I added more info to the Winbox 3.24 topic about this issue. [again at 14:35 after more testing]
It appears it requires a complex/busy router to reproduce.
Does anybody knows when this decrease was introduced?
We have two links with 6.45.9, 802.11ac, dual chain, -48, 20/40/80, CCQ around 100% and we cannot get more than 140mbits with nstream (when the radios are connected on 650 mbits).
Issue was introduced in all 6.46.x versions, everything was fine in all 6.45.x versions. So in switch from 6.45 to 6.46 …
Does anyone has problem with CRL with this release?
It seems that my router does not get the latest crl as the last date of update is older and now the crl appears as invalid in the crl tab.
The only error I got is the DoH server connection error. SSL handshake failed: unable to get certificate CRL.
If I uncheck Verify DoH Certificate in the DNS setting tab, it works.
I am using cloudflare DOH and I have uploaded the cloudflare certificate. All the regular DOH DNS queries work normally even with the verify DOH certificate option. Only CRL download does not.
Had the same issue. Stopped using DOH and cloudflare until they sort it out. Guess you could use it without certs and not validate the certs you have and it would be fine. It appears that the certs expire before it can renew them and once they expire you are basically locked out of cloudflare unless you turn off using the cert validation or just use the normal 1.1.1.1 to get DNS to allow you to download the new CRL files and then you can turn things back on again.
…
I am using cloudflare DOH and I have uploaded the cloudflare certificate. All the regular DOH DNS queries work normally even with the verify DOH certificate option. Only CRL download does not.
Not having any issues with DoH cert validation (AC^2, 6.47).
I uploaded certs for both Google DNS and 1.1.1.1 - but not the leaf certs, rather the intermediate and root certs.
For Google, the intermediate is “GTS CA 1O1” expires “Dec/15/2021” and its root cert is “GlobalSign Root CA - R2” expires “Dec/15/2021”.
For Cloudflare, it’s " DigiCert ECC Secure Server CA" expires “Mar/08/2023” and “DigiCert Global Root CA” expires “Nov/10/2031”.
Both chains can be obtained using a web browser and doing “export certificate chain” from viewing the site’s properties and then certificate (at least that’s the UI in Chrome).
The intermediate certs are probably not needed since they’re sent by both (Google and CloudFlare) servers, only the root certs should be necessary, but I’ve already got both imported…
I can confirm that cloudflare https://1.1.1.1/dns-query works perfectly only with root cert “DigiCert Global Root CA”.
Pea, I can also confirm that it ‘did’ work using the proper URL and CRL’s. But over time I would start getting errors and it was because the router could not download the updated CRL info cause the old ones were perhaps not valid, so basically I was locked out from getting the downloads since the router could not query cloudflare with the certs I had downloaded previously. I had to disable DOH and let the router just use 1.1.1.1 as normal DNS and then it downloaded the CRL info and once I turned DOH back on, it was fine again…until the next event where it happened again.
New version 6.47.1 has been released in stable RouterOS channel:
http://forum.mikrotik.com/t/v6-47-1-stable-is-released/141227/1