[Linksys] Error message: Peer certificate verification failure

This forum is for general conversation and user-user networking.

Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Tue Nov 08, 2022 8:35 pm

*********************************************************************************
_ _ __ _ __ _____ __ __ _____
| | | || \ | | / // ____]\ \ / // ____]TM
| | | || \ | | / /| (___ \ V /| (____
| | | || |\ \| |\ \ \____ \ \ / \____ \
| |_____ | || | \ | \ \ ____) | | | ____) |
|_______||_||_| \__| \_\[____ / |_| [_____/

(c) 2014 Belkin International, Inc. and/or its affiliates. All rights reserved.
Booting rango (firmware version 1.0.8.199531)
*********************************************************************************
[utopia][init] System Initialization
[utopia][init] Creating /proc
[utopia][init] Creating /sys
[utopia][init] Creating /dev
[utopia][init] Creating /tmp
[utopia][init] Allocating 100M for /tmp
[utopia][init] Prepairing /dev/pts
[utopia][init] Setting /tmp and /var permissions
[utopia][init] Starting udev..
[ 6.431370] orion_wdt: Initial timeout 171 sec
Attempting mount of ubifs syscfg partition
UBI device number 0, total 680 LEBs (86343680 bytes, 82.3 MiB), available 0 LEBs (0 bytes), LEB size 126976 bytes (124.0 KiB)
[utopia][init] Using persistent syscfg data from /var/config/syscfg
[utopia][init] Starting system logging
[utopia][init] Starting sysevent subsystem
net.netfilter.nf_conntrack_acct = 1
watchdog running
[utopia][init] Setting any unset system values to default
mac_setup.sh, setting up MAC addresses for all interfaces based on 60:38:E0:XX:XX:XX
NTP Servers do not need to be updated
[utopia][init] committing default syscfg values
configuring switch port to router mode
checking for interactive script start up...
Updating BootCount Page[32]:10000 ... Done

cpu temp monitor created
Thu Oct 11 06:00:00 UTC 2012
wdev0 no private ioctls.

wdev1 no private ioctls.

wan, sysevent received: wan-start
wdev0ap0 no private ioctls.

wdev0ap1 no private ioctls.

wdev0ap2 no private ioctls.

wdev0ap3 no private ioctls.

wdev1ap0 no private ioctls.

wdev1ap1 no private ioctls.

wdev1ap2 no private ioctls.

Lighttpd Model Base: WRT3200ACM
Generating Rainier lighttpd config
wifi, sysevent received: lan-started (Wed Oct 10 23:00:04 PDT 2012)
Creating /tmp/var/config/license
Build temporary www configuration directory:
wifi, service_start()
TSLIIHauhEfGE
Power cycle Ethernet ports.
Registering Service myrouter._http._tcp.local port 80
Got a reply for myrouter._http._tcp.local.: Name now registered and active
wifi, EEPROM powertables support
wifi, wdev0 regioncode: wdev0 getregioncode:16
wifi, wdev0 powertable: wdev0 gettxpower:0x00
wifi, wdev1 regioncode: wdev1 getregioncode:16
wifi, wdev1 powertable: wdev1 gettxpower:0x00
SKU is WRT3200ACM-EU
wifi, wifi_physical_start(wdev0)
Not ready for JNAP. Sleeping for 15 seconds...
[utopia] Not setting ppp_clamp_mtu
Interface doesn't accept private ioctl...
11hdfsmode (8BE0): Operation not supported
wifi_physical, iwconfig wdev0 commit
wifi, wifi_virtual_start(wdev0)
wifi, wifi_user_start(wdev0)
wifi, enable MU beam former on wdev0ap0
wifi, primary AP: wdev0ap0 is up
wifi, wifi_guest_start(wdev0)
wifi, guest wdev0ap1 is disabled, do not start wifi guest
wifi, wifi_physical_start(wdev1)
wifi_physical, iwconfig wdev1 commit
wifi, wifi_virtual_start(wdev1)
wifi, wifi_user_start(wdev1)
wifi, enable MU beam former on wdev1ap0
wifi, primary AP: wdev1ap0 is up
wifi, wifi_guest_start(wdev1)
wifi, guest wdev1ap1 is disabled, do not start wifi guest
wifi, setting WiFi Red CE settings
wifi, start_hostapd()
Configuration file: /tmp/hostapd-wdev1ap0.conf
Using interface wdev1ap0 with hwaddr 60:38:e0:XX:XX:XX and ssid "Linksys13051"
Configuration file: /tmp/hostapd-wdev0ap0.conf
Using interface wdev0ap0 with hwaddr 60:38:e0:XX:XX:XX
and ssid "Linksys13051_5GHz"
Restarting nfqrecv service...
[utopia] Not setting ppp_clamp_mtu on dslite protocol
wan, sysevent received: phylink_wan_state
Got a TERM signal, will terminate.
Warning! nfqrecv encountered errors when doing recv(): Interrupted system call
wan, sysevent received: phylink_wan_state
Power cycle Ethernet ports.
Registering Service myrouter._http._tcp.local port 80
Got a reply for myrouter._http._tcp.local.: Name now registered and active
Starting smbd ...
wan, sysevent received: phylink_wan_state
udhcpc (v1.15.2) started
Sending discover...
Sending select for 84.192.XXX.XXX...
Lease of 84.192.XXX.XXX obtained, lease time 7200
QoS auto-prioritize [info]: No networkID; skipping auto-priority update
device_registration: Received event: wan-started
Thu Oct 11 06:02:07 2012 xrac Device is not associated, exiting...
device_registration: Service started
creating server keys for OpenVPN
easy_rsa/
easy_rsa/tmp/
easy_rsa/tmp/build-key-server
easy_rsa/tmp/file
easy_rsa/tmp/vars
easy_rsa/tmp/build-key-pass
easy_rsa/tmp/inherit-inter
easy_rsa/tmp/whichopensslcnf
easy_rsa/tmp/revoke-full
easy_rsa/tmp/list-crl
easy_rsa/tmp/clean-all
easy_rsa/tmp/pkitool
easy_rsa/tmp/README.gz
easy_rsa/tmp/sign-req
easy_rsa/tmp/build-key
easy_rsa/tmp/build-req
easy_rsa/tmp/build-req-pass
easy_rsa/tmp/build-ca
easy_rsa/tmp/build-dh
easy_rsa/tmp/build-key-pkcs12
easy_rsa/tmp/build-inter
easy_rsa/tmp/openssl-0.9.6.cnf
easy_rsa/tmp/openssl-1.0.0.cnf
easy_rsa/build-key-server
easy_rsa/keys/
easy_rsa/keys/index.txt
easy_rsa/keys/serial
easy_rsa/vars
easy_rsa/build-key-pass
easy_rsa/inherit-inter
easy_rsa/whichopensslcnf
easy_rsa/revoke-full
easy_rsa/openssl-1.0.0.cnf-old-copy
easy_rsa/list-crl
easy_rsa/clean-all
easy_rsa/Makefile
easy_rsa/pkitool
easy_rsa/README.gz
easy_rsa/sign-req
easy_rsa/build-key
easy_rsa/build-req
easy_rsa/build-req-pass
easy_rsa/build-ca
easy_rsa/build-dh
easy_rsa/build-key-pkcs12
easy_rsa/build-inter
easy_rsa/openssl-0.9.6.cnf
easy_rsa/openssl-0.9.8.cnf
easy_rsa/openssl-1.0.0.cnf
NOTE: If you run ./clean-all, I will be doing a rm -rf on /tmp/openvpn/easy_rsa/keys
Using CA Common Name: Mamba
Generating a 1024 bit RSA private key
......++++++
...............++++++
writing new private key to 'ca.key'
-----
Using Common Name: Mamba
Generating a 1024 bit RSA private key
.........++++++
............++++++
writing new private key to 'server.key'
-----
Using configuration from /tmp/openvpn/easy_rsa/openssl-1.0.0.cnf
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
countryName :PRINTABLE:'US'
stateOrProvinceName :PRINTABLE:'CA'
localityName :PRINTABLE:'Irvine'
organizationName :PRINTABLE:'Linksys'
organizationalUnitName:PRINTABLE:'Belkin'
commonName :PRINTABLE:'Mamba'
name :PRINTABLE:'BlackMamba'
emailAddress :IA5STRING:'support@linksys.com'
Certificate is to be certified until Nov 5 20:15:24 2032 GMT (3650 days)

Write out database with 1 new entries
Data Base Updated
Using Common Name: client
Generating a 1024 bit RSA private key
..Belkin ICC Cron job created
..++++++
.....................................................................................++++++
writing new private key to 'client.key'
-----
Using configuration from /tmp/openvpn/easy_rsa/openssl-1.0.0.cnf
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
countryName :PRINTABLE:'US'
stateOrProvinceName :PRINTABLE:'CA'
localityName :PRINTABLE:'Irvine'
organizationName :PRINTABLE:'Linksys'
organizationalUnitName:PRINTABLE:'Belkin'
commonName :PRINTABLE:'client'
name :PRINTABLE:'BlackMamba'
emailAddress :IA5STRING:'support@linksys.com'
Certificate is to be certified until Nov 5 20:15:25 2032 GMT (3650 days)

Write out database with 1 new entries
Data Base Updated
creating server keys for OpenVPN - DONE
Device "br1" does not exist.
br1 global address not available to delete
lo global address not available to delete
device_registration: error: Failed to get token with error ErrorCloudUnavailable
device_registration: Received event: device_registered
Last edited by jaakdaniels on Wed Nov 09, 2022 7:51 am, edited 2 times in total.

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Tue Nov 08, 2022 8:40 pm

jeremys wrote:
Thu Oct 20, 2022 7:48 pm
Just wondering how long till we can expect a fix. Seems it should not be that big of a challenge. Guess it’s better to keep your fingers crossed than to hold your breath?
And It wasn't a big challenge :) You just need to know how :) Again 10 years VPN here :p

Anycolour
OpenVpn Newbie
Posts: 2
Joined: Wed Nov 09, 2022 12:37 am

Re: [Linksys] Error message: Peer certificate verification failure

Post by Anycolour » Wed Nov 09, 2022 12:38 am

jaakdaniels wrote:
Tue Nov 08, 2022 8:40 pm
jeremys wrote:
Thu Oct 20, 2022 7:48 pm
Just wondering how long till we can expect a fix. Seems it should not be that big of a challenge. Guess it’s better to keep your fingers crossed than to hold your breath?
And It wasn't a big challenge :) You just need to know how :) Again 10 years VPN here :p
Well what was the process?

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Wed Nov 09, 2022 6:55 am

Did more stuff together, so i don't know if every step is going to be usefull, but as long as it works...
The thing is, try to do as if it's first time use, out of the box. Restoring configuration will not affect the certificates AFTER they have been generated, but it certainly does BEFORE the certificates are generated.

1) Make a backup of your configuration
2) Remove the WAN cable and all other cables, leave only the cable from a LAN port to your computer to login
3) Hold "reset" pressed for 20 seconds, untill the front LED's go out and allow the router reboot (Old certificates are now erased)
4) Go to http://192.168.1.1 and login with "admin"
5) Configure the router BY HAND! Follow the steps as if it's your first time using it. The settings you do are not important
6) Follow this until the router complains about the missing WAN cable, and then connect the WAN cable
7) When the configuration is completed, download the *.ovpn file and check the "ca.crt" certificate-part
8) When it is valid you can restore your configuration. It does not affect the new certificates
9) Come back to this forum and let me know if it worked

Good luck to all!

mkruidhof
OpenVpn Newbie
Posts: 1
Joined: Wed Nov 09, 2022 10:23 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by mkruidhof » Wed Nov 09, 2022 10:33 pm

jaakdaniels,

Your instructions worked as planned on my Linksys WRT1900ACS and I was able to see that the <cert> Validity dates updated:

Issuer: C=US, ST=CA, L=Irvine, O=Linksys, OU=Belkin, CN=Mamba/name=BlackMamba/emailAddress=support@linksys.com
Validity
Not Before: Nov 9 20:14:18 2022 GMT
Not After : Nov 6 20:14:18 2032 GMT
Subject: C=US, ST=CA, L=Irvine, O=Linksys, OU=Belkin, CN=client/name=BlackMamba/emailAddress=support@linksys.com

But when I attempted to use this new *.ovpn file on my laptop, I still received the "Peer certificate verification failure".

So I looked online for a certificate decoder online <https://www.geocerts.com/certificate-decoder> and pasted in the text between -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- within the <ca> section, they reported it as :

Certificate Information:
Common Name: Mamba
Subject Alternative Names (SANs): N/A
Organization: Linksys
Locality: Irvine
State: CA
Country: US
Valid From: 2012-10-11 06:02:38 UTC
Valid To: 2022-10-09 06:02:38 UTC
Issuer: Mamba
Serial Number: 18171133334370081905
Algorithm: sha1WithRSAEncryption
Key size: 1024

It has the old expiration date of 2022-10-09 06:02:38 UTC.

Sorry, it did NOT solve my problem.

Thanks for offering a possible solution.

wombatus
OpenVpn Newbie
Posts: 9
Joined: Sat Jun 06, 2020 6:28 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by wombatus » Thu Nov 10, 2022 12:30 am

I just followed the instrructions and got the same expired CA cert results, with the 2012/2022 dates. So unless there is something else to the procedure that I missed this does not work. But thanks for trying, maybe we'll get this fixed someday.

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Thu Nov 10, 2022 6:10 am

I looked it over and it's possible that i did the manual configuration completely and rebooted it after this and then plug in the WAN cable. Only the moment the WAN cable is plugged in the certificates are made (After pressing the reset button for 20 sec) But the system clock must be in sync with the RTC. That (should) happen after configuration...

If you see the logging, the date is still at year 2012 just before te certificates are generated, so i thing it's a matter of timing.

I bought another WRT32X router yesterday to convert to WRT3200ACM on stock FW and i'll look more closely how it can be reproduced. Possible i missed something. Would be for this weekend.

Thnx for the update!

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Thu Nov 10, 2022 11:29 am

wombatus wrote:
Thu Nov 10, 2022 12:30 am
I just followed the instrructions and got the same expired CA cert results, with the 2012/2022 dates. So unless there is something else to the procedure that I missed this does not work. But thanks for trying, maybe we'll get this fixed someday.
It worked on my router, so under certain circumstances the router is able to renew all 3 certificates. Only thing, i tried so many things together that i've could have missed something. I also flashed it via serial port, but i doubt that this has effect. Also via serial i resetted the environment variables.

This evening (or tomorrow, day off) i'll try to get the other WRT32X that i bought flash to WRT3200acm and let it get faulty certificates. After that i'll try to clarify the exact procedure that worked, because my own router had proven that it is possible to generate them.

I'll keep you guys informed if there's any progress ;)

wombatus
OpenVpn Newbie
Posts: 9
Joined: Sat Jun 06, 2020 6:28 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by wombatus » Thu Nov 10, 2022 5:33 pm

When I did this, I didn't plug in the WAN cable when configuring the router (just setting it for another IP Adress range than the default). Only when I was ready to configure Open VPN did I plug in the WAN cable. I wonder it I should just stop for a bit and let the router get time sync?

When you say you used the serial port, is that the eSata port on the back? I've never tried this but I have about 6 1900 and 3200 routers lying around so it may be worth a shot. I did notice that one of the 1900ACSV2s that is used to segnent my network did have a ca with a 2032 date but I've been unable to reporduce it on any other hardware.

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Thu Nov 10, 2022 6:09 pm

If you remove the 2 screw of the front feet and pull the cover off (goes difficult sometimes) you see at the top at the right side of the PCB a white connector. Pin 1 = ground, Pin 2 = RX and pin 4 = TX at 115200 bps, no parity, 8 databits, 1 stopbit, no handshake
Connect a USB to serial adapter and you can flash the router, even play with the uboot loader. Very interesting. More info at the DDWRT-Site about how this works. You can even reprogram bricked routers.

wombatus
OpenVpn Newbie
Posts: 9
Joined: Sat Jun 06, 2020 6:28 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by wombatus » Thu Nov 10, 2022 11:29 pm

Good to know, thanks.

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Fri Nov 11, 2022 8:54 am

Meanwhile i tried and tried the upper procedure again on the second WRT3200ACM to generate certificates with no result but ca-2022 and the other 2 were intermittend 2022 and 2032. It strongly suspect it's a timing problem from Linksys FW.

So an idea, the certificate was still generated earlier than the clock and date were set. To slow this down, i kept on pressing the "WPS" button. It generates WPS events that slow the startup down and delay the creation of certificates. You could follow this with a serial connection and PUTTY.

So in brief:
- Keep the WAN cable connected
- Hold reset for 20 seconds
- When the WAN LED lights op, press/hold the "WPS" button during booting untill it's fully booted
- Check the CA-certificate

I can't guarantee it works every time or if i was lucky, but here it worked the first time i tried! I now have a second router with all 3 certificates up untill 2032, so it's proven that the router is able to generate them.
If you try, please note your results here, maybe others can benefit from this info. I am very curious if it works for other people and we have a stable workaround.

jmv_10
OpenVpn Newbie
Posts: 1
Joined: Fri Nov 11, 2022 2:52 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jmv_10 » Fri Nov 11, 2022 2:56 pm

Hello

I confirm that your last recipe WORKED on a WRT1900ac v1.
Just try 2 different times (I would recommend always pressing the wps button as soon as you release the hard reset button).
It was just my impression, because that way it worked for me.

Thanks a lot !!!!!

wombatus
OpenVpn Newbie
Posts: 9
Joined: Sat Jun 06, 2020 6:28 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by wombatus » Fri Nov 11, 2022 6:50 pm

I've tried this with both a 1900V2 and a 3200, and have had no success. I've noticed w/o the WAN cable plugged in the logs show a 2012 date, plugging it in and refreshing the logs show current (2022) date. But the main CA cert generated show 2012-2022. When I tried this wth Jaak's first method I was able to generate the plain text version of the CA with current dates, but running those through a certificate parser showed the wrong dates. I'm probably doing something that does not delay the timing but having done the new (WPS Press) procedure 4 times I don't know what that is.

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Fri Nov 11, 2022 7:02 pm

jmv_10 wrote:
Fri Nov 11, 2022 2:56 pm
Hello

I confirm that your last recipe WORKED on a WRT1900ac v1.
Just try 2 different times (I would recommend always pressing the wps button as soon as you release the hard reset button).
It was just my impression, because that way it worked for me.

Thanks a lot !!!!!
Thnx for the feedback! Enjoy another 10 years of VPN 😉

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Fri Nov 11, 2022 7:05 pm

wombatus wrote:
Fri Nov 11, 2022 6:50 pm
I've tried this with both a 1900V2 and a 3200, and have had no success. I've noticed w/o the WAN cable plugged in the logs show a 2012 date, plugging it in and refreshing the logs show current (2022) date. But the main CA cert generated show 2012-2022. When I tried this wth Jaak's first method I was able to generate the plain text version of the CA with current dates, but running those through a certificate parser showed the wrong dates. I'm probably doing something that does not delay the timing but having done the new (WPS Press) procedure 4 times I don't know what that is.
Indeed, the date in the *.ovpn file is from the 2nd and 3th certificate. The first generated is the CA cert, and it shows no date in the *.ovpn file. If the 2nd or 3th certificate showed 2032, you're close! Maybe try to hold it pressed constantly after the release of the reset button. Anyway, the WAN cable must be connected to do this procedure

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Fri Nov 18, 2022 7:13 pm

New update guys! And i think it's great news this time!

Stay tuned!

User avatar
steven424
OpenVpn Newbie
Posts: 8
Joined: Mon Oct 24, 2022 2:40 am

Re: [Linksys] Error message: Peer certificate verification failure

Post by steven424 » Sat Nov 19, 2022 3:45 am

Is it real or just an announcement? There's a large gulf between this Virtual and Reality

andrej.poljak
OpenVpn Newbie
Posts: 11
Joined: Sat Nov 19, 2022 1:58 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by andrej.poljak » Sat Nov 19, 2022 2:21 pm

Hi,

we have the same issue with Linksys WRT3200ACM firmware Ver. 1.0.8.199531.
We try everything. Factory reset. Hard reset. Hard reset then WPS, etc....

At the end we solved the issue.

We also call Linksys and tel us:
- backup the config file
- factory reset
- restore the config file
new certs will be created that will last another 10 years.

Yes and this is true, but missing one LARGE detail.
And this is NOT have connect router with WAN port anywhere.
Unplug any cable form WAN port, connect one PC to first LAN port.
Make HARD reset (pushing reset "red mini button" for 20 sec).
Wait to reset and reboot router. Then login (IP 192.168.1.1), local login, admin password.
Router will give a message no internet. Push "Ignore" to go next window.
We I login into router, I wait few minutes (5). Then I connect (internet) cable to WAN port.
Router get the right date/time. Then I go to VPN options and create one user/password.
Then download .ovpn file (not start OpenVPN server).
The CA and user certificate have 10years validate time (to 2032).
Then I restore router settings form previous made backup.
And now we have new 10years working OpenVPN.

BR,
Andrej
SLOVENIA
EUROPE

jaakdaniels
OpenVPN User
Posts: 37
Joined: Thu Oct 13, 2022 5:26 pm

Re: [Linksys] Error message: Peer certificate verification failure

Post by jaakdaniels » Sat Nov 19, 2022 3:12 pm

Hi Andrej,

Thank you for your contribution. Had the same procedure but was not successfull every time. The difference was that i was not so patiently to wait 5 minutes... The question is, in logging you see the Router resetting the RTC to Jan 01, 1970. So it had no clue of time at boot moment and can only retrieve time from the internet. This happens at nearly the same time as te certificates are generated, so it's a timing issue from Linksys. They need to retrieve time and generate certificates AFTER the NTP-time is acquired.
I guess you were lucky, like i was only one time. Don't press that reset button again mate! :)

After 7 days of testing almost everything it seems i have a stable solution, at least, it worked 2 times in a row... :)
Almost everybody has FW 1.0.8.199531 installed. Me 2. So i thought, why not going to the time things DID work. After all, the definition of an upgrade/update is solve the known bugs and add unknown bugs...


So this is my procedure that worked twice in a row:

- I downgraded to FW version 1.0.5.175944 and gave the router a factory reset. You can find the FW here
(Details: I flashed both partitions with the serial cable in uBoot, but i asume it should also work downgrading just 1 partition)
- Let it boot and log in at 192.168.1.1 (I normally use Google Chrome, but this old FW only worked on the old Internet Explorer)
- Make a VPN profile and download the certificate. Check it at https://www.sslshopper.com/certificate-decoder.html
- The certificate should be valid until Dec 1, 2023
- If this is the case, restore the "older" software. You can do this in the firmware update menu or switch the router 3 times on and off for about 3 seconds. The 4th time the router will switch to FW 1.0.8.199531 again and generate new certificates valid until 2032


Good luck!
Last edited by jaakdaniels on Sun Nov 20, 2022 12:08 pm, edited 1 time in total.

Post Reply