• April 16, 2024, 02:43:46 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Certificate key (PEM) for OpenVPN  (Read 27974 times)

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov
Certificate key (PEM) for OpenVPN
« on: October 21, 2012, 07:59:21 PM »

Good day
I'm using F/W 1.05B53_WW at DSR-250N
Now i need to configure OpenVPN client using certificates
For this client, i have previously created files ca.crt, client.crt, client.key. Last file was converted to PEM format by command openssl rsa -in client.key -out client.pem
At the "OpenVPN auth" menu, i've uploaded CA/client certificates (CRT files) normally, but client key (PEM) always failed with message "upload failed"
How do i need to prepare PEM file to be able upload this?
Logged
BR, Alexandr Danilov

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Certificate key (PEM) for OpenVPN
« Reply #1 on: October 22, 2012, 07:35:24 AM »

You should contact D-Link supported direct, level 2, about this.
« Last Edit: October 28, 2012, 01:43:41 PM by FurryNutz »
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov
Re: Certificate key (PEM) for OpenVPN
« Reply #2 on: October 27, 2012, 11:34:23 PM »

Any news about this issue?
Logged
BR, Alexandr Danilov

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Certificate key (PEM) for OpenVPN
« Reply #3 on: October 28, 2012, 01:43:20 PM »

Have you contacted DLink support level 2 yet?
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov
Re: Certificate key (PEM) for OpenVPN
« Reply #4 on: October 28, 2012, 01:53:29 PM »

Actually, my local D-Link office had no direct idea about this.
They propose to try certificates generated by other solution, but i'm not sure will it help or not.

How can i contact any global support?
Logged
BR, Alexandr Danilov

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Certificate key (PEM) for OpenVPN
« Reply #5 on: October 28, 2012, 01:59:19 PM »

I would try email support if you haven't done that already. If you dont' seem to get any feedback, let me know and I'll forward this onto D-Link USA here and see if anyone here can help. You might try submitting a email ticket on the U.S. site and see if you get any feedback.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

Thiesy

  • Level 1 Member
  • *
  • Posts: 5
Re: Certificate key (PEM) for OpenVPN
« Reply #6 on: November 18, 2012, 11:44:34 AM »

A few days ago I installed FW 1.05B73 and finally got my openVPN server running. I also am using certificates/keys generate with scripts supplied with the openVPN software for Win from Openvpn.net.

I also experienced the problem you describe.

I solved it with the free software from Christian Hohnstädt at http://xca.sourceforge.net/

I imported the key and exported it into PEM format using the PKCS#8 option. The generated file worked with the above FW.


Jörg
« Last Edit: November 18, 2012, 11:46:18 AM by Thiesy »
Logged
DSR-250N
DAP-1522
DAP-2310
DGS-1210-16

nickaardo

  • Level 1 Member
  • *
  • Posts: 3
Re: Certificate key (PEM) for OpenVPN
« Reply #7 on: November 22, 2012, 12:23:30 PM »

worked for me too...
Thanks for this important tip !
Logged

ddywz

  • Level 1 Member
  • *
  • Posts: 12
Re: Certificate key (PEM) for OpenVPN
« Reply #8 on: December 07, 2012, 08:07:46 AM »

FW version 1.05B73 is posted on german support site of DLink.  Does anyone know if it is ok to upgrade to this version a US based router?  Latest version posted for US is 1.05B20.  Does FW 1.05B73 has an english language menu?

I'd like to setup OpenVPN and I read that only this new version of fw works fine for it.

Thanks,
« Last Edit: December 07, 2012, 08:24:57 AM by ddywz »
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: Certificate key (PEM) for OpenVPN
« Reply #9 on: December 07, 2012, 08:51:27 AM »

I see that EN and ALL is in the file name. I presume it would work and is in English or has English language UI options. DSR-250N_fw_revALL_1-05B73_all_en_20121112

Read the release notes file for fixes.
I would play it safe, save off the current configruation to file, then do a factory reset, update FW, Factory reset once more then configure the router from scratch. There maybe differences between the FW versions and config files that may warrant a clean setup from scratch.

Let us know how it works for you.
« Last Edit: December 07, 2012, 08:56:53 AM by FurryNutz »
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

danilovav

  • Level 4 Member
  • ****
  • Posts: 424
  • Alexandr Danilov
Re: Certificate key (PEM) for OpenVPN
« Reply #10 on: December 07, 2012, 11:49:59 AM »

There are only one special logic - if you upgrade F/W to different region with previous one, device will be reseted to defaults. So, it seems maximum problem you can get.
Logged
BR, Alexandr Danilov