Josh
2016-05-26 03:54:45 UTC
Greetings,
I have created CA, client and server certificates using TinyCA2 default
settings two years ago and they were working fine.
Upon renewal no client is able to connect. Searching the list I came
across
http://readlist.com/lists/lists.sourceforge.net/openvpn-users/3/17633.html
, added "serverAuth, clientAuth" to extendedKeyUsage settings in TinyCA2
and created new client certificate - no changes. Should I create new
server certificate as well?
In general, how does one verify extendedKeyUsage extensions?
Regards,
Josh.
I have created CA, client and server certificates using TinyCA2 default
settings two years ago and they were working fine.
Upon renewal no client is able to connect. Searching the list I came
across
http://readlist.com/lists/lists.sourceforge.net/openvpn-users/3/17633.html
, added "serverAuth, clientAuth" to extendedKeyUsage settings in TinyCA2
and created new client certificate - no changes. Should I create new
server certificate as well?
In general, how does one verify extendedKeyUsage extensions?
Regards,
Josh.