Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN private key

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 2 Posters 673 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance
      last edited by

      I am using OpenVPN with user certificate authentication.
      When using the client export tool and enabling the option for 'Microsoft Certificate Storage' i am able to generate the .exe.
      Afterward, going through the install process its stating that the private key is protected with a password. At no point was i prompted to create a password.
      Any idea on how to proceed?

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @michmoor
        last edited by

        @michmoor
        Windows is expecting password protection on a private key.

        152c37cb-e43c-409d-b5b0-f5b4ed4debe2-grafik.png

        M 1 Reply Last reply Reply Quote 1
        • M
          michmoor LAYER 8 Rebel Alliance @viragomann
          last edited by

          @viragomann Gotcha.
          Thats solved.
          The next issue is im still able to sign in even though i removed the certificate from my trust store.

          99e060a1-5b69-482b-8b9b-1dcca6a6c6de-image.png

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @michmoor
            last edited by

            @michmoor said in OpenVPN private key:

            im still able to sign in even though i removed the certificate from my trust store.

            On the Windows client?
            I'd expect, that the client would complain due to missing certificate.

            M 1 Reply Last reply Reply Quote 0
            • M
              michmoor LAYER 8 Rebel Alliance @viragomann
              last edited by

              @viragomann Solved it. the installer correctly intalls the certificate as PCKS12.
              If you remove the cert and attempt to add the user cert back [i have the file on my desktop] the OpenVPN client correctly states it cant find the user cert. Took me a few minutes to realize that the cert exported from the User certificate manager on pfsense is not in the correct format for OpenVPN to read from in the certificate store.

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @michmoor
                last edited by

                @michmoor said in OpenVPN private key:

                that the cert exported from the User certificate manager on pfsense is not in the correct format for OpenVPN to read from in the certificate store.

                You need both on the client, the user cert and the private key. The PKCS12 even contains both.
                But I don't know at the moment, how to import them into Windows in this format. But you could put both files into a directory and state them in the .ovpn file.

                M 1 Reply Last reply Reply Quote 0
                • M
                  michmoor LAYER 8 Rebel Alliance @viragomann
                  last edited by

                  @viragomann If i re-run the installer from Clients export in pfsense, then it installs the PCKS12 file i need and in the certificate store. OpenVPN config file is generated to automatically to look at the trust store. So thats what i have been doing to test.
                  User Cert + 2FA, and no admin rights on this workers laptop...Im happy.

                  Firewall: NetGate,Palo Alto-VM,Juniper SRX
                  Routing: Juniper, Arista, Cisco
                  Switching: Juniper, Arista, Cisco
                  Wireless: Unifi, Aruba IAP
                  JNCIP,CCNP Enterprise

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.