/#comment-1186</guid>
		<description>We use the webmin plugin (OpenVPN + CA) to manage 3 instances of OpenVPN and two CAs.  It&#039;s very easy to use - although requires that the CA reside on the OpenVPN server, which could lack some security.
I would recommend it.</description>
		<content:encoded><![CDATA[<p>We use the webmin plugin (OpenVPN + CA) to manage 3 instances of OpenVPN and two CAs.  It&#8217;s very easy to use &#8211; although requires that the CA reside on the OpenVPN server, which could lack some security.<br />
I would recommend it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rola</title>
		<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/comment-page-1/#comment-1178</link>
		<dc:creator>Rola</dc:creator>
		<pubDate>Wed, 18 Jun 2008 17:43:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/#comment-1178</guid>
		<description>Hi.

i&#039;m just a beginner in using openvpn, let alone using it on mac os. Can anyone point me to where i can find some documentation on how to set up the Certificate Authority (CA) and generate certificates and keys for an OpenVPN server and client?

Thanks</description>
		<content:encoded><![CDATA[<p>Hi.</p>
<p>i&#8217;m just a beginner in using openvpn, let alone using it on mac os. Can anyone point me to where i can find some documentation on how to set up the Certificate Authority (CA) and generate certificates and keys for an OpenVPN server and client?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hartleigh</title>
		<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/comment-page-1/#comment-978</link>
		<dc:creator>Hartleigh</dc:creator>
		<pubDate>Thu, 24 Jan 2008 04:58:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/#comment-978</guid>
		<description>Fixed it!

I removed the down ./tap-up-down.sh line from the config file and now everything works as it should. Config file now looks like this...

&lt;i&gt;verb 1
client
dev tap
proto udp
remote xxx.xxx.xxx.xxx 1194
ca &quot;ca.crt&quot;
tls-auth &quot;ta.key&quot; 1
comp-lzo
auth-user-pass
&lt;/i&gt;&lt;i&gt;up ./tap-up-down.sh&lt;/i&gt;</description>
		<content:encoded><![CDATA[<p>Fixed it!</p>
<p>I removed the down ./tap-up-down.sh line from the config file and now everything works as it should. Config file now looks like this&#8230;</p>
<p><i>verb 1<br />
client<br />
dev tap<br />
proto udp<br />
remote xxx.xxx.xxx.xxx 1194<br />
ca &#8220;ca.crt&#8221;<br />
tls-auth &#8220;ta.key&#8221; 1<br />
comp-lzo<br />
auth-user-pass<br />
</i><i>up ./tap-up-down.sh</i></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hartleigh</title>
		<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/comment-page-1/#comment-976</link>
		<dc:creator>Hartleigh</dc:creator>
		<pubDate>Thu, 24 Jan 2008 02:11:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/#comment-976</guid>
		<description>Hi there,

I am glad in a way that others are having problems with Tunnelblick... I am not able to get this fix working. I have saved the script you provided and made it executable...

&lt;i&gt;ITD001:~/Library/openvpn hburton$ ls -la
total 56
drwxr-xr-x    7 hburton  hburton   238 Jan 24 12:01 .
drwx------   40 hburton  hburton  1360 Jan 24 08:03 ..
-rw-r--r--    1 hburton  hburton  6148 Jan 24 10:49 .DS_Store
-rwxrwxrwx    1 hburton  hburton  1237 Feb 20  2006 ca.crt
-rw-r--r--    1 root     wheel     164 Jan 24 12:01 openvpn.conf
-rwxrwxrwx    1 hburton  hburton   636 Feb 20  2006 ta.key
&lt;b&gt;-rwxr-xr-x    1 hburton  hburton  4339 Jan 24 10:46 tap-up-down.sh&lt;/b&gt;&lt;/i&gt;

Edited my configuration file so it has the required changes...

&lt;i&gt;verb 1
client
dev tap
proto udp
remote xxx.xxx.xxx.xxx 1194
ca &quot;ca.crt&quot;
tls-auth &quot;ta.key&quot; 1
comp-lzo
auth-user-pass
&lt;b&gt;up ./tap-up-down.sh
down ./tap-up-down.sh&lt;/b&gt;&lt;/i&gt;

Previously Tunnelblick would ask for my username/password then establish a connection with the server and give the code=5 error message. However now with this new script in place it will not even attempt to connect. When I press the connect button it will briefly flash to connecting and then back to disconnected with no ouput to the log at all. I am using v3.0b6 on OSX 10.4.11. If anyone has any details that might help it would be greatly appreciated.</description>
		<content:encoded><![CDATA[<p>Hi there,</p>
<p>I am glad in a way that others are having problems with Tunnelblick&#8230; I am not able to get this fix working. I have saved the script you provided and made it executable&#8230;</p>
<p><i>ITD001:~/Library/openvpn hburton$ ls -la<br />
total 56<br />
drwxr-xr-x    7 hburton  hburton   238 Jan 24 12:01 .<br />
drwx&#8212;&#8212;   40 hburton  hburton  1360 Jan 24 08:03 ..<br />
-rw-r&#8211;r&#8211;    1 hburton  hburton  6148 Jan 24 10:49 .DS_Store<br />
-rwxrwxrwx    1 hburton  hburton  1237 Feb 20  2006 ca.crt<br />
-rw-r&#8211;r&#8211;    1 root     wheel     164 Jan 24 12:01 openvpn.conf<br />
-rwxrwxrwx    1 hburton  hburton   636 Feb 20  2006 ta.key<br />
<b>-rwxr-xr-x    1 hburton  hburton  4339 Jan 24 10:46 tap-up-down.sh</b></i></p>
<p>Edited my configuration file so it has the required changes&#8230;</p>
<p><i>verb 1<br />
client<br />
dev tap<br />
proto udp<br />
remote xxx.xxx.xxx.xxx 1194<br />
ca &#8220;ca.crt&#8221;<br />
tls-auth &#8220;ta.key&#8221; 1<br />
comp-lzo<br />
auth-user-pass<br />
<b>up ./tap-up-down.sh<br />
down ./tap-up-down.sh</b></i></p>
<p>Previously Tunnelblick would ask for my username/password then establish a connection with the server and give the code=5 error message. However now with this new script in place it will not even attempt to connect. When I press the connect button it will briefly flash to connecting and then back to disconnected with no ouput to the log at all. I am using v3.0b6 on OSX 10.4.11. If anyone has any details that might help it would be greatly appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/comment-page-1/#comment-927</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Thu, 10 Jan 2008 05:15:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/#comment-927</guid>
		<description>I also am having the same issue on 10.5.1 Justin. Any headway? I wish I could get this working.</description>
		<content:encoded><![CDATA[<p>I also am having the same issue on 10.5.1 Justin. Any headway? I wish I could get this working.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin</title>
		<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/comment-page-1/#comment-918</link>
		<dc:creator>Justin</dc:creator>
		<pubDate>Tue, 08 Jan 2008 20:19:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/#comment-918</guid>
		<description>Hi - Thanks for positing!

I tried this on leopard using tunnelblick 3.0b6 but am still getting the tap/tun error=5 errors.  The output from scutil --dns also doesn&#039;t seem to change.  

Have you tried this fix on leopard?  Any help would be greatly appreciated!

Thanks!</description>
		<content:encoded><![CDATA[<p>Hi &#8211; Thanks for positing!</p>
<p>I tried this on leopard using tunnelblick 3.0b6 but am still getting the tap/tun error=5 errors.  The output from scutil &#8211;dns also doesn&#8217;t seem to change.  </p>
<p>Have you tried this fix on leopard?  Any help would be greatly appreciated!</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karel Minarik</title>
		<link>http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/comment-page-1/#comment-719</link>
		<dc:creator>Karel Minarik</dc:creator>
		<pubDate>Fri, 30 Nov 2007 15:03:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.mccambridge.org/blog/2007/10/correct-way-to-set-up-openvpn-client-on-mac-os-x/#comment-719</guid>
		<description>Hi,

thank you very much! Works absolutely brilliant :)

(Maybe just add reminder to chmod +x the .sh script, so people like me don&#039;t forget to do that :))

Cheers,

Karel</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>thank you very much! Works absolutely brilliant :)</p>
<p>(Maybe just add reminder to chmod +x the .sh script, so people like me don&#8217;t forget to do that :))</p>
<p>Cheers,</p>
<p>Karel</p>
]]></content:encoded>
	</item>
</channel>
</rss>
