Solved

Secondary OpenVPN server needs to trust client certificates

Posted on 2014-07-24
2
405 Views
Last Modified: 2014-07-25
I have an OpenVPN server set up on W2K3 and working fine with certificate (static) authentication.  I am setting up a second OpenVPN server for failover.  How do I get the secondary server to trust the client certificates that were generated on the primary server (with easy-rsa)?  I do not have a separate CA and don't want to use one so that the secondary server will still work if it can't connect to a CA (or the failed primary).

Thanks,
-Rich
0
Comment
Question by:rdyaz
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 33

Accepted Solution

by:
Dave Howe earned 500 total points
ID: 40218996
OpenVPN servers need to have the CA cert (Not the key, just the cert) for the issuer of each client cert they must trust.
Just copy it from the config of the first server.
0
 

Author Comment

by:rdyaz
ID: 40220315
Ok it worked--that was a lot easier than I was making it.  Thanks!
0

Featured Post

Ready to trade in that old firewall?

Whether you need to trade-up to a shiny new Firebox or just ready to upgrade from whatever appliance you're using now, WatchGuard has the right appliance for you! Find your perfect Firebox today with appliance sizing tool!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question