• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Certificate does not have key usage extension

Scheduled Pinned Locked Moved OpenVPN
22 Posts 6 Posters 7.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    testsia @viragomann
    last edited by Apr 22, 2022, 1:58 PM

    @viragomann
    Do I need to restart all the OPENVPN services or is the one "OpenVPN server: Mobil-Video-CCTV_NEW"on which I conduct experiments enough?
    I reloaded one"OpenVPN server: Mobil-Video-CCTV_NEW".Снимок экрана 2022-04-22 в 4.56.06 PM.png

    V 1 Reply Last reply Apr 22, 2022, 2:03 PM Reply Quote 0
    • V
      viragomann @testsia
      last edited by Apr 22, 2022, 2:03 PM

      @testsia
      Yes, it's sufficient to restart a single service, but the changes only affects to the restarted services naturally.

      T 1 Reply Last reply Apr 22, 2022, 2:05 PM Reply Quote 0
      • T
        testsia @viragomann
        last edited by Apr 22, 2022, 2:05 PM

        @viragomann
        Then I don't know what to do with this problem!
        I will try to restart the whole server tonight

        T 1 Reply Last reply Apr 25, 2022, 8:41 AM Reply Quote 0
        • T
          testsia @testsia
          last edited by Apr 25, 2022, 8:41 AM

          Hey!
          I rebooted the server but my problem was not solved.
          I went further in my experiments.
          I have generated a new "CA" certificate. Generated a certificate for the server, specified them in my OPENVPN configuration and now it works fine. But as soon as I return certificates that were not generated on PFSENSE, my problem returns. Does anyone have any ideas how to solve the problem?

          1 Reply Last reply Reply Quote 0
          • T
            testsia
            last edited by Apr 27, 2022, 1:20 PM

            @testsia
            Hi friends!
            I went further in my experiments.
            I installed Pfsense version 2.5, performed a restore from a backup.

            And OPENVPN works as expected!
            I can conclude that the problem is Pfsense version 2.6.
            I don't know where to write to inform the developers. But the problem is exactly Pfsense version 2.6.
            It does not work with certificates that were generated outside Pfsense.

            T 1 Reply Last reply May 2, 2022, 3:07 PM Reply Quote 0
            • T
              testsia @testsia
              last edited by May 2, 2022, 3:07 PM

              @testsia
              I determined what the problem is.
              My client certificates do not have serverAuth and clientAuth ExtendedKeyUSage ("EKU") attribytes.
              In version 2.6 this check is mandatory

              Certificate does not have key usage extension
              91.203.115.5:56352 VERIFY KU ERROR
              

              Who knows how I can disable this check on the server???
              Снимок экрана 2022-05-02 в 1.11.41 PM.png

              1 Reply Last reply Reply Quote 0
              • J
                jimp Rebel Alliance Developer Netgate
                last edited by jimp May 2, 2022, 6:49 PM May 2, 2022, 6:46 PM

                @testsia said in Certificate does not have key usage extension:

                Who knows how I can disable this check on the server???

                That was already answered upthread.

                • Read https://redmine.pfsense.org/issues/13056
                • Install the System Patches package
                • Create entries in the System Patches package for 48cf54f850c5bf4fe26a8e33deb449807e71c204 and 47f2f4060d9e5b71c5c69356b61191fd2931383c
                • Fetch and apply both patches
                • Uncheck "Client Certificate Key Usage Validation" in the OpenVPN server and Save

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                T X S 3 Replies Last reply May 3, 2022, 11:44 AM Reply Quote 4
                • T
                  testsia @jimp
                  last edited by May 3, 2022, 11:44 AM

                  @jimp said in Certificate does not have key usage extension:

                  @testsia said in Certificate does not have key usage extension:

                  Who knows how I can disable this check on the server???

                  That was already answered upthread.

                  • Read https://redmine.pfsense.org/issues/13056
                  • Install the System Patches package
                  • Create entries in the System Patches package for 48cf54f850c5bf4fe26a8e33deb449807e71c204 and 47f2f4060d9e5b71c5c69356b61191fd2931383c
                  • Fetch and apply both patches
                  • Uncheck "Client Certificate Key Usage Validation" in the OpenVPN server and Save

                  I am very grateful to you!
                  You helped solve my problem!
                  Thanks!!!

                  W 1 Reply Last reply Jun 30, 2022, 6:59 PM Reply Quote 0
                  • W
                    webdawg @testsia
                    last edited by webdawg Aug 4, 2022, 5:54 PM Jun 30, 2022, 6:59 PM


                    1 Reply Last reply Reply Quote 0
                    • X
                      Ximulate @jimp
                      last edited by Jul 11, 2022, 1:48 PM

                      @jimp said in Certificate does not have key usage extension:

                      Uncheck "Client Certificate Key Usage Validation" in the OpenVPN server and Save

                      Does this create a security issue? If so, is there a proper way within pfSense to set-up the certificate so that the EKU works?

                      The post at the link below indicates it does:
                      https://superuser.com/questions/1446201/openvpn-certificate-does-not-have-key-usage-extension

                      1 Reply Last reply Reply Quote 0
                      • J
                        jimp Rebel Alliance Developer Netgate
                        last edited by Jul 11, 2022, 1:56 PM

                        If you create a new cert structure the cert manager in pfSense will put the proper set of attributes in everything these days.

                        Those certs may have been made externally or before the cert manager was adding the correct attributes.

                        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • A ads76 referenced this topic on Sep 1, 2022, 4:35 PM
                        • A ads76 referenced this topic on Sep 1, 2022, 4:35 PM
                        • S
                          slu @jimp
                          last edited by Dec 14, 2022, 1:17 PM

                          @jimp
                          thank you Jim, I'm running into the same problem with some older VPN clients/certs.

                          pfSense Gold subscription

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            [[user:consent.lead]]
                            [[user:consent.not_received]]