Update - got it working. I think the problem was that the fully qualified domain name didn't match.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: viragomann on June 03, 2025, 09:47:54 PMBut possibly you get the same error if the client cannot use the private key. Is it installed properly?
Quote from: viragomann on June 03, 2025, 09:47:54 PMWhich client software are you using?
Does it use a recent OpenSSL version?
Quote from: viragomann on June 03, 2025, 09:05:49 PMSo search for it in OPNsense > System > Trust > Certificates.
Is it shown there as "in use" by a user?
And is the purpose "clientAuth"?
Quote from: viragomann on June 03, 2025, 07:31:09 PMWhich certificate is mentioned in the error message? Is it the server cert or the client cert?
Quote from: viragomann on June 03, 2025, 08:28:35 PMThe error mentioned the whole cert details like common name (CN) and organisation (O). You should be able to determine which it is from this.
Quote from: viragomann on June 03, 2025, 08:48:48 PMCNs have to be unique for each client and the server.
Quote from: viragomann on June 03, 2025, 07:31:09 PMWhich certificate is mentioned in the error message? Is it the server cert or the client cert?
Quote from: viragomann on June 03, 2025, 08:28:35 PMThe error mentioned the whole cert details like common name (CN) and organisation (O). You should be able to determine which it is from this.
Quote from: viragomann on June 03, 2025, 07:31:09 PMWhich certificate is mentioned in the error message? Is it the server cert or the client cert?
Quote from: viragomann on June 03, 2025, 06:31:06 PMQuote from: julf on June 03, 2025, 06:28:39 PMI generated a client certificate, then set up an OpenVPN instanceThis could be a server or a client.
??
Where do you see the error??
Quote from: viragomann on June 03, 2025, 05:37:34 PMQuote from: julf on June 03, 2025, 05:07:51 PMerror=unsuitable certificateThis should be the hint.
purpose
Did you assign a server certificate?
Quote from: viragomann on June 03, 2025, 06:18:21 PMYes.
However, you were not clear about what you really did and where you get this error.
Quote from: viragomann on June 03, 2025, 05:37:34 PMQuote from: julf on June 03, 2025, 05:07:51 PMerror=unsuitable certificateThis should be the hint.
purpose
Did you assign a server certificate?
2025-06-03 16:54:10 VERIFY ERROR: depth=0, error=unsuitable certificate
purpose: C=NL, ST=NH, L=Amsterdam, O=#########,
emailAddress=#########, CN=######, serial=4
2025-06-03 16:54:10 OpenSSL: error:0A000086:SSL routines::certificate
verify failed
Quote from: dseven on January 30, 2025, 10:55:09 AMIs it possible the menu is exceeding available screen real estate? Try expanding the menu (">" button at the top) if it's expanded, and see if that helps? Otherwise, screenshots?