Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Secondary OpenVPN server needs to trust client certificates

Posted on 2014-07-24
2
Medium Priority
?
409 Views
Last Modified: 2014-07-25
I have an OpenVPN server set up on W2K3 and working fine with certificate (static) authentication.  I am setting up a second OpenVPN server for failover.  How do I get the secondary server to trust the client certificates that were generated on the primary server (with easy-rsa)?  I do not have a separate CA and don't want to use one so that the secondary server will still work if it can't connect to a CA (or the failed primary).

Thanks,
-Rich
0
Comment
Question by:rdyaz
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 33

Accepted Solution

by:
Dave Howe earned 2000 total points
ID: 40218996
OpenVPN servers need to have the CA cert (Not the key, just the cert) for the issuer of each client cert they must trust.
Just copy it from the config of the first server.
0
 

Author Comment

by:rdyaz
ID: 40220315
Ok it worked--that was a lot easier than I was making it.  Thanks!
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question