Presidente, perdona loro perche` non sanno quello che dicono.
Da "man openvpn"
--client-cert-not-required
Don't require client certificate, client will authenticate using
username/password only. Be aware that using this directive is
less secure than requiring certificates from all clients.
--secret file [direction]
Enable Static Key encryption mode (non-TLS). Use pre-shared
secret file which was generated with --genkey.
[...]
The OpenVPN distribution contains a set of scripts for managing RSA
certificates & keys, located in the easy-rsa subdirectory.
E il problema dei certificati mi pare di capire che non sono gestiti internamente
da opnvpn, ma si appoggiano su un'infrastruttura esterna.
Sempre sui vari posto openvpn ho trovato questo:
You can create a new certificate authority and user certificates
from System: Trust. It should be relatively easy to mimic the
settings of the expired certificates. You can view them from there,
too.
Generating new certificate authorities entails switching user
certificates, or finding the right options to ignore the expiry
within OpenVPN itself. We, however, don't recommend this.
Questo signore spiega bene il problema (coincide con quanto leggo sul
manuale), ma nessuno gli ha risposto:
https://superuser.com/questions/1521168/how-to-allow-some-expired-client-certificates-in-openvpn
Quest'altro tipo invece si e` gia` bruciato e ora fa certificati che espirano piu` tardi:
https://delphinus.qns.net/xwiki/bin/view/Blog/Mikrotik%20expired%20certificate
/rubi 'gnurant che dovrebbe star zitto invece di dire boiate