Hello,
I am using the native ACME client in RouterOS v7 to provision Let's Encrypt certificates for an IKEv2 VPN server. I am struggling with automatic renewals when Let's Encrypt rotates their intermediate CAs (e.g., recently switching from R13/R14 to YR1).
When this rotation happens, the ACME client renews the certificate, but my setup fails to build the correct certificate chain for the VPN service. Because the new intermediate CA is missing clients are droped with an AUTH_FAILED error because they don't receive the required Let's Encrypt intermediate cert.
It really should work this way?
-
Manually fetch and import the new Let's Encrypt intermediate certificate.
-
Manually delete the old intermediate certificates from mkt.
-
Re-link the renewed certificate in
/ip ipsec identityif the binding broke during the process.
Since ACME is designed for full automation, having to manually intervene and debug VPN connection failures every 60-90 days defeats the purpose.
Is there a proper, fully automated way to handle this?
How do you ensure that the correct intermediate CA is automatically fetched, trusted, and seamlessly chained by the IKEv2 service upon renewal? Is a custom scheduler script the only reliable workaround for this cleanup and re-linking, or am I missing a specific configuration step?
My hw is RB760iGS, with ROS 7.24.4
Thanks for advice, or best practices how it should be done