Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Cihat_Bulut
Contributor
Contributor

Avoid fingerprint warning after certificate renewal

Hello,

If you don’t want VPN clients to receive warnings every time the server certificate changes, don’t import only the server certificate. Instead, include the root and intermediate certificates within the server certificate itself. You can do this using the command below.

Assume you have one SubCA: 

cat SubCA.crt rootCA.crt >> fullchain.crt 

cpopenssl pkcs12 -export -inkey private.key  -in cert.crt   -certfile fullchain.crt   -name "myCert"   -out mycert.p12

Import this file into the Mobile Portal. The fingerprint shown will correspond to the Root CA.

After this, you won’t see any warnings as long as the Root CA remains the same.

 

 

 

0 Kudos
3 Replies
the_rock
MVP Platinum
MVP Platinum

Excellent, thank you for that @Cihat_Bulut 

Best,
Andy
0 Kudos
Lesley
MVP Gold
MVP Gold

Thanks for the tip first of all.

Only thing I would like to add if you use a fail chain will give an anchor warning in SSL labs. 

Instructions
 
-------
Please press "Accept as Solution" if my post solved it 🙂
the_rock
MVP Platinum
MVP Platinum

Excellent points @Lesley 

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events