OpenVPN技术问询:能否加密auth-user-pass参数指定的账号密码文件?
auth-user-pass Credentials File Great question—keeping your OpenVPN credentials out of plaintext is a smart move, and there are several reliable ways to pull this off. Let’s walk through the most practical methods:
1. On-the-Fly Decryption with a Script
Instead of handing OpenVPN a plaintext file directly, you can use a script that decrypts your encrypted credentials on the fly and feeds them to OpenVPN. Here’s how to set this up with GPG (a widely used encryption tool):
- First, encrypt your plaintext
credentials.txtfile:
This will prompt you for a passphrase and create an encryptedgpg -c credentials.txtcredentials.txt.gpgfile. Delete the plaintextcredentials.txtimmediately—no need to leave it lying around. - Next, create a simple bash script (name it something like
decrypt-creds.sh) that handles decryption:
Make the script executable with:#!/bin/bash gpg --batch --passphrase-fd 0 -d /full/path/to/credentials.txt.gpgchmod +x decrypt-creds.sh - Finally, update your OpenVPN command to use this script. The
--auth-user-pass-verifyflag tells OpenVPN to use the script to retrieve credentials:
When you run this, you’ll be prompted for your GPG passphrase, which decrypts the credentials temporarily just for OpenVPN to use.openvpn --auth-user-pass-verify /full/path/to/decrypt-creds.sh via-file --auth-nocache [your other flags]
2. Store Credentials on an Encrypted Filesystem
If you prefer a system-level approach, store your credentials file on an encrypted filesystem that you only mount when you need to use OpenVPN. This way, the credentials are encrypted on disk most of the time.
- On Linux, tools like
ecryptfsor LUKS work well. Here’s a quickecryptfsexample:- Create a directory and encrypt it:
Follow the prompts to set a passphrase and encryption settings (stick to the defaults if you’re unsure).mkdir ~/encrypted-openvpn-creds sudo mount -t ecryptfs ~/encrypted-openvpn-creds ~/encrypted-openvpn-creds - Copy your
credentials.txtinto the mounted, encrypted directory. - When you need to run OpenVPN, mount the directory first, run your OpenVPN command pointing to the file inside, then unmount it afterward:
sudo umount ~/encrypted-openvpn-creds
- Create a directory and encrypt it:
- For macOS, you can use Disk Utility to create an encrypted disk image, and for Windows, BitLocker or a third-party encrypted container tool works similarly.
3. Use a System Keyring to Avoid Files Altogether
Why store credentials in a file at all? You can use a system keyring (like GNOME Keyring, KWallet, or the pass password manager) to store your credentials securely, then pipe them directly to OpenVPN.
- Here’s how to do it with
pass(a lightweight, command-line password manager):- Store your OpenVPN credentials in
pass—enter your username first, then your password when prompted:pass insert openvpn/my-vpn-creds - Run OpenVPN and pipe the output of
passdirectly into it. This skips the file entirely:pass openvpn/my-vpn-creds | openvpn --auth-user-pass /dev/stdin [your other flags]
- Store your OpenVPN credentials in
- For desktop environments, you can also use GUI tools to store credentials in the system keyring and configure OpenVPN to pull from it directly (many OpenVPN GUI clients support this out of the box).
Critical Best Practices
- Never leave plaintext credentials lying around: After encrypting or moving them to a secure location, delete the original plaintext file and empty your trash/recycle bin.
- Lock down permissions: Any scripts or encrypted files should have strict permissions (e.g.,
chmod 700for scripts) so only your user can access them. - Be cautious with automated setups: If you’re running OpenVPN as a service and need automatic decryption, avoid storing decryption passphrases in plaintext. Use a hardware security key (like YubiKey) or a dedicated key file with restricted permissions instead.
内容的提问来源于stack exchange,提问作者gecharita

