--- doc/openvpn.8.html.orig 2021-10-05 05:57:01 UTC +++ doc/openvpn.8.html @@ -650,7 +650,7 @@ lower priority, n le
Don't re-read key files across SIGUSR1
or --ping-restart.
This option can be combined with --user nobody to allow restarts +
This option can be combined with --user openvpn to allow restarts
triggered by the SIGUSR1
signal. Normally if you drop root
privileges in OpenVPN, the daemon cannot be restarted since it will now
be unable to re-read protected key files.
By setting user to nobody
or somebody similarly unprivileged,
+
By setting user to openvpn
or somebody similarly unprivileged,
the hostile party would be limited in what damage they could cause. Of
course once you take away privileges, you cannot return them to an
OpenVPN session. This means, for example, that if you want to reset an