Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Client Export Can't Locate "the Requested Certificate"

    Scheduled Pinned Locked Moved pfSense Packages
    9 Posts 5 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • EveningStarNME
      EveningStarNM
      last edited by EveningStarNM

      We have a peer-to-peer VPN using the OpenVPN server in pfSense 2.6. The Open VPN Client Export Utility was just upgraded to version 1.6_6. Since then, the export utility fails and returns "Unable to locate the requested certificate" in a red banner at the top of the utility's page.

      Our configuration uses an Active Directory Radius server to provide authentication. Other server notes are:

      • Device mode: TUN
      • Protocol: UDP on IPv4 Only
      • TLS Encryption and Authentication in the default direction
      • Root CA
      • Revocation List
      • Server Certificate for the external FQDN, which has a different hostname than is used internally.
      • Enable Data Encryption negotiation
      • Redirect all traffic from WAN through pfSense

      The client is configured to use x509 verification where possible, block outside DNS. When I go to do the client download, I get the error message. I don't know which certificate it's talking about. They're all good.

      I've created a new server certificate and futzed with numerous settings and checked Redmine for clues, but the only thing close relies on PKCS, which we aren't using. I have no idea where to go from here. I'll be grateful for suggestions.

      C DerelictD 2 Replies Last reply Reply Quote 1
      • C
        chovekoliki @EveningStarNM
        last edited by

        @eveningstarnm Same problem.

        1 Reply Last reply Reply Quote 0
        • P
          pablomichelin
          last edited by

          same problem, any help?

          1 Reply Last reply Reply Quote 0
          • jimpJ jimp moved this topic from OpenVPN on
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            What authentication mode is the server set for? (e.g. SSL/TLS, User Auth, SSL/TLS + User Auth)

            If it's set for user auth, is the authentication local or through an authentication server (RADIUS, LDAP, etc)?

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            P 1 Reply Last reply Reply Quote 0
            • P
              pablomichelin @jimp
              last edited by

              @jimp
              Server mode Remote Access (User Auth)
              Backend with Active Directory server.

              1 Reply Last reply Reply Quote 0
              • P
                pablomichelin
                last edited by

                Captura de Tela 2022-11-07 às 10.55.16.png

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate @EveningStarNM
                  last edited by Derelict

                  @eveningstarnm https://redmine.pfsense.org/issues/12475

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    Should be fixed in pkg v1.7_2 and v1.6_7 (and later)

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    C 1 Reply Last reply Reply Quote 0
                    • C
                      chovekoliki @jimp
                      last edited by

                      @jimp Fixed!

                      1 Reply Last reply Reply Quote 2
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.