I am trying to upgrade or improve my certificates on my OpenVPN server. My clients get the MD5 not supported after april 2018 warning when connecting. (i used the standard install how-to a while ago)
I see that I need to use a 3.x version of Easy-RSA to create the new key en cert files for the server and clients (I think). But I can't seem to get the startup script to start Easy-RSA the right way, my error: (when starting "Easy-RSA-start.bat")
Searched google, github easy-rsa issues, this forum and tried every version of Easy-RSA, all the same outcome.FATAL: EasyRSA Shell init is missing a required external file:
which.exe
Your installation is incomplete and cannot function without the required
files.
Press enter to exit.
Can somebody help?
How can I create better certificates (sha256 I have read)? (is this perhaps possible with easy-rsa 2.x that works fine?)
My setup:
- Windows server 2003r2
- Easy-RSA 3.0.4
- OpenVPN server 2.3.13
- Clients mostly IOS devices and still working fine (except for de MD5 warning)
Thanks for helping.