File tree Expand file tree Collapse file tree 2 files changed +8
-11
lines changed Expand file tree Collapse file tree 2 files changed +8
-11
lines changed Original file line number Diff line number Diff line change @@ -454,12 +454,11 @@ which mode OpenVPN is configured as.
454
454
independently of network and tunnel issues.
455
455
456
456
--tmp-dir dir
457
- Specify a directory ``dir `` for temporary files. This directory will be
458
- used by openvpn processes and script to communicate temporary data with
459
- openvpn main process. Note that the directory must be writable by the
460
- OpenVPN process after it has dropped it's root privileges.
457
+ Specify a directory ``dir `` for temporary files instead of the default
458
+ :code: `TMPDIR ` (or "/tmp" if unset). Note that it must be writable by the main
459
+ process after it has dropped root privileges.
461
460
462
- This directory will be used by in the following cases :
461
+ This directory will be used to communicate with scripts and plugins :
463
462
464
463
* ``--client-connect `` scripts and :code: `OPENVPN_PLUGIN_CLIENT_CONNECT `
465
464
plug-in hook to dynamically generate client-specific configuration
@@ -469,7 +468,7 @@ which mode OpenVPN is configured as.
469
468
470
469
* :code: `OPENVPN_PLUGIN_AUTH_USER_PASS_VERIFY ` plug-in hooks returns
471
470
success/failure via :code: `auth_control_file ` when using deferred auth
472
- method and pending authentication via :code: `pending_auth_file `.
471
+ method and pending authentication via :code: `auth_pending_file `.
473
472
474
473
--use-prediction-resistance
475
474
Enable prediction resistance on mbed TLS's RNG.
Original file line number Diff line number Diff line change @@ -87,11 +87,9 @@ SCRIPT HOOKS
87
87
and password to the first two lines of a temporary file. The filename
88
88
will be passed as an argument to ``cmd ``, and the file will be
89
89
automatically deleted by OpenVPN after the script returns. The location
90
- of the temporary file is controlled by the ``--tmp-dir `` option, and
91
- will default to the current directory if unspecified. For security,
92
- consider setting ``--tmp-dir `` to a volatile storage medium such as
93
- :code: `/dev/shm ` (if available) to prevent the username/password file
94
- from touching the hard drive.
90
+ of the temporary file is controlled by the ``--tmp-dir `` option. For security,
91
+ consider setting it to a volatile storage medium such as :code: `/dev/shm ` (if
92
+ available) to prevent the username/password file from touching the hard drive.
95
93
96
94
The script should examine the username and password, returning a success
97
95
exit code (:code: `0 `) if the client's authentication request is to be
You can’t perform that action at this time.
0 commit comments