Community discussions

MikroTik App
 
VaMpIrEKiNg
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 57
Joined: Sat Dec 10, 2016 6:56 am

How according to openvpn.conf to import certificates to ROS?

Mon Dec 19, 2016 3:20 pm

I bought a vpn service and they provide me the conf file only, How to convert the conf to ROS?
openvpn.conf content as blew:

setenv FORWARD_COMPATIBLE 1
setenv UV_SERVERID 352
client
dev tun
proto udp
remote 118.163.202.118 8292
nobind
persist-key
persist-tun
ns-cert-type server
key-direction 1
push-peer-info
comp-lzo
explicit-exit-notify
verb 3
mute 20
reneg-sec 86400
mute-replay-warnings
max-routes 1000
<ca>
-----BEGIN CERTIFICATE-----
MIIEFTCCAv2gAwIBAgIJAOt26+6pZCokMA0GCSqGSIb3DQEBCwUAMGQxCzAJBgNV
BAYTAi4uMQswCQYDVQQIEwIuLjELMAkGA1UEBxMCLi4xCzAJBgNVBAoTAi4uMQsw
CQYDVQQLEwIuLjEOMAwGA1UEAxMFQVNDQTIxETAPBgkqhkiG9w0BCQEWAi4uMB4X
DTE0MDQxMTIwNTgwMloXDTI0MDQwODIwNTgwMlowZDELMAkGA1UEBhMCLi4xCzAJ
BgNVBAgTAi4uMQswCQYDVQQHEwIuLjELMAkGA1UEChMCLi4xCzAJBgNVBAsTAi4u
MQ4wDAYDVQQDEwVBU0NBMjERMA8GCSqGSIb3DQEJARYCLi4wggEiMA0GCSqGSIb3
DQEBAQUAA4IBDwAwggEKAoIBAQC1gI7za3IjgZeUlOyMypx+vuABzGWANEW2Z0uK
/uOHEIxwB4/Xvaf+Xo3y416fayyo+dlPE/iFapKZCGRQbf/88YaK2ZTEgsMR9awX
eeP50rKD/9pJPf2fLDzbNnHYz5oF0oKzwc3msU2s/1xCCqSv8NoSpyqivA088UFd
OCuowps4QxQvc8jAdfO8saajnvsG/aXRMwJapuZ10G2ia6Ln9DYnM79Qg0iFzzGP
Q0EOE64eecqEeHmKgGTFl4VavfVkspgBhxn0c6ss1K8vS+J3sLth9XP1gMb0qNQz
Dfsz6KwxTJ/3p5OorCbNjW+HINT2+GZXrD+GOm4tBgEG+Dw9AgMBAAGjgckwgcYw
HQYDVR0OBBYEFHKIZ9TwU70GU9QzuQ9MsUFNjqkRMIGWBgNVHSMEgY4wgYuAFHKI
Z9TwU70GU9QzuQ9MsUFNjqkRoWikZjBkMQswCQYDVQQGEwIuLjELMAkGA1UECBMC
Li4xCzAJBgNVBAcTAi4uMQswCQYDVQQKEwIuLjELMAkGA1UECxMCLi4xDjAMBgNV
BAMTBUFTQ0EyMREwDwYJKoZIhvcNAQkBFgIuLoIJAOt26+6pZCokMAwGA1UdEwQF
MAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJKHXc4JABvR0bC4u56eTzTi+tQtzyl1
I2Sb2RwV5Z99QibIf1CwAUo6cO7TZUheDCBQ2zT9EvbBk6LH2HL8gRX5bRFMdEMU
8dAVBp01d6RWmwRA5X9LgjTzxaCiRPnfzpMBLlYT5SXwqVdHT6hniCr6QkLHIosU
WXBjRX3c7I0YlMxCIigUzkelJhMTsr9D8eRNtDsS2UvsfkCvh2gn6wZiUfZJIMFJ
rKWYJfvn1DN9Ri0k1OaryfEAeplsvxSj3nGC8kN5df9tnhU/kuei1rR7tYUiajMF
DWqvB+wv9DtX42uWOd4i4kmuivuw5zTMZFVborRUbO3IlODkx4sgRAE=
-----END CERTIFICATE-----
</ca>
<cert>
-----BEGIN CERTIFICATE-----
MIIEGzCCAwOgAwIBAgIDDBnEMA0GCSqGSIb3DQEBCwUAMGQxCzAJBgNVBAYTAi4u
MQswCQYDVQQIEwIuLjELMAkGA1UEBxMCLi4xCzAJBgNVBAoTAi4uMQswCQYDVQQL
EwIuLjEOMAwGA1UEAxMFQVNDQTIxETAPBgkqhkiG9w0BCQEWAi4uMB4XDTE2MDcz
MTA5MDUwMVoXDTI2MDczMDA4MDUwMVowLDEqMCgGA1UEAxMhQVMxNjk2MTU5LTIx
NTY0NTIyNzRFQi1GOTM3MjIxNzQyMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB
CgKCAQEAvxAT8CUdsNA1w1jLpZog864KrOAY5aUl5O0OtmoXLANrIAVWOHLN6++H
lVtRmf5R2EaER7Yjy7dkEeW89ukvNerNBA2qgTYZdyLR4jwIPYXwY/RgaxUqr6FQ
+PigRUhGB0+pr+lnJW6KUldSLTcM4du62hVrzwmnNf2l3uBAB3Aem6S1vLQvO/dj
wfUcbi/Nt51Ycsw5DLTkbtrz9u9/I3zsstj0tAuImOW9aWvEiozOOjafyxgoFOjA
PtZxZWbZNGZXCQGmI2LFVOu29YHwbvyFW3JbcCgQ2hKRLaBIfQ29TqQf5D2ylXy4
LcbyAi1AhJ8A/oalv61yuOhS4qtPswIDAQABo4IBDDCCAQgwCQYDVR0TBAIwADAh
BglghkgBhvhCAQ0EFBYSQ2xpZW50IENlcnRpZmljYXRlMB0GA1UdDgQWBBT62ycN
ujXzp7ujD0ROOW2lMlkvRzCBlgYDVR0jBIGOMIGLgBRyiGfU8FO9BlPUM7kPTLFB
TY6pEaFopGYwZDELMAkGA1UEBhMCLi4xCzAJBgNVBAgTAi4uMQswCQYDVQQHEwIu
LjELMAkGA1UEChMCLi4xCzAJBgNVBAsTAi4uMQ4wDAYDVQQDEwVBU0NBMjERMA8G
CSqGSIb3DQEJARYCLi6CCQDrduvuqWQqJDATBgNVHSUEDDAKBggrBgEFBQcDAjAL
BgNVHQ8EBAMCB4AwDQYJKoZIhvcNAQELBQADggEBAC0VzRJHtE+uFoIvQBxeEOUD
QE0ZQENGoKQOZftZw8BtBC9VSLoYd5ykaCAI0WCjuHUaNoQkB2pG8nWcFPJ2wR7J
/wGHwyi7P/5eAta2pGwJevAcw3Kp7RKcj0bpe4hvtAhAFvERXiOr2d6XgXuhfHHr
dPA/dPhZChNU8At862409w/cqV9rrpBDjT7y0cjtbd9PjnBYDCb19vraAZZvNSP3
l8p24Mo+plGhrzbovmyJuqpMGkWQzd4wQ1A+PPKQpSAkn9hHFMrs+Zd8WsRYK4cI
1uJ2N8fsJ/uymvytwyMx1eEY36P9h/Fi2ZNwUFe6XOkwI3FDGOwyxNa3Um69GKA=
-----END CERTIFICATE-----
</cert>
Last edited by VaMpIrEKiNg on Tue Dec 20, 2016 9:16 pm, edited 1 time in total.
 
darkprocess
Member Candidate
Member Candidate
Posts: 249
Joined: Fri Mar 20, 2015 1:16 pm

Re: How according to openvpn.conf to import certificates to ROS?

Mon Dec 19, 2016 4:51 pm

Lzo is not supported on mtk

Envoyé de mon SM-A510F en utilisant Tapatalk
 
VaMpIrEKiNg
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 57
Joined: Sat Dec 10, 2016 6:56 am

Re: How according to openvpn.conf to import certificates to ROS?

Mon Dec 19, 2016 6:26 pm

can be connected without comp-lzo parameter
 
Sob
Forum Guru
Forum Guru
Posts: 9121
Joined: Mon Apr 20, 2009 9:11 pm

Re: How according to openvpn.conf to import certificates to ROS?

Mon Dec 19, 2016 6:30 pm

"proto udp" is not supported either.
 
VaMpIrEKiNg
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 57
Joined: Sat Dec 10, 2016 6:56 am

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 8:41 am

both protocol can connect, it's up to you
These parameters are not important, the most important is certificates.
How to import certificates to MTK.
 
Sob
Forum Guru
Forum Guru
Posts: 9121
Joined: Mon Apr 20, 2009 9:11 pm

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 2:40 pm

Just save them to file, upload to router and import using:
/certificate import file-name=<your file>
It fact, you can use the config as is and import will find both certificates and key in it (but only certificates, it won't import OpenVPN settings).
 
VaMpIrEKiNg
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 57
Joined: Sat Dec 10, 2016 6:56 am

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 5:33 pm

I knew hot to import certificates to ros
but when I imported it, it appears not correct Certs.
see below
[root@MikroTik] /certificate> print
Flags: K - private-key, D - dsa, L - crl, C - smart-card-key, A - authority, I - issued, R - revoked, E - expired, T - trusted
# NAME COMMON-NAME SUBJECT-ALT-NAME FINGERPRINT
0 T 1.ovpn_0 ASCA2 d9ff4cc75892ceab131...
1 K T 1.ovpn_1 AS1696159-2150087CD... d676e3703712cf6cd87...


No KR Flags.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 5:46 pm

Looks fine to me. There shouldn't be a R flag. R flag is for revoked certificates.
 
VaMpIrEKiNg
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 57
Joined: Sat Dec 10, 2016 6:56 am

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 6:05 pm

dec/21 00:04:14 ovpn,debug,packet sent P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 sid=cb4ac4dc6e2dba3 pid=0 DATA len=0
dec/21 00:04:14 ovpn,debug ovpn-out1: disconnected <peer disconnected>
 
VaMpIrEKiNg
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 57
Joined: Sat Dec 10, 2016 6:56 am

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 6:18 pm

http://wiki.mikrotik.com/wiki/Manual:Cr ... rtificates

They said If everything is imported properly then certificate should show up with KR flag.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 6:24 pm

Fixed, it was left there from old versions.
 
VaMpIrEKiNg
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 57
Joined: Sat Dec 10, 2016 6:56 am

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 7:15 pm

The log shows the process went to interrupt before enterned to TLS Auth,the problem occurred during the certificate authentication phase.
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 7:32 pm

Unfortunately I cannot tell anythign specific without logs and supout file. Try to contact support with attached supout file.
 
R1CH
Forum Guru
Forum Guru
Posts: 1101
Joined: Sun Oct 01, 2006 11:44 pm

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 7:40 pm

You should be aware that the config you posted lets anyone use your VPN account. Never post private keys.
 
VaMpIrEKiNg
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 57
Joined: Sat Dec 10, 2016 6:56 am

Re: How according to openvpn.conf to import certificates to ROS?

Tue Dec 20, 2016 7:48 pm

This private key is a test key, and the conf file also contain the tls-auth field to authenticate the username and password.
 
jimint
just joined
Posts: 18
Joined: Fri Aug 11, 2017 12:58 am

Re: How according to openvpn.conf to import certificates to ROS?

Fri Aug 11, 2017 1:22 pm

Hello
I try to do the same thing.
What can i do?
I have to save the .ovpn file and import to mikrotik?? Only this 1 file or i have to save the key below separately to other 2 files?
I import only .ovpn and printed only T without K.
 
jimint
just joined
Posts: 18
Joined: Fri Aug 11, 2017 12:58 am

Re: How according to openvpn.conf to import certificates to ROS?

Fri Aug 11, 2017 2:31 pm

Just save them to file, upload to router and import using:
/certificate import file-name=<your file>
It fact, you can use the config as is and import will find both certificates and key in it (but only certificates, it won't import OpenVPN settings).
I bought me too a vpn service and they provide me the conf file .ovpn and other two files .key and .crt

I import .ovpn but show me only "T". What can i do next steps. I try to import the others two files.key and .crt but still "T"
 
Sob
Forum Guru
Forum Guru
Posts: 9121
Joined: Mon Apr 20, 2009 9:11 pm

Re: How according to openvpn.conf to import certificates to ROS?

Sat Aug 12, 2017 1:46 am

If you use .ovpn file in certificate import, RouterOS will recognize embedded certificates (blocks with BEGIN / END). If you have certificates/keys in separate files, you need to import those. First import certificate and then key and RouterOS should put them together.
 
jimint
just joined
Posts: 18
Joined: Fri Aug 11, 2017 12:58 am

Re: How according to openvpn.conf to import certificates to ROS?

Sat Aug 12, 2017 8:54 am

If you use .ovpn file in certificate import, RouterOS will recognize embedded certificates (blocks with BEGIN / END). If you have certificates/keys in separate files, you need to import those. First import certificate and then key and RouterOS should put them together.
OK i have this 2 files seperate:
.key
.crt
But when import this 2 files only appear left the letter "T" means trust. I think the right is with letters "KT" isn't it?
 
Sob
Forum Guru
Forum Guru
Posts: 9121
Joined: Mon Apr 20, 2009 9:11 pm

Re: How according to openvpn.conf to import certificates to ROS?

Sat Aug 12, 2017 11:49 pm

Order is important. Are you importing .crt first and .key after that? If you do, check what's in .key file. If it starts with "-----BEGIN PRIVATE KEY-----", it should just work. If it's "-----BEGIN ENCRYPTED PRIVATE KEY-----", you need to use the right password for import.
 
jimint
just joined
Posts: 18
Joined: Fri Aug 11, 2017 12:58 am

Re: How according to openvpn.conf to import certificates to ROS?

Sun Aug 13, 2017 7:32 am

Order is important. Are you importing .crt first and .key after that? If you do, check what's in .key file. If it starts with "-----BEGIN PRIVATE KEY-----", it should just work. If it's "-----BEGIN ENCRYPTED PRIVATE KEY-----", you need to use the right password for import.
As right password you mean the Passphrase to import? I don't have it i thought that was blank. I have to ask them about it?
The .crt starts with:-----BEGIN CERTIFICATE----- and .key starts with:---------BEGIN Static key V1---------
 
Sob
Forum Guru
Forum Guru
Posts: 9121
Joined: Mon Apr 20, 2009 9:11 pm

Re: How according to openvpn.conf to import certificates to ROS?

Sun Aug 13, 2017 8:41 pm

Your key looks like the one used with "tls-auth" option (check .ovpn file). If that's the case, then it's the bad news, because OpenVPN in RouterOS doesn't support that. But you should also have another key for client certificate.
 
jimint
just joined
Posts: 18
Joined: Fri Aug 11, 2017 12:58 am

Re: How according to openvpn.conf to import certificates to ROS?

Sun Aug 13, 2017 10:28 pm

Your key looks like the one used with "tls-auth" option (check .ovpn file). If that's the case, then it's the bad news, because OpenVPN in RouterOS doesn't support that. But you should also have another key for client certificate.
Finally OpenVPN in RouterOS doesn't support it. I contact with company and they told that mikrotik only has the pptp protokol and its not possible to connect with Ovpn as client.
Is there someone that work RouterOS as a vpn client with Ovpn?

Who is online

Users browsing this forum: Bing [Bot], Yahoo [Bot] and 183 guests