Page 1 of 1

Dynamic DNS error message related to server certificates

Posted: Mon Dec 17, 2018 6:50 pm
by lylinformatica
Hello:

First of all, I've not found a similar problem in the forum, but if someone find something similar, please make me know.
Second, excuse my poor english.
Third, the problem is that I've this error messaje in the Dynamic DNS Function windows of one of my VPN servers (see attached file).
error dynamiic dns vpn.PNG
The full text says:
"Unable to trust the certificate provided by the destination server. The setting to always verify the server certificate is enabled in the VPN Connection Settings. Either register a root certificate that can be trusted or register a individual certificate."

The xxxxxxxxxx.vpnazure.net works well (slow), but the xxxxxxxxx.softether.net do not work at all.
Public iP from WAN side is OK.

Any clue....

Thanks a lot.

Re: Dynamic DNS error message related to server certificates

Posted: Mon Dec 17, 2018 11:26 pm
by davidebeatrici
Hello,

It's possible that your network's gateway is acting as a MiTM SSL proxy.

Are you the owner of the network?

Best regards,
Davide

Re: Dynamic DNS error message related to server certificates

Posted: Tue Dec 18, 2018 9:43 am
by lylinformatica
Hi,
I don't know for sure, but I don't think so.
I'll check that in the firewall.

Thanks.

Re: Dynamic DNS error message related to server certificates

Posted: Tue Dec 18, 2018 3:44 pm
by lylinformatica
Hello:
Nothing leads to a problem with an SSL Proxy that don't seem to exist.

The message says that there are untrusted certificates that dont allow to register the VPN server in Dynamic DNS service...

Any help?

Re: Dynamic DNS error message related to server certificates

Posted: Tue Dec 18, 2018 4:24 pm
by lylinformatica
Hello everyone:

More info for diagnostics...

Usin the public WAN ip WORKS!

Also using a no-ip.com domain (that points to public WAN ip).

But Dynamic DNS service from softether do not.

Thanks

Re: Dynamic DNS error message related to server certificates

Posted: Thu Jan 24, 2019 6:24 am
by thisjun
Nothing leads to a problem with an SSL Proxy that don't seem to exist.
The DDNS service registry work on HTTPS.
So, if there is MITM, DNS registry fails.