vpnaccess
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| vpnaccess [2024/09/20 16:44] – The file was misnamed. ljflores | vpnaccess [2026/09/16 18:42] (current) – djgalloway | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== VPN Access ====== | ====== VPN Access ====== | ||
| - | ===== Requesting Access ===== | + | ===== Requesting |
| - | To request access to the Sepia lab, | + | |
| - | - Generate login credentials by following directions under **VPN Client Access** below. | + | |
| - | - [[http:// | + | |
| - | < | + | Visit https:// |
| - | 1) Do you just need VPN access or will you also be running teuthology jobs? | + | ===== Existing User Additional Credential ===== |
| - | 2) Desired Username: | + | Use this form if you are registering an additional machine and need another Wireguard or SSH key. |
| - | 3) Alternate e-mail address(es) we can reach you at: | + | See https:// |
| - | 4) If you don't already have an established history of code contributions to Ceph, is there an existing community or core developer you've worked with who has reviewed your work and can vouch for your access request? | + | ===== Existing User Replace Credential ===== |
| - | If you answered " | + | Use this form if you are // |
| - | 4a) Paste a link to a Blueprint or planning doc of yours that was reviewed at a Ceph Developer Monthly. | + | https:// |
| - | 4b) Paste a link to an accepted pull request for a major patch or feature. | + | ===== Existing User Remove SSH Key ===== |
| - | 4c) If applicable, include a link to the current project (planning doc, dev branch, or pull request) that you are looking to test. | + | https:// |
| - | 5) Paste your SSH public key(s) between the pre tags | + | ===== Approvals ===== |
| - | 6) Paste your hashed VPN credentials between the pre tags (Format: user@hostname 22CharacterSalt 65CharacterHashedPassword) | + | User access requests from @ibm.com and @redhat.com e-mail addresses are automatically approved once they confirm their e-mail via a magic link. (Other domains can be added. |
| - | For details on our particular OpenVPN server setup, see [[services: | + | Non-whitelisted domains require an existing lab user to " |
| - | </ | + | Once an account is approved, automation runs to add the user' |
| - | ===== VPN Client Access ===== | + | |
| - | Follow the instructions corresponding | + | |
| - | **NOTE:** You will need VPN credentials for each machine/ | + | The user will then be e-mailed their Wireguard IP and can log in. |
| - | + | Admins can approve/deny/clean up at https://onboarding-admin.front.sepia.ceph.com/ | |
| - | ==== Linux ==== | + | |
| - | < | + | |
| - | sudo [apt-get|yum] install openvpn | + | |
| - | + | ||
| - | sudo mkdir -p /run/openvpn | + | |
| - | + | ||
| - | ## Fedora 28 and later | + | |
| - | cd / | + | |
| - | + | ||
| - | ## All others | + | |
| - | cd / | + | |
| - | + | ||
| - | + | ||
| - | sudo wget https://filedump.ceph.com/ | + | |
| - | sudo tar zxvf sepia-vpn-client.tar.gz | + | |
| - | + | ||
| - | + | ||
| - | # Generate client credentials | + | |
| - | # USER should be your desired username and HOST should describe your workstation | + | |
| - | # e.g., dgalloway@thinkpad | + | |
| - | + | ||
| - | sudo ./ | + | |
| - | + | ||
| - | # Submit the command output in your ticket | + | |
| - | # After you've been notified in your ticket that access has been granted, | + | |
| - | + | ||
| - | sudo service openvpn restart | + | |
| - | OR | + | |
| - | sudo systemctl restart openvpn@sepia | + | |
| - | OR | + | |
| - | sudo systemctl restart openvpn-client@sepia | + | |
| - | + | ||
| - | # Try all 3. One of them should work. | + | |
| - | # Whichever works, enable the systemd service | + | |
| - | + | ||
| - | sudo systemctl enable openvpn@sepia | + | |
| - | OR | + | |
| - | sudo systemctl enable openvpn-client@sepia | + | |
| - | </ | + | |
| - | + | ||
| - | === Linux Gotchas === | + | |
| - | You may need to edit '' | + | |
| - | + | ||
| - | < | + | |
| - | sed -i ' | + | |
| - | sed -i ' | + | |
| - | </ | + | |
| - | + | ||
| - | ---- | + | |
| - | + | ||
| - | If you're using OpenVPN for any other VPN connection (e.g., Red Hat' | + | |
| - | + | ||
| - | < | + | |
| - | # ERASE | + | |
| - | dev tun | + | |
| - | + | ||
| - | # REPLACE WITH | + | |
| - | dev sepia0 | + | |
| - | dev-type tun | + | |
| - | </ | + | |
| - | + | ||
| - | ---- | + | |
| - | + | ||
| - | If the '' | + | |
| - | + | ||
| - | < | + | |
| - | sudo sed -i ' | + | |
| - | </ | + | |
| - | + | ||
| - | === Troubleshooting === | + | |
| - | Please disable SELinux on rhel clients | + | |
| - | + | ||
| - | To troubleshoot your VPN connection, try running the following command to determine where the connection is failing: | + | |
| - | + | ||
| - | < | + | |
| - | openvpn --config / | + | |
| - | OR | + | |
| - | openvpn --config / | + | |
| - | </ | + | |
| - | + | ||
| - | ==== Fedora NetworkManager GUI ==== | + | |
| - | + | ||
| - | - Make sure you've followed all the prerequisite steps [[vpnaccess# | + | |
| - | - Right click the NetworkManager icon | + | |
| - | - **Edit Connections** | + | |
| - | - Click the + symbol | + | |
| - | - Select **Import a saved VPN configuration** from the bottom | + | |
| - | - Click **Create** | + | |
| - | - Browse to ''/ | + | |
| - | - Enter your the first line in ''/ | + | |
| - | - Enter the second line in your ''/ | + | |
| - | + | ||
| - | + | ||
| - | ==== Fedora Network Manager GUI -- Fedora 34 ==== | + | |
| - | + | ||
| - | This procedure was confirmed to work on Fedora 34 on 14 July 2021. | + | |
| - | + | ||
| - | - Make sure you've followed all the prerequisite steps [[vpnaccess# | + | |
| - | - Right click the NetworkManager icon | + | |
| - | - Select **Settings** --> **Network** | + | |
| - | - Click the **+** symbol under VPN | + | |
| - | - Select **Import from file...** from the bottom | + | |
| - | - Browse to ''/ | + | |
| - | - Enter your the first line in ''/ | + | |
| - | - Enter the second line in your ''/ | + | |
| - | + | ||
| - | ==== Mac/OS X ==== | + | |
| - | Tunnelblick and Viscosity are two clients known to work with the Sepia VPN. | + | |
| - | + | ||
| - | === Tunnelblick **UNTESTED** === | + | |
| - | - Download and untar the Sepia VPN client [[https:// | + | |
| - | mkdir / | + | |
| - | cd / | + | |
| - | wget https:// | + | |
| - | sudo tar zxvf sepia-vpn-client.tar.gz | + | |
| - | + | ||
| - | # Generate client credentials | + | |
| - | # USER should be your desired username and HOST should describe your workstation | + | |
| - | # e.g., dgalloway@thinkpad | + | |
| - | + | ||
| - | sudo ./ | + | |
| - | + | ||
| - | # Submit the output of this command in your ticket</ | + | |
| - | - Replace the line '' | + | |
| - | - Follow [[https:// | + | |
| - | - When prompted for user/pass, enter username USER@HOST as above, and for password use the secret contents of the file ''/ | + | |
| - | - Save to your keychain if you wish | + | |
| - | + | ||
| - | === Viscosity === | + | |
| - | + | ||
| - | - Download https:// | + | |
| - | - Download https:// | + | |
| - | - Import the Sepia.visz config into Viscosity | + | |
| - | - Extract sepia-vpn-client.tar.gz | + | |
| - | - Save '' | + | |
| - | - Run '' | + | |
| - | - Replace '' | + | |
| - | - In Viscosity, under the Authentication tab, set: | + | |
| - | - **Authentication: | + | |
| - | - Check **Use Username/ | + | |
| - | - **CA:** to the ca.crt file you saved earlier | + | |
| - | - **Tls-Auth: | + | |
| - | - When connecting to the VPN for the first time, | + | |
| - | - Enter your '' | + | |
| - | - Enter the second line of '' | + | |
| - | - Save the credentials to your keychain | + | |
| - | - You can now delete any downloaded and created files (except ca.crt) | + | |
| - | + | ||
| - | ===== A Note About DNS ===== | + | |
| - | Due to complexities around adding nameservers to various Linux distro VPN clients, our OpenVPN server does not use the [[https:// | + | |
| - | + | ||
| - | Instead, we serve our private DNS records publicly. | + | |
| - | + | ||
| - | If you're using dnsmasq, you can add '' | + | |
vpnaccess.1726850646.txt.gz · Last modified: by ljflores
