diff --git a/openvpn-install.sh b/openvpn-install.sh index b3cfba3..6e4085c 100644 --- a/openvpn-install.sh +++ b/openvpn-install.sh @@ -519,6 +519,8 @@ else ./easyrsa --batch revoke "$client" ./easyrsa --batch --days=3650 gen-crl rm -f /etc/openvpn/server/crl.pem + rm -f /etc/openvpn/server/easy-rsa/pki/reqs/"$client".req + rm -f /etc/openvpn/server/easy-rsa/pki/private/"$client".key cp /etc/openvpn/server/easy-rsa/pki/crl.pem /etc/openvpn/server/crl.pem # CRL is read with each client connection, when OpenVPN is dropped to nobody chown nobody:"$group_name" /etc/openvpn/server/crl.pem