Page 1 of 1

CA expired - seeking how avoiding connect to each client

Posted: Mon Jan 21, 2019 2:40 pm
by rmorgade
Dear all,

We are facing a huge problem with our OpenVPN solution. Our ca.crt has expired this weekend.

After reading a lot this morning we managed to recreate a new ca.crt with same Modulus as the old one. But still the way to go seems to be to copy that new ca.crt to ALL the clients.

Our projects do not allow this easily, because they are worldwide, difficult access, etc

Can anyone thing of any possibility, ANY, which might avoid have to connect to all of them? We are open to lack security for a while until fix it pemanently (yes, lacking security is not in consonance with VPN... but, you know, desperate times...)

Thanks in advance

Re: CA expired - seeking how avoiding connect to each client

Posted: Fri May 24, 2019 6:42 am
by er4z0r
Hi,

I ran into the same problem last week. Got any fixes?

The solution from viewtopic.php?t=18671 didn't work for me.
Maybe it's because the new ca.crt hast a key-size of 2048?

Re: CA expired - seeking how avoiding connect to each client

Posted: Mon Jun 29, 2020 5:30 am
by baldox
Hi, we are in the same issue, Got any fixes?

your answer will be really appreciated.