To configure the OpenVPN client on your remote sites (in our case: site 2 in Paris), you will need the certificates exported previously.
As a reminder, you need:
To import the certificate of the internal certification authority created on site 1, go to the "System -> Cert Manager" menu on site 2 (Paris).
Important : as a reminder, screen prints on a black background concern site 2 (Paris) and those on a white background concern site 1 (Brussels).
Go to the "CAs" tab and click: Add.
In the "Create / Edit CA" section, configure the settings like this:
In the "Existing Certificate Authority" section, you will need to paste your CA certificate into the "Certificate data" box.
To do this, open the certificate of your internal certificate authority (CA) with notepad.
Since the certificate is in PEM format, it can be opened with a simple text editor.
Copy its contents including the "BEGIN CERTIFICATE" and "END CERTIFICATE" lines.
Paste its contents into the "Certificate data" box and click Save.
The certificate of your internal certification authority (CA) appears in the list and pfSense displays its full name, ...
Important : this certificate is necessary so that OpenVPN can verify the signature of client certificates using the public key of your certification authority.
Note that you will not be able to create certificates from this site since you only have the public key of this certification authority.
To import the certificate that your future OpenVPN client will use, go to "Certificates" and click: Add/Sign.
In the "Add/Sign a New Certificate" section, indicate the following:
Then, in the "Import Certificate" section:
Open the client certificate (.crt) and its associated private key (.key) with Notepad.
Complete these fields:
Then, click Save.
Your client certificate appears.
Firewall 8/13/2025
Firewall 9/3/2025
Firewall 9/10/2025
Firewall 6/6/2025
Pinned content
Contact
® InformatiWeb-Pro.net - InformatiWeb.net 2008-2022 - © Lionel Eppe - All rights reserved.
Total or partial reproduction of this site is prohibited and constitutes an infringement punishable by articles L.335-2 and following of the intellectual property Code.
No comment