Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN Certs

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      PfsenseServer350
      last edited by

      Hi guys,

      Just a quick question. After I revoke a certificate for OpenVPN or after a certificate has expired I am free to hit the delete button correct?

      We have run into some issues in the past and I just want to confirm this.

      Thanks!

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        No, you must not delete revoked certificates from the server!
        If you delete a cert it doesn't be count as revoked and will be accepted by the server since it fits to the servers CA.

        Expired certs will not be accepted anyway.

        1 Reply Last reply Reply Quote 0
        • P
          PfsenseServer350
          last edited by

          Then whats the best way to prevent the list from getting clogged up and very long?

          1 Reply Last reply Reply Quote 0
          • K
            kpa
            last edited by

            The best way I can think of is that you create the certificates with short enough lifetimes so that regardless of you messing up the CRL the damage is minimized. What is short enough depends, it could be a year or two or longer in some cases.

            1 Reply Last reply Reply Quote 0
            • C
              cmb
              last edited by

              You can delete them once they're expired or revoked. Might want to only delete the expired certs just in case the CRL gets messed up at some point so it's easy to add them back to the CRL/to a new CRL. Of course could always restore from backup as well in that case.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.