5 ms·
They have different objectives. Streisand's goal is to circumvent censorship, so it provisions a set of different VPN protocols (OpenVPN, LT2P/IPSEC, Shadowsock
by subliminalpanda 10y ago
They have different objectives. Streisand's goal is to circumvent censorship, so it provisions a set of different VPN protocols (OpenVPN, LT2P/IPSEC, Shadowsocks, etc...) and instructions on how to use them, where as sovereign sets up e-mail, caldav, and other cloud related tools (which Streisand does not do).
- rosser 10y agoYeah, my question was comparing the linked project to Streisand, not Sovereign to Streisand.
- robbintt 10y agoThis project is designed to be auditable and disposable. It does only one thing and (hopefully) does it well. Also this project is intended to be broadly accessible to people who feel they can do the basics of managing a server.
- subliminalpanda 10y agoI misread your question, my apologies. At a quick glance (and a very quick one at that), Streisand's OpenVPN setup is configured to work on both TCP and UDP ports, where as the references project is being templated from [https://github.com/Stouts/Stouts.openvpn/tree/9c83736608e4cce03fd728a6c9b67dc825ffb978 https://github.com/Stouts/Stouts.openvpn/tree/9c83736608e4cc...]. Looking at the linked project's setup, it seems it's using outdated configurations for OpenVPN (BF-CBC instead of AES-CBC, 1024 bit keys instead of 2048) [https://github.com/Stouts/Stouts.openvpn/blob/9c83736608e4cce03fd728a6c9b67dc825ffb978/defaults/main.yml https://github.com/Stouts/Stouts.openvpn/blob/9c83736608e4cc...]. It's also configured to log info where as Streisand tries its best not to.
- robbintt 10y agoI may have to fork the Stouts.openvpn role. I also am not pleased that their easy-rsa tarball is not easily auditable rather than pulling it as a subrepository directly from OpenVPN. edit: I have audited the easy-rsa tarball. It's still not a totally appropriate way to manage things.
- subliminalpanda 10y agoeasy-rsa 3 has saner defaults, especially how it configures OpenSSL, so if you fork that would be a good place to start.