- ovpmon-helper: new publish-crl command (validated copy of pki/crl.pem to /etc/openvpn/crl.pem, root:root 644); crl-verify allowlisted only for that path; CRL is refreshed on service start/restart. - Profiler: publish after gen-crl (init/revoke) and on server/configure; generator renders the published path when running unprivileged. - doas rule for publish-crl; docs and helper copy updated. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
OpenVPN Profiler Module (APP_PROFILER)
The Profiler module is a FastAPI-based service (port 8000) dedicated to management tasks:
- Public Key Infrastructure (PKI) management (EasyRSA wrapper).
- Client Profile (
.ovpn) generation. - Server Configuration management.
- Process control (Start/Stop OpenVPN service).
Documentation
- API Reference: See
DOCS/Profiler_Management/API_Reference.md. - Overview: See
DOCS/Profiler_Management/Overview.md.
Quick Start (Dev)
# Setup
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
# Run
python3 main.py
# Swagger UI available at http://localhost:8000/docs