Community discussions

MikroTik App
 
reciphergroup
just joined
Topic Author
Posts: 1
Joined: Wed Oct 07, 2015 2:21 am

SSTP VPN CA certificate import problem

Wed Oct 07, 2015 2:34 am

Hi there,

I am new to MikroTik. Recently, I was configuring SSTP site-to-site VPN follow the tutorial on http://wiki.mikrotik.com/wiki/Manual:In ... -Site_SSTP. Then, I found a problem when I try to import CA certificate to the Client Router. The flags of CA certificate in Client only showed KLT, A-Authority was missing. So the client cannot recognize the CA certificate and the handshake failed , error message was "unable to get issuer certificate locally - CA certificate is not imported locally."

Can someone tell me how to fix it ?

Regard.
 
jaytcsd
Member
Member
Posts: 332
Joined: Wed Dec 29, 2004 9:50 am
Location: Pittsboro IN
Contact:

Re: SSTP VPN CA certificate import problem

Sun Nov 08, 2015 9:49 pm

I don't have much luck with the wikis.

This site may have the answer, have not had a chance to try his way. I tried 3 or 4 wiki articles on SSTP and never got it working.

http://www.nasa-security.net/mikrotik/sstp/

I found a youtube video for site to site SSTP VPN last week but did not bookmark it and now I don't see it, it was done by a firm in Australia but the guy did not sound like an Aussie.
 
User avatar
anthonws
Frequent Visitor
Frequent Visitor
Posts: 76
Joined: Sat Jan 09, 2016 6:46 pm

Re: SSTP VPN CA certificate import problem

Sat Jan 09, 2016 7:02 pm

Is it possible to setup a SSTP VPN (not site to site) using a wildcard certificate (i.e. *.domain.com)?

And has anyone used certificates from DigiCert to establish a SSTP VPN in RouterOS? If yes, can anyone please provide some pointers for a n00b? :P

Much appreciated and sorry for the thread hijack!

Cheers,
anthonws.

Who is online

Users browsing this forum: jaclaz and 105 guests