Solved

Secondary OpenVPN server needs to trust client certificates

Posted on 2014-07-24
2
395 Views
Last Modified: 2014-07-25
I have an OpenVPN server set up on W2K3 and working fine with certificate (static) authentication.  I am setting up a second OpenVPN server for failover.  How do I get the secondary server to trust the client certificates that were generated on the primary server (with easy-rsa)?  I do not have a separate CA and don't want to use one so that the secondary server will still work if it can't connect to a CA (or the failed primary).

Thanks,
-Rich
0
Comment
Question by:rdyaz
2 Comments
 
LVL 33

Accepted Solution

by:
Dave Howe earned 500 total points
ID: 40218996
OpenVPN servers need to have the CA cert (Not the key, just the cert) for the issuer of each client cert they must trust.
Just copy it from the config of the first server.
0
 

Author Comment

by:rdyaz
ID: 40220315
Ok it worked--that was a lot easier than I was making it.  Thanks!
0

Featured Post

Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
HTTP to HTTPS redirect is not working 1 93
Teamviewer vpn for dc replication 9 33
SSL - A Registrar-Level Change? 4 16
ASA 5505 packet drops 14 46
Like many others, when I created a Windows 2008 RRAS VPN server, I connected via PPTP, and still do, but there are problems that can arise from solely using PPTP.  One particular problem was that the CFO of the company used a Virgin Broadband Wirele…
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question