Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Upgrade 2.7.2 disabled OpenVPN. Server certificate not in the list anymore

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 2 Posters 267 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      balmmva
      last edited by

      Hi
      I upgraded from 2.7.0 to 2.7.2
      My OpenVPN server has been disabled and I can't enable it as the server certificate is not in the list of available certificate.
      Is there a trick to make the old certificate selectable and restart the OpenVPN server ?
      thx

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @balmmva
        last edited by

        @balmmva

        Start with this trick : OpenVPN forum - first first pinned post : HEADS UP: OpenVPN deprecating shared key mode, requires TLS, deprecating cipher selection.

        Example : If the certificate you've been using was to old, not secure enough anymore, it could have been 'thrown away' as OpenVPN can't use it anymore.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        B 1 Reply Last reply Reply Quote 0
        • B Offline
          balmmva @Gertjan
          last edited by balmmva

          @Gertjan
          thank you. It must be the cause.

          OpenVPN was still working "fine" with pfsense 2.7.0 and the deprecated server certificate.
          I suppose someone had "cheated" and allowed old certs. Is this possible ?

          Is there a way to reenable in order to give access again to all the clients.
          I would then be able to change every client config. But only if they can connect. Many (80+) are remote workers.

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG Offline
            Gertjan @balmmva
            last edited by Gertjan

            @balmmva said in Upgrade 2.7.2 disabled OpenVPN. Server certificate not in the list anymore:

            I suppose someone had "cheated" and allowed old certs. Is this possible ?

            It's not the 'age', but the settings used to create the cert.
            I'm using my OpenVPN server (and clients connected to it) with certs I created some where in 2017, they still work / are accepted.

            If you create new certs for each user (test first ^^) then you have to redeploy a openvpn client config for every user ....

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            B 1 Reply Last reply Reply Quote 0
            • B Offline
              balmmva @Gertjan
              last edited by

              @Gertjan
              right. certs are not "old", they are obsolete. sha1

              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.