Forums

zhura
zhura
Offline
Resolved
0 votes
please i need help with expired system sertificate renewal
openvpn says:
Nov 18 15:17:54 system openvpn[2474]: VERIFY ERROR: depth=0, error=certificate has expired
when i select "renew" from system->certificate manager->system certificate
clearos creates some -cert.pem
what is my next step?
In OpenVPN
Thursday, November 18 2021, 05:14 PM
Share this post:
Responses (3)
  • Accepted Answer

    Friday, November 19 2021, 08:33 AM - #Permalink
    Resolved
    0 votes
    5.0.2!!!! This is antique. You didn't even get as far as 5.1! Seriously, this must have so many vulnerabilities now. Isn't it still branded Clarkconnect? I seem to remember it became ClearOS at 5.1. Really you must upgrade.
    The reply is currently minimized Show
  • Accepted Answer

    zhura
    zhura
    Offline
    Friday, November 19 2021, 05:52 AM - #Permalink
    Resolved
    0 votes
    thanks for answer.

    i've manually switched sys-0-cert.pem with -cert.pem and restarted clearos and now it works fine

    /etc/pki/CA is empty sertificates found in /etc/ssl:
    [root@system ssl]# openssl x509 -dates -noout -in /etc/ssl/sys-0-cert.pem
    notBefore=Nov 18 08:58:46 2021 GMT
    notAfter=Nov 16 02:31:34 2031 GMT

    clearos enterprise 5.0.2 :(
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, November 18 2021, 05:31 PM - #Permalink
    Resolved
    0 votes
    If it creates a new sys-0-cert.pem, all you should have to do is restart OpenVPN. If it also created a new ca-cert.pem then all user certificates need to be regenerated. What does this give:
    openssl x509 -dates -noout -in /etc/pki/CA/sys-0-cert.pem
    The reply is currently minimized Show
Your Reply