Community discussions

MikroTik App
 
CPromper
just joined
Topic Author
Posts: 24
Joined: Wed Aug 05, 2009 8:34 am

OVPN:require client certificate not working anymore [SOLVED]

Fri Mar 21, 2014 2:51 pm

Hello,

I've updated from v6.10 to v6.11 and the OVPN option "require client certificate" doesn't work anymore!

If I remove the option I can login again with OpenVPN client on iPhone.

But with this option set I can't login (in 6.10 it worked).

Can anyone confirm it?

Best regards

Carsten
Last edited by CPromper on Wed Apr 16, 2014 1:09 pm, edited 2 times in total.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7169
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: OVPN: require client certificate not working anymore

Fri Mar 21, 2014 2:56 pm

Is client certificate from the same CA chain?
 
revizor
just joined
Posts: 1
Joined: Mon Feb 24, 2014 12:29 pm

Re: OVPN: require client certificate not working anymore

Fri Mar 21, 2014 4:43 pm

Confirming, after updating to 6,11 i have the same problem.
 
elgrandiegote
newbie
Posts: 40
Joined: Tue Feb 05, 2013 6:02 am
Location: Buenos Aires, Argentina

Re: OVPN: require client certificate not working anymore

Fri Mar 21, 2014 11:19 pm

I have exactly the same problem
Downgrade to 6.10
 
bramfm
just joined
Posts: 4
Joined: Sat Jul 07, 2012 2:56 pm

Re: OVPN: require client certificate not working anymore

Sat Mar 22, 2014 5:54 pm

Same problem here..... :(
 
yozz
just joined
Posts: 15
Joined: Fri Jan 31, 2014 11:51 pm

Re: OVPN: require client certificate not working anymore

Sat Mar 22, 2014 8:33 pm

yes.. problems is it.
 
CPromper
just joined
Topic Author
Posts: 24
Joined: Wed Aug 05, 2009 8:34 am

Re: OVPN: require client certificate not working anymore

Mon Mar 24, 2014 6:09 pm

Hello mrz,

yes, I only have one CA installed, and the client certificate is signed by this CA.

Downgraded to 6.10 and it works again.

I have seen that there was an issue with the client certificate option (that I did not have)
because the changelog of 6.11 says:
*) ovpn - fixed require-client-certificate

Regards

Carsten
 
patrickmkt
Member Candidate
Member Candidate
Posts: 202
Joined: Sat Jul 28, 2012 5:21 pm

Re: OVPN: require client certificate not working anymore

Mon Mar 24, 2014 8:46 pm

Same problem for me.
I have CA and intermediate CA with LT status in ROS.
 
emuell
just joined
Posts: 22
Joined: Fri Dec 07, 2012 5:01 pm

Re: OVPN: require client certificate not working anymore

Thu Mar 27, 2014 3:38 pm

i can also confirm that since v6.11 "require-client-certificate" option does not work anymore!
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7169
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: OVPN: require client certificate not working anymore

Thu Mar 27, 2014 4:22 pm

Will be fixed in next version. It is related to CRL.
 
fievel
just joined
Posts: 6
Joined: Wed Apr 02, 2014 9:48 am

Re: OVPN: require client certificate not working anymore

Wed Apr 02, 2014 3:14 pm

When is planned the next version ?
 
CPromper
just joined
Topic Author
Posts: 24
Joined: Wed Aug 05, 2009 8:34 am

Re: OVPN: require client certificate not working anymore

Wed Apr 16, 2014 1:06 pm

Hi folks,

today I upgraded to version 6.12 and openvpn didn't work.

The flags of the CA and the router certificate after updating was only a big "T"

After I deleted the certificates (CA and signed certificate for router) and imported them again everythings works as expected. <== (I didn't do this step in 6.11, maybe it works also here???)

The flags are: for CA = "AT" and for the router cert = "KT"

So, the option "Require Client Certificate" in version 6.12 works.

Best regards

Who is online

Users browsing this forum: McSee and 21 guests