summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorRoy Marples <uberlord@gentoo.org>2006-05-09 09:21:41 +0000
committerRoy Marples <uberlord@gentoo.org>2006-05-09 09:21:41 +0000
commitc04e276b9f16c0a87687c32f052b28ba4f0b0792 (patch)
tree996b4343c78d08b54319c0feb50d8d38af0e58e6 /net-misc
parentMisc cleanup and add elibtoolize. (diff)
downloadhistorical-c04e276b9f16c0a87687c32f052b28ba4f0b0792.tar.gz
historical-c04e276b9f16c0a87687c32f052b28ba4f0b0792.tar.bz2
historical-c04e276b9f16c0a87687c32f052b28ba4f0b0792.zip
New upstream beta release with smartcard support (#118435).
We now add an openvpn user/group so you can drop root if you wish (#120425). If you use the remote keyword in your config then you are deemed to be a client and we force our up/down scripts to be used. These scripts start/stop any services depending on openvpn AND apply any DNS information to resolvconf or /etc/resolv.conf directly if resolvconf is not installed. Package-Manager: portage-2.1_pre10-r5
Diffstat (limited to 'net-misc')
-rw-r--r--net-misc/openvpn/ChangeLog14
-rw-r--r--net-misc/openvpn/Manifest28
-rw-r--r--net-misc/openvpn/files/digest-openvpn-2.1_beta143
-rwxr-xr-xnet-misc/openvpn/files/down.sh22
-rwxr-xr-xnet-misc/openvpn/files/openvpn-2.1.init104
-rwxr-xr-xnet-misc/openvpn/files/up.sh38
-rw-r--r--net-misc/openvpn/openvpn-2.1_beta14.ebuild143
7 files changed, 347 insertions, 5 deletions
diff --git a/net-misc/openvpn/ChangeLog b/net-misc/openvpn/ChangeLog
index 625c9ca65c9e..6737bf2d1192 100644
--- a/net-misc/openvpn/ChangeLog
+++ b/net-misc/openvpn/ChangeLog
@@ -1,6 +1,18 @@
# ChangeLog for net-misc/openvpn
# Copyright 2002-2006 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/net-misc/openvpn/ChangeLog,v 1.83 2006/05/05 15:27:05 uberlord Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-misc/openvpn/ChangeLog,v 1.84 2006/05/09 09:21:40 uberlord Exp $
+
+*openvpn-2.1_beta14 (09 May 2006)
+
+ 09 May 2006; Roy Marples <uberlord@gentoo.org> +files/openvpn-2.1.init,
+ +files/down.sh, +files/up.sh, +openvpn-2.1_beta14.ebuild:
+ New upstream beta release with smartcard support (#118435).
+ We now add an openvpn user/group so you can drop root if you wish (#120425).
+
+ If you use the remote keyword in your config then you are deemed to be a
+ client and we force our up/down scripts to be used. These scripts start/stop
+ any services depending on openvpn AND apply any DNS information to resolvconf
+ or /etc/resolv.conf directly if resolvconf is not installed.
05 May 2006; Roy Marples <uberlord@gentoo.org> files/openvpn.init:
Tweak init script to start before netmount.
diff --git a/net-misc/openvpn/Manifest b/net-misc/openvpn/Manifest
index 08afb5ce0f89..97fd692f1334 100644
--- a/net-misc/openvpn/Manifest
+++ b/net-misc/openvpn/Manifest
@@ -1,20 +1,37 @@
+AUX down.sh 601 RMD160 c9acda4179e57fac8e17446a06ff1884f654f2b1 SHA1 52cc19f28229610991d6a4dbde71d510a06c7213 SHA256 06055424721ee5a6aa37aa9a6dca081de27d1c7c3ef5bde0033d99e0af4a9e1e size 601
+MD5 b9afdc27c5a22753eeb4b347dcfa3cde files/down.sh 601
+RMD160 c9acda4179e57fac8e17446a06ff1884f654f2b1 files/down.sh 601
+SHA256 06055424721ee5a6aa37aa9a6dca081de27d1c7c3ef5bde0033d99e0af4a9e1e files/down.sh 601
AUX openvpn-2.0.4-darwin.patch 717 RMD160 66aa5ea349329cf3e6089aa75eb7c80e0d21063b SHA1 ca21fbc61b78d893699b6bf4fb40eb2735db28c8 SHA256 ad70b77c10bb57a07af3d512e953fc8b5a07108df5bf9795e0cb12e1ba2b2136 size 717
MD5 9f0fcb64287dc55bb770ca86415e5cdd files/openvpn-2.0.4-darwin.patch 717
RMD160 66aa5ea349329cf3e6089aa75eb7c80e0d21063b files/openvpn-2.0.4-darwin.patch 717
SHA256 ad70b77c10bb57a07af3d512e953fc8b5a07108df5bf9795e0cb12e1ba2b2136 files/openvpn-2.0.4-darwin.patch 717
+AUX openvpn-2.1.init 3244 RMD160 31828a31b000367216d921759af45346ca1d4584 SHA1 4330efcbf4dbf22c61e295edfd5b171f6e4f7f7e SHA256 2c92ae82eba3a000c613fb50c099f9c2dd25fa663e39a434863b23692fb5e4e4 size 3244
+MD5 c59b44b9175dd76ede0d977921cef23a files/openvpn-2.1.init 3244
+RMD160 31828a31b000367216d921759af45346ca1d4584 files/openvpn-2.1.init 3244
+SHA256 2c92ae82eba3a000c613fb50c099f9c2dd25fa663e39a434863b23692fb5e4e4 files/openvpn-2.1.init 3244
AUX openvpn.init 1458 RMD160 38e1c7ef3197bbb5d9f7fc764f6ce5149387a4e6 SHA1 6b6aef1a95177f68c20623c07198abd421502ad9 SHA256 54f33e766a455baeb5f8e1e318ad3be5fb0b88450ffad98f90812d64baef5e04 size 1458
MD5 a66a9752a2dce48aa7061a535ef2ab4d files/openvpn.init 1458
RMD160 38e1c7ef3197bbb5d9f7fc764f6ce5149387a4e6 files/openvpn.init 1458
SHA256 54f33e766a455baeb5f8e1e318ad3be5fb0b88450ffad98f90812d64baef5e04 files/openvpn.init 1458
+AUX up.sh 1305 RMD160 aedd4ea014d130621809e146290565e365f0831a SHA1 76e7a44e4fa5246723ed88a6e1904b276e50e734 SHA256 5a468d45bb7c27ccff314715f7942bcd9e9a242330968ebf888fe014c344ba1d size 1305
+MD5 f0648af0045195f707574beac0d49061 files/up.sh 1305
+RMD160 aedd4ea014d130621809e146290565e365f0831a files/up.sh 1305
+SHA256 5a468d45bb7c27ccff314715f7942bcd9e9a242330968ebf888fe014c344ba1d files/up.sh 1305
DIST openvpn-2.0.6.tar.gz 664816 RMD160 cf3cd807bb657baf317e896b57900958cf442a63 SHA256 1074c9fb5a7881e6d4ff0b125cf1e44a9fb650beef187f061785698522453003 size 664816
+DIST openvpn-2.1_beta14.tar.gz 775042 RMD160 1c7845405b33153c1380aa48eaa88308a5eadd2c SHA256 da61d236047b9a5985765961930446a706aeef87dc2b4ce0f7e2c9f2831566ea size 775042
EBUILD openvpn-2.0.6.ebuild 3855 RMD160 8ea7fc436052eaedc29cab3d23a4786c64907214 SHA1 b89d1d8a5ad7d97644d042a1651d6d747678a006 SHA256 643a375dee682284d428aa84c25c8e2610e6e8b6c5e1f9a775dd8cf9cfadff89 size 3855
MD5 418f9c55fcaad0fbc9441a1afa298b37 openvpn-2.0.6.ebuild 3855
RMD160 8ea7fc436052eaedc29cab3d23a4786c64907214 openvpn-2.0.6.ebuild 3855
SHA256 643a375dee682284d428aa84c25c8e2610e6e8b6c5e1f9a775dd8cf9cfadff89 openvpn-2.0.6.ebuild 3855
-MISC ChangeLog 12385 RMD160 08c9da13c763d79bfa91ac69f9ca2fe0dfb7fb80 SHA1 cac1d7fe180d46b456f48e0ea38272a1b2d95dc7 SHA256 b2ee70fa92f05ee15b70294324669a0dd8dfbe62793cb87b3d868836dfb63ec6 size 12385
-MD5 586f081a002cccd8fb43d6f1bda866e2 ChangeLog 12385
-RMD160 08c9da13c763d79bfa91ac69f9ca2fe0dfb7fb80 ChangeLog 12385
-SHA256 b2ee70fa92f05ee15b70294324669a0dd8dfbe62793cb87b3d868836dfb63ec6 ChangeLog 12385
+EBUILD openvpn-2.1_beta14.ebuild 4224 RMD160 1fb5d3f1052d54639367ba5142a02a62ef3e5074 SHA1 ef2ed19ca8262de398cf5032b921af89cd1a0a72 SHA256 15a0cf630e2e4ee768a7263ca50362829d17227055f2fc2d50e387a5cfd98576 size 4224
+MD5 f11d0a54965ea04499a63774c8bca12f openvpn-2.1_beta14.ebuild 4224
+RMD160 1fb5d3f1052d54639367ba5142a02a62ef3e5074 openvpn-2.1_beta14.ebuild 4224
+SHA256 15a0cf630e2e4ee768a7263ca50362829d17227055f2fc2d50e387a5cfd98576 openvpn-2.1_beta14.ebuild 4224
+MISC ChangeLog 12994 RMD160 a48f28d4671f37c011d9824efe28416ab4f90c17 SHA1 21d1562032bac65f91b06d7ab9153b6335be10c8 SHA256 68beac6dcceef6ff18bbe7c1a1b668c49e7689a93fa1561d921d24d723e1dd9f size 12994
+MD5 b364c074d52f83f0b4a24ed054ec6123 ChangeLog 12994
+RMD160 a48f28d4671f37c011d9824efe28416ab4f90c17 ChangeLog 12994
+SHA256 68beac6dcceef6ff18bbe7c1a1b668c49e7689a93fa1561d921d24d723e1dd9f ChangeLog 12994
MISC metadata.xml 440 RMD160 120089ec9c799161dfeeacd9a3adfc40b4317f06 SHA1 23d2975ef0f709dc2e754a5867942e679ee60740 SHA256 408ca4fc4f58fa21e629582d0a44a759f9695a018479d70efbd3338b6bdbcfd6 size 440
MD5 62aa0438042b29eba4a6afd971037761 metadata.xml 440
RMD160 120089ec9c799161dfeeacd9a3adfc40b4317f06 metadata.xml 440
@@ -22,3 +39,6 @@ SHA256 408ca4fc4f58fa21e629582d0a44a759f9695a018479d70efbd3338b6bdbcfd6 metadata
MD5 9b5501be21ae9235fea7d51ef84b644e files/digest-openvpn-2.0.6 241
RMD160 3bca5f56e3526082debc843084ae21fe35e65f93 files/digest-openvpn-2.0.6 241
SHA256 cc2c7e3423898778eb6f6b45bdd4ba18d2a20be748cfa8482eba4ca20c2f80bd files/digest-openvpn-2.0.6 241
+MD5 9f3dee432a917a273baf3b721d3f01e2 files/digest-openvpn-2.1_beta14 256
+RMD160 8b38bd1027c85531c3483c2f290d37854f461750 files/digest-openvpn-2.1_beta14 256
+SHA256 2f60d11bdb0d5795151caf35752124cb849b1baf757f58aa1bb6aef2b67d2af6 files/digest-openvpn-2.1_beta14 256
diff --git a/net-misc/openvpn/files/digest-openvpn-2.1_beta14 b/net-misc/openvpn/files/digest-openvpn-2.1_beta14
new file mode 100644
index 000000000000..4f7bc1faa04f
--- /dev/null
+++ b/net-misc/openvpn/files/digest-openvpn-2.1_beta14
@@ -0,0 +1,3 @@
+MD5 7bd96eaa834a1779755d68c9b2591583 openvpn-2.1_beta14.tar.gz 775042
+RMD160 1c7845405b33153c1380aa48eaa88308a5eadd2c openvpn-2.1_beta14.tar.gz 775042
+SHA256 da61d236047b9a5985765961930446a706aeef87dc2b4ce0f7e2c9f2831566ea openvpn-2.1_beta14.tar.gz 775042
diff --git a/net-misc/openvpn/files/down.sh b/net-misc/openvpn/files/down.sh
new file mode 100755
index 000000000000..28ecd304ff20
--- /dev/null
+++ b/net-misc/openvpn/files/down.sh
@@ -0,0 +1,22 @@
+#!/bin/sh
+# Copyright (c) 2006 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# Contributed by Roy Marples (uberlord@gentoo.org)
+
+# If we have a service specific script, run this now
+if [[ -x /etc/openvpn/"${SVCNAME}"-down.sh ]] ; then
+ ( /etc/openvpn/"${SVCNAME}"-down.sh )
+fi
+
+# Setup our resolv.conf
+[[ -x /sbin/resolvconf ]] && /sbin/resolvconf -d "${dev}"
+
+# Re-enter the init script to start any dependant services
+if /etc/init.d/"${SVCNAME}" --quiet status ; then
+ export IN_BACKGROUND=true
+ /etc/init.d/"${SVCNAME}" --quiet stop
+fi
+
+exit 0
+
+# vim: ts=4 :
diff --git a/net-misc/openvpn/files/openvpn-2.1.init b/net-misc/openvpn/files/openvpn-2.1.init
new file mode 100755
index 000000000000..5f01ffca6781
--- /dev/null
+++ b/net-misc/openvpn/files/openvpn-2.1.init
@@ -0,0 +1,104 @@
+#!/sbin/runscript
+# Copyright 1999-2005 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+
+VPNDIR="${VPNDIR:-/etc/openvpn}"
+VPN="${SVCNAME##*.}"
+if [[ -n ${VPN} && ${SVCNAME} != "openvpn" ]]; then
+ VPNPID="/var/run/openvpn.${VPN}.pid"
+else
+ VPNPID="/var/run/openvpn.pid"
+fi
+VPNCONF="${VPNDIR}/${VPN}.conf"
+
+depend() {
+ need net
+}
+
+checkconfig() {
+ if [[ ! -e /dev/net/tun ]]; then
+ if ! modprobe tun ; then
+ eerror "TUN/TAP support is not available in this kernel"
+ return 1
+ fi
+ fi
+
+ if [[ ! -e "${VPNCONF}" ]]; then
+ eend 1 "${VPNCONF} does not exist"
+ return 1
+ fi
+}
+
+start() {
+ # If we are re-called by the openvpn gentoo-up.sh script
+ # then we don't actually want to start openvpn
+ [[ ${IN_BACKGROUND} == "true" ]] && return 0
+
+ ebegin "Starting ${SVCNAME}"
+
+ checkconfig || return 1
+
+ local args="" client=false
+ # If the config file does not specify the cd option, we do
+ # But if we specify it, we override the config option which we do not want
+ if ! grep -q "^[ \t]*cd[ \t].*" "${VPNCONF}" ; then
+ args="${args} --cd ${VPNDIR}"
+ fi
+
+ # We mark the service as inactive and then start it.
+ # When we get an authenticated packet from the peer then we run our script
+ # which configures our DNS if any and marks us as up.
+ if grep -q "^[ \t]*remote[ \t].*" "${VPNCONF}" ; then
+ client=true
+ args="${args} --nobind --up-delay --up-restart"
+ args="${args} --up /etc/openvpn/up.sh"
+ args="${args} --down /etc/openvpn/down.sh"
+
+ # Warn about setting scripts as we override them
+ if grep -Eq "^[ \t]*(up|down)[ \t].*" "${VPNCONF}" ; then
+ ewarn "WARNING: You have defined your own up/down scripts"
+ ewarn "As you're running as a client, we now force Gentoo specific"
+ ewarn "scripts to be run for up and down events."
+ ewarn "These scripts will call /etc/openvpn/${SVCNAME}-{up,down}.sh"
+ ewarn "where you can put your own code."
+ fi
+
+ # Warn about the inability to change ip/route/dns information when
+ # dropping privs
+ if grep -q "^[ \t]*user[ \t].*" "${VPNCONF}" ; then
+ ewarn "WARNING: You are dropping root privileges!"
+ ewarn "As such openvpn may not be able to change ip, routing"
+ ewarn "or DNS configuration."
+ fi
+ else
+ # So we're a server. Run as openvpn unless otherwise specified
+ grep -q "^[ \t]*user[ \t].*" "${VPNCONF}" || args="${args} --user openvpn"
+ grep -q "^[ \t]*group[ \t].*" "${VPNCONF}" || args="${args} --group openvpn"
+ fi
+
+ # Some generic options to improve reliability
+ args="${args} --persist-tun --persist-key"
+
+ if ${client} && [[ $(type -t mark_service_inactive) == "function" ]] ; then
+ mark_service_inactive "${SVCNAME}"
+ fi
+ start-stop-daemon --start --exec /usr/sbin/openvpn --pidfile "${VPNPID}" \
+ -- --config "${VPNCONF}" --writepid "${VPNPID}" --daemon ${args}
+ eend $? "Check your logs to see why startup failed"
+}
+
+stop() {
+ # If we are re-called by the openvpn gentoo-down.sh script
+ # then we don't actually want to stop openvpn
+ if [[ ${IN_BACKGROUND} == "true" ]] ; then
+ [[ $(type -t mark_service_inactive) == "function" ]] \
+ && mark_service_inactive "${SVCNAME}"
+ return 0
+ fi
+
+ ebegin "Stopping ${SVCNAME}"
+ start-stop-daemon --stop --exec /usr/sbin/openvpn --pidfile "${VPNPID}"
+ eend $?
+}
+
+# vim: ts=4
diff --git a/net-misc/openvpn/files/up.sh b/net-misc/openvpn/files/up.sh
new file mode 100755
index 000000000000..95dc6bc97b16
--- /dev/null
+++ b/net-misc/openvpn/files/up.sh
@@ -0,0 +1,38 @@
+#!/bin/sh
+# Copyright (c) 2006 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# Contributed by Roy Marples (uberlord@gentoo.org)
+
+# Setup our resolv.conf
+# Vitally important that we use the domain entry in resolv.conf so we
+# can setup the nameservers are for the domain ONLY in resolvconf if
+# we're using a decent dns cache/forwarder like dnsmasq and NOT nscd/libc.
+# nscd/libc users will get the VPN nameservers before their other ones
+# and will use the first one that responds - maybe the LAN ones?
+# non resolvconf users just the the VPN resolv.conf
+
+DNS="# Generated by openvpn for interface ${dev}\n
+ $( set | sed -n "s/^foreign_option_.* DNS \(.*\)'/nameserver \1\\n/; T next; p;
+ :next; s/^foreign_option_.* DOMAIN \(.*\)'/domain \1\\n/; T; p;")"
+
+if [[ -x /sbin/resolvconf ]] ; then
+ echo -e "${DNS}" | /sbin/resolvconf -a "${dev}"
+else
+ echo -e "${DNS}" > /etc/resolv.conf
+ chmod 644 /etc/resolv.conf
+fi
+
+# If we have a service specific script, run this now
+if [[ -x /etc/openvpn/"${SVCNAME}"-up.sh ]] ; then
+ ( /etc/openvpn/"${SVCNAME}"-up.sh )
+fi
+
+# Re-enter the init script to start any dependant services
+if ! /etc/init.d/"${SVCNAME}" --quiet status ; then
+ export IN_BACKGROUND=true
+ /etc/init.d/${SVCNAME} --quiet start
+fi
+
+exit 0
+
+# vim: ts=4 :
diff --git a/net-misc/openvpn/openvpn-2.1_beta14.ebuild b/net-misc/openvpn/openvpn-2.1_beta14.ebuild
new file mode 100644
index 000000000000..c007a61ae09b
--- /dev/null
+++ b/net-misc/openvpn/openvpn-2.1_beta14.ebuild
@@ -0,0 +1,143 @@
+# Copyright 1999-2006 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/net-misc/openvpn/openvpn-2.1_beta14.ebuild,v 1.1 2006/05/09 09:21:41 uberlord Exp $
+
+inherit eutils gnuconfig multilib
+
+DESCRIPTION="OpenVPN is a robust and highly flexible tunneling application compatible with many OSes."
+SRC_URI="http://openvpn.net/release/openvpn-${PV}.tar.gz"
+HOMEPAGE="http://openvpn.net/"
+
+LICENSE="GPL-2"
+SLOT="0"
+KEYWORDS="~alpha ~amd64 ~hppa ~ppc ~ppc-macos ~sparc ~x86"
+IUSE="examples iproute2 minimal pam passwordsave selinux smartcard ssl static threads"
+
+DEPEND=">=dev-libs/lzo-1.07
+ kernel_linux? (
+ iproute2? ( sys-apps/iproute2 ) !iproute2? ( sys-apps/net-tools )
+ )
+ !minimal? ( pam? ( virtual/pam ) )
+ selinux? ( sec-policy/selinux-openvpn )
+ smartcard? ( dev-libs/opensc )
+ ssl? ( >=dev-libs/openssl-0.9.6 )"
+
+src_unpack() {
+ unpack ${A}
+ gnuconfig_update
+ cd "${S}"
+ epatch "${FILESDIR}/${PN}"-2.0.4-darwin.patch
+}
+
+src_compile() {
+ local myconf=""
+ # We cannot use use_enable with iproute2 as the Makefile stupidly
+ # enables it with --disable-iproute2
+ use iproute2 && myconf="${myconf} --enable-iproute2"
+ use minimal && myconf="${myconf} --disable-plugins"
+
+ econf ${myconf} \
+ $(use_enable passwordsave password-save) \
+ $(use_enable smartcard pkcs11) \
+ $(use_enable ssl) \
+ $(use_enable ssl crypto) \
+ $(use_enable threads pthread) \
+ || die "configure failed"
+
+ use static && sed -e -i '/^LIBS/s/LIBS = /LIBS = -static /' Makefile
+
+ emake || die "make failed"
+
+ if ! use minimal ; then
+ cd plugin
+ for i in $( ls 2>/dev/null ); do
+ [[ ${i} == "README" || ${i} == "examples" ]] && continue
+ [[ ${i} == "auth-pam" ]] && ! use pam && continue
+ einfo "Building ${i} plugin"
+ cd "${i}"
+ emake || die "make failed"
+ cd ..
+ done
+ cd ..
+ fi
+}
+
+src_install() {
+ make DESTDIR="${D}" install || die "make install failed"
+
+ # install documentation
+ dodoc AUTHORS ChangeLog PORTS README
+
+ # Empty dir
+ dodir /etc/openvpn
+ keepdir /etc/openvpn
+
+ # Install some helper scripts
+ exeinto /etc/openvpn
+ doexe "${FILESDIR}/up.sh"
+ doexe "${FILESDIR}/down.sh"
+
+ # Install the init script
+ newinitd "${FILESDIR}/openvpn-2.1.init" openvpn
+
+ # install examples, controlled by the respective useflag
+ if use examples ; then
+ # dodoc does not supportly support directory traversal, #15193
+ insinto /usr/share/doc/${PF}/examples
+ doins -r sample-{config-files,keys,scripts} contrib
+ prepalldocs
+ fi
+
+ # Install plugins and easy-rsa
+ if ! use minimal ; then
+ cd easy-rsa/2.0
+ exeinto "/usr/share/${PN}/easy-rsa"
+ doexe *-* pkitool
+ insinto "/usr/share/${PN}/easy-rsa"
+ doins README openssl.cnf vars
+ cd ../..
+
+ exeinto "/usr/$(get_libdir)/${PN}"
+ doexe plugin/*/*.so
+ fi
+}
+
+pkg_postinst() {
+ # Add openvpn user so openvpn servers can drop privs
+ # Clients should run as root so they can change ip addresses,
+ # dns information and other such things.
+ enewgroup openvpn
+ enewuser openvpn "" "" "" openvpn
+
+ if [[ -n $(ls /etc/openvpn/*/local.conf 2>/dev/null) ]] ; then
+ ewarn "WARNING: The openvpn init script has changed"
+ ewarn ""
+ fi
+
+ einfo "The openvpn init script expects to find the configuration file"
+ einfo "openvpn.conf in /etc/openvpn along with any extra files it may need."
+ einfo ""
+ einfo "To create more VPNs, simply create a new .conf file for it and"
+ einfo "then create a symlink to the openvpn init script from a link called"
+ einfo "openvpn.newconfname - like so"
+ einfo " cd /etc/openvpn"
+ einfo " ${EDITOR##*/} foo.conf"
+ einfo " cd /etc/init.d"
+ einfo " ln -s openvpn openvpn.foo"
+ einfo ""
+ einfo "You can then treat openvpn.foo as any other service, so you can"
+ einfo "stop one vpn and start another if you need to."
+
+ if grep -Eq "^[ \t]*(up|down)[ \t].*" ${ROOT}/etc/openvpn/*.conf 2>/dev/null ; then
+ ewarn ""
+ ewarn "WARNING: If you use the remote keyword then you are deemed to be"
+ ewarn "a client by our init script and as such we force up,down scripts."
+ ewarn "These scripts call /etc/openvpn/\$SVCNAME-{up,down}.sh where you"
+ ewarn "can move your scripts to."
+ fi
+
+ if ! use minimal ; then
+ einfo ""
+ einfo "plugins have been installed into /usr/$(get_libdir)/${PN}"
+ fi
+}