Client Certificate for OpenVPN

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
dedidata
Posts: 1
Joined: Tue Jul 02, 2019 11:04 am

Client Certificate for OpenVPN

Post by dedidata » Tue Jul 02, 2019 11:20 am

Hi,
I set up the OpenVPN and I use generated file on my Windows and also my Android app
Everythings are ok on the Windows and I don't get any warning when I connect
But on the Android, Every time I want to connect, I get this warning:

This profile doesn't include a client certificate. Continue connecting without a certificate or select one from the Android keychain

There are 2 options of CONTNUE and SELECT CERTIFICATE (Select Doesn't work - nothing happen!)
Although I can connect by pushing on "CONTNUE", but I prefer to connect using a certificate,
I have another OPEN VPN profile, which I use User/Pass for authentication But it has a certificate in the profile for the client, And when I connect using it, I don't get any warning

So How can I generate a client certificate and include it in my Open VPN profile?
Thank you

thisjun
Posts: 2458
Joined: Mon Feb 24, 2014 11:03 am

Re: Client Certificate for OpenVPN

Post by thisjun » Tue Jul 09, 2019 5:21 am

SoftEther VPN doesn't support cert auth with OpenVPN.

WideOpen
Posts: 2
Joined: Wed Aug 14, 2019 9:22 pm

Re: Client Certificate for OpenVPN

Post by WideOpen » Wed Aug 14, 2019 9:33 pm

you will need to add a dummy client cert to the profile.
The latest version of seems to not do this when you export the profile

add this to the end of it

###############################################################################
# The client certificate file (dummy).
#
# In some implementations of OpenVPN Client software
# (for example: OpenVPN Client for iOS),
# a pair of client certificate and private key must be included on the
# configuration file due to the limitation of the client.
# So this sample configuration file has a dummy pair of client certificate
# and private key as follows.

<cert>
-----BEGIN CERTIFICATE-----
MIICxjCCAa4CAQAwDQYJKoZIhvcNAQEFBQAwKTEaMBgGA1UEAxMRVlBOR2F0ZUNs
aWVudENlcnQxCzAJBgNVBAYTAkpQMB4XDTEzMDIxMTAzNDk0OVoXDTM3MDExOTAz
MTQwN1owKTEaMBgGA1UEAxMRVlBOR2F0ZUNsaWVudENlcnQxCzAJBgNVBAYTAkpQ
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5h2lgQQYUjwoKYJbzVZA
5VcIGd5otPc/qZRMt0KItCFA0s9RwReNVa9fDRFLRBhcITOlv3FBcW3E8h1Us7RD
4W8GmJe8zapJnLsD39OSMRCzZJnczW4OCH1PZRZWKqDtjlNca9AF8a65jTmlDxCQ
CjntLIWk5OLLVkFt9/tScc1GDtci55ofhaNAYMPiH7V8+1g66pGHXAoWK6AQVH67
XCKJnGB5nlQ+HsMYPV/O49Ld91ZN/2tHkcaLLyNtywxVPRSsRh480jju0fcCsv6h
p/0yXnTB//mWutBGpdUlIbwiITbAmrsbYnjigRvnPqX1RNJUbi9Fp6C2c/HIFJGD
ywIDAQABMA0GCSqGSIb3DQEBBQUAA4IBAQChO5hgcw/4oWfoEFLu9kBa1B//kxH8
hQkChVNn8BRC7Y0URQitPl3DKEed9URBDdg2KOAz77bb6ENPiliD+a38UJHIRMqe
UBHhllOHIzvDhHFbaovALBQceeBzdkQxsKQESKmQmR832950UCovoyRB61UyAV7h
+mZhYPGRKXKSJI6s0Egg/Cri+Cwk4bjJfrb5hVse11yh4D9MHhwSfCOH+0z4hPUT
Fku7dGavURO5SVxMn/sL6En5D+oSeXkadHpDs+Airym2YHh15h0+jPSOoR6yiVp/
6zZeZkrN43kuS73KpKDFjfFPh8t4r1gOIjttkNcQqBccusnplQ7HJpsk
-----END CERTIFICATE-----

</cert>

<key>
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEA5h2lgQQYUjwoKYJbzVZA5VcIGd5otPc/qZRMt0KItCFA0s9R
wReNVa9fDRFLRBhcITOlv3FBcW3E8h1Us7RD4W8GmJe8zapJnLsD39OSMRCzZJnc
zW4OCH1PZRZWKqDtjlNca9AF8a65jTmlDxCQCjntLIWk5OLLVkFt9/tScc1GDtci
55ofhaNAYMPiH7V8+1g66pGHXAoWK6AQVH67XCKJnGB5nlQ+HsMYPV/O49Ld91ZN
/2tHkcaLLyNtywxVPRSsRh480jju0fcCsv6hp/0yXnTB//mWutBGpdUlIbwiITbA
mrsbYnjigRvnPqX1RNJUbi9Fp6C2c/HIFJGDywIDAQABAoIBAERV7X5AvxA8uRiK
k8SIpsD0dX1pJOMIwakUVyvc4EfN0DhKRNb4rYoSiEGTLyzLpyBc/A28Dlkm5eOY
fjzXfYkGtYi/Ftxkg3O9vcrMQ4+6i+uGHaIL2rL+s4MrfO8v1xv6+Wky33EEGCou
QiwVGRFQXnRoQ62NBCFbUNLhmXwdj1akZzLU4p5R4zA3QhdxwEIatVLt0+7owLQ3
lP8sfXhppPOXjTqMD4QkYwzPAa8/zF7acn4kryrUP7Q6PAfd0zEVqNy9ZCZ9ffho
zXedFj486IFoc5gnTp2N6jsnVj4LCGIhlVHlYGozKKFqJcQVGsHCqq1oz2zjW6LS
oRYIHgECgYEA8zZrkCwNYSXJuODJ3m/hOLVxcxgJuwXoiErWd0E42vPanjjVMhnt
KY5l8qGMJ6FhK9LYx2qCrf/E0XtUAZ2wVq3ORTyGnsMWre9tLYs55X+ZN10Tc75z
4hacbU0hqKN1HiDmsMRY3/2NaZHoy7MKnwJJBaG48l9CCTlVwMHocIECgYEA8jby
dGjxTH+6XHWNizb5SRbZxAnyEeJeRwTMh0gGzwGPpH/sZYGzyu0SySXWCnZh3Rgq
5uLlNxtrXrljZlyi2nQdQgsq2YrWUs0+zgU+22uQsZpSAftmhVrtvet6MjVjbByY
DADciEVUdJYIXk+qnFUJyeroLIkTj7WYKZ6RjksCgYBoCFIwRDeg42oK89RFmnOr
LymNAq4+2oMhsWlVb4ejWIWeAk9nc+GXUfrXszRhS01mUnU5r5ygUvRcarV/T3U7
TnMZ+I7Y4DgWRIDd51znhxIBtYV5j/C/t85HjqOkH+8b6RTkbchaX3mau7fpUfds
Fq0nhIq42fhEO8srfYYwgQKBgQCyhi1N/8taRwpk+3/IDEzQwjbfdzUkWWSDk9Xs
H/pkuRHWfTMP3flWqEYgW/LW40peW2HDq5imdV8+AgZxe/XMbaji9Lgwf1RY005n
KxaZQz7yqHupWlLGF68DPHxkZVVSagDnV/sztWX6SFsCqFVnxIXifXGC4cW5Nm9g
va8q4QKBgQCEhLVeUfdwKvkZ94g/GFz731Z2hrdVhgMZaU/u6t0V95+YezPNCQZB
wmE9Mmlbq1emDeROivjCfoGhR3kZXW1pTKlLh6ZMUQUOpptdXva8XxfoqQwa3enA
M7muBbF0XN7VO80iJPv+PmIZdEIAkpwKfi201YB+BafCIuGxIF50Vg==
-----END RSA PRIVATE KEY-----

</key>

macbookprouser
Posts: 2
Joined: Tue Aug 20, 2019 10:06 pm

Re: Client Certificate for OpenVPN

Post by macbookprouser » Tue Aug 20, 2019 10:16 pm

Hmm,

Tried adding dummy CERT's but no luck. No stuck on trying to establish connection and then time out.
Would like to check log information on connection attempts, any suggestions?

I am using macbook Pro and Mojave

Cheers

Safdar
Posts: 5
Joined: Tue Aug 13, 2019 6:01 am
Location: Lahore
Contact:

Re: Client Certificate for OpenVPN

Post by Safdar » Wed Aug 21, 2019 2:27 pm

dedidata wrote:
Tue Jul 02, 2019 11:20 am
Hi,
I set up the OpenVPN and I use generated file on my Windows and also my Android app
Everythings are ok on the Windows and I don't get any warning when I connect
But on the Android, Every time I want to connect, I get this warning:

This profile doesn't include a client certificate. Continue connecting without a certificate or select one from the Android keychain

There are 2 options of CONTNUE and SELECT CERTIFICATE (Select Doesn't work - nothing happen!)
Although I can connect by pushing on "CONTNUE", but I prefer to connect using a certificate,
I have another OPEN VPN profile, which I use User/Pass for authentication But it has a certificate in the profile for the client, And when I connect using it, I don't get any warning

So How can I generate a client certificate and include it in my Open VPN profile?
Thank you
Dear Use Stable Softether VPN Server Software... Not Beta Version...

Post Reply