Page 1 of 1

Certificate upgrades on Windows (7) due to obsolete MD5

Posted: Thu Sep 13, 2018 2:03 pm
by knicknack
Hello,

After updating to the latest version of OpenVPN server on our Windows 7 system it has ceased to work due to support for MD5 being dropped with this version (openvpn-install-2.4.6-I602.exe).

Unfortunately I can only find information about upgrading certificates on linux-type platforms and I fear the official how-to for Windows is out of date.

Before I delve in and do it wrong, does anyone know of a resource for Windows which deals with upgrading server and client certificates? Not sure how to proceed. Many thanks.

Re: Certificate upgrades on Windows (7) due to obsolete MD5

Posted: Thu Sep 13, 2018 2:25 pm
by TinCanTech

Re: Certificate upgrades on Windows (7) due to obsolete MD5

Posted: Thu Sep 13, 2018 2:31 pm
by knicknack
Yes have just downloaded the latest easy-rsa. Now, because this is an existing installation I presume I need to move all my old keys, crt and pem files out of there before I start with easy-rsa, would that be right?

Re: Certificate upgrades on Windows (7) due to obsolete MD5

Posted: Thu Sep 13, 2018 2:43 pm
by TinCanTech
Always make a backup ..

Re: Certificate upgrades on Windows (7) due to obsolete MD5

Posted: Thu Sep 13, 2018 2:45 pm
by knicknack
Indeed, but if I'm not mistaken, the old key, pem and crt files could cause confusion and/or problems if I leave them in there. I'll take them out...

Re: Certificate upgrades on Windows (7) due to obsolete MD5

Posted: Thu Sep 13, 2018 2:50 pm
by TinCanTech
You will have to create a completely new PKI so make sure your old one is not in your way.

Re: Certificate upgrades on Windows (7) due to obsolete MD5

Posted: Wed Sep 19, 2018 7:23 am
by knicknack
So I install easy-rsa but it can't find the PATH to ssl. I add the path to the Windows environment variables but it still can't find the commands. What gives? I see some others have gone ahead and re-installed Open SSL. What do you recommend?

Re: Certificate upgrades on Windows (7) due to obsolete MD5

Posted: Wed Sep 19, 2018 12:18 pm
by TinCanTech
See vars.example

Re: Certificate upgrades on Windows (7) due to obsolete MD5

Posted: Fri Sep 28, 2018 12:35 pm
by knicknack
Ok, that was helpful, thank you.
For others having difficulty, also helpful was this tutorial, although I didn't encrust the certificates in the server.config like he did:
https://www.alanbonnici.com/2018/01/how ... lient.html