Server certificate expired - certificate verify expired
Posted: Tue Feb 14, 2017 1:23 pm
Hi,
we current have a problem with our OpenVPN conncetivity.
Two days ago the ca.crt along with server.crt, server.key and server.csr expired.
We are using WinServer 2008r2 with Windows clients.
A new ca.crt and server.crt was built, ca.crt without pw but server.crt with pw.
I replaced the ca.crt in the server folder where server.ovpn config is telling me to.
I also replaced the ca.crt on my local client but unfortunatly without success.
The commands I use were build-ca and build-key-pass for the server.crt, and before them the command vars.bat.
Should I build the server certificate without password?
What is the command for that?
The error I get is:
VERIFY ERROR: depth=0, error=unable to get local issuer certificate: ...
OpenSSL: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed.
Can I somehow verify the new certificates?
thank a lot
intane
we current have a problem with our OpenVPN conncetivity.
Two days ago the ca.crt along with server.crt, server.key and server.csr expired.
We are using WinServer 2008r2 with Windows clients.
A new ca.crt and server.crt was built, ca.crt without pw but server.crt with pw.
I replaced the ca.crt in the server folder where server.ovpn config is telling me to.
I also replaced the ca.crt on my local client but unfortunatly without success.
The commands I use were build-ca and build-key-pass for the server.crt, and before them the command vars.bat.
Should I build the server certificate without password?
What is the command for that?
The error I get is:
VERIFY ERROR: depth=0, error=unable to get local issuer certificate: ...
OpenSSL: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed.
Can I somehow verify the new certificates?
thank a lot
intane