Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Certificate does not have key usage extension / CRL expiration - again

    Scheduled Pinned Locked Moved OpenVPN
    1 Posts 1 Posters 548 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michaelschefczyk
      last edited by

      Dear All,

      Some time ago there was an issue with OpenVPN suddenly not accepting certain certificates anymore. This seems to be around:
      https://redmine.pfsense.org/issues/13056
      in German: https://www.andysblog.de/pfsense-openvpn-verbindungen-scheitern-an-certificate-does-not-have-key-usage-extension

      Then, there were patches though the patches pakage like:

      • OpenVPN Enforce key usage option fix
      • OpenVPN Enforce key usage option typo fix
      • Fix for CRL expiration lifetime default and maximum values (Redmine #13424)

      It seems that these packages did mitigate the problem for a while. Now, I am facing "Certificate does not have key usage extension" issues again, seemingly with older certificates and not so much with more recent certificates. The OpenVPN server does reject some certificates - which were in use for a long time without issues and which are not expored - while accepting others.

      Can someonne please be so kind to point me at what to do to solve this? Will there maybe be a new version of pfSense solving this in the near future?

      Regards,

      Michael Schefczyk

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.