SSTP VeriSign Certificate problem (CA/VerifyCertificate/etc)

Hello Everybody!

Running Mikrotik >6.5 (about) I’ve big issue with valid certificate and SSTP connections

== Scenario: ==

  • Server
  • MKT SSTP Server 6.12
  • Valid VeriSign certificate (KLT)
  • Imported Intermediate certificate from Verisign (AT)
  • No “Verify Client Certificate”
  • No “Force AES”
  • Client
  • MKT SSTP Client 6.12
  • Imported Intermediate certificate from Verisign (AT)
  • No “Verify Server Certificate”
  • No problem with “Verify Server Address From Certificate” enabled/disabled

== Results ==
Connection (Windows 7 → Server) work correctly!
Connection (SSTP Client → Server) work correctly if “Verify Server Certificate” (from Client) is disabled.
If this verify option is enable, the log from client show “… handshake failed (6)” and the server not show anything about these loop connections from client.

== Note ==
https://ssltools.websecurity.symantec.com/checker/views/certCheck.jsp tool show this also if I’ve imported intermediate certificate:
Intermediate certificate missing. VeriSign Class 3 Secure Server CA - G3 | Download certificate
Your certificate chain is valid, but some older browsers may not recognize it. To support older browsers, download and install the missing intermediate certificate.

== Question ==
How can I resolve this issue or establish a SECURE connection with valid SSL certificate?

Thanks in advance!

A= authority
T= trusted
K= private key
L= crl
T= trusted


TopGun

You need the whole cert chain - you need the root CA cert also, not just the intermediate CA.

It work with Windows, because windows has both the root CA and the intermediate CA in its cert store, therefor can validate the whole cert chain.

Hello Tomaskir,

thanks for your reply.

In my previous post unfortunately I have omitted this information but the cert chain is complete.
Unluckily the problem remains and the question is again:
How can I resolve this issue or establish a SECURE connection with valid SSL certificate?

Thanks in advance.

Regards.

Hello Mikrotik users!

It is useless a VPN / SSTP solution without “real” SSL…
I’m starting to think that mikrotik is not really professional and safe… :confused:

Any idea about this?
Thanks

Hello everybody!

I have seen that yesterday has been released the new version of RouterOS (6.13).
I have red the changelog but there isn’t a solution for the issue that I have indicated in my post.

Anyone have a suggest/idea/solution?

Waiting for a reply…

Best Regards.
Top

Good Morning,

with the new release of Mikrotik (6.13) I’he the follow error every 180sec :

“Encryption got out of sync”
“sstp disabling encoding mppe128 stateless”

and the issue with “CA/public/real certificates aren’t recognized” is still present!

:open_mouth: :open_mouth: :open_mouth:

Downgrade to 6.12 is essential for fix this new/other SSTP bug

Have same issue with Comodo Positive SSL. Root and intermediate certificates installed as well. For some reason, Mikrotik do not provide chain to users and clients get error. Workaroud: import intermediate certificates to clients machine as well. Was working fine before 6.15.