Creating a certificate with the following commands used to work - until now.
Code: Select all
certificate add name=root-cert common-name=root-certificate days-valid=3650 key-usage=key-cert-sign,crl-sign
certificate sign root-cert
certificate add name=https-cert common-name=https-certificate days-valid=3650
certificate sign ca=root-cert https-cert
ip service set www-ssl certificate=https-cert disabled=no
... but at least it was working in firefox.
However, as of today even firefox complains, and gives a no-go:
Cannot communicate securely with peer: no common encryption algorithm(s). Error code: SSL_ERROR_NO_CYPHER_OVERLAP
The wiki here https://wiki.mikrotik.com/wiki/SSL_Certificate_setup seems to be outdated and the forum search gives ancient results.
Is anyone aware of a set of commands that actually create a self-signed certificate that works in firefox and chrome, preferably by IP and by a domain name eventually?
And could we please please put this to the MikroTik wiki, so people can actually find it, and don't waste time on outdated pages?