OneConnect VPN certificate not trustedLast modified on 1 Dec, 2021. Revision 12
|Up to date for||
cOS Core 13.00.09 and up
cOS Core 13.00.09
|Not valid for||
cOS Core 13.00.08 and older
When trying to initiate a connection with Clavister OneConnect Client you may get the following error.
Windows: Server certificate is not trusted by Windows
iOS: Invalid certificate format
BackgroundCertification validation is done in several steps.
- First Client initiates a connection to the configured NetWall (vpnserver.mydomain.com).
- Next, the Netwall presents it's system certificate. The subject field needs to contain the correct DNS name(s) (FQDN), either vpnserver.mydomain.com (or *.mydomain.com when using a wildcard certificate).
- If the first two steps are successful the certificate will be checked against the clients system certificate store.
If there is a mismatch (for example you enter the IP address instead of the FQDN, or the certificate is not trusted) you get the described error.
- Make sure that your certificate fits the requirements and has the correct FQDN
- Import the certificate incl. private key in your NetWall under /Objects /General /Key Ring. Type must show as Local.
- Select the certificate as HTTPS certificate under /System /Device /Device Settings /Remote Management → /Advanced Settings
Be aware that this is also the certificate of your Web-User-Interface!
- Import the certificate to your clients system certificate store.
- If the certificate is bought from a well-known CA authority you should be able to skip this step, as your computer already trusts the according CA.
- If the certificate is self-signed then you need to import it on all clients using OneConnect. Please follow the documentation of your operating system on how to do this.
- Note: The private key should not be exported.
Common Windows VPN client Errors that are related to certificate mismatch
- Windows: Server certificate is not trusted by Windows.
- Windows: Server Certificate is not valid for the requested usage. This error is also returned if the certificate has an invalid name.
An example on how to generate a self-signed certificate from Cos Core itself.
- Navigate to Object->Key Ring
- Click the drop-down menu Add->Certificate
- Provide a name to the Certificate (eg., Oneconnect_160)
- Under Generate Certificate Sub-menu ->Click Configure->It will open a Certificate Generator Pop-Up window.
5. Select the Certificate Type as Self-Signed.
6. Provide the Subject Name and Subject Alternative Name along with Key size and Type details.
- Subject name = CN=Clavister
- Subject Alternative Names = 10.122.137.160
- Public Key Type : RSA or EC
- Key Size : 2048 bits
- Signature Algorithm : SHA-256
- Validity : 365 days
7. Click Generate.
8. Once when the certificate is successfully generated, verify and download.
Important: Client hostname must match certificate hostname
A specific requirement when using certificates with the OneConnect Interface is that the
hostname value entered into the clientmust be the same as either the Common Name
(CN) or one of the Subject Alternative Name (SAN) options in the certificate used by the
cOS Core OneConnect Interface**.
Note that the One connect VPN client profile must be specified with a IP Address or a FQDN that matches with the certificate in the Cos Core.
The above image is taken from the Windows One connect VPN client
9. Select the certificate as HTTPS certificate under /System /Device /Device Settings /Remote Management → Advanced Settings.
10. Import the certificate to your client system certificate store.
23 Nov, 2021 oneconnect macos ios windows
15 Feb, 2022 oneconnect openconnect sslvpn
19 Apr, 2022 oneconnect sase
29 Oct, 2021 sslvpn openconnect oneconnect macos ios netwall
5 Apr, 2022 core certificate oneconnect ipsec vpn
5 Mar, 2021 sslvpn openconnect oneconnect android core
29 Oct, 2021 sslvpn openconnect oneconnect windows
13 Oct, 2021 oneconnect macos openconnect ios
2 Feb, 2021 core sslvpn macos certificate
5 Mar, 2021 sslvpn openconnect oneconnect linux core
8 Apr, 2021 core sslvpn oneconnect interfaces arp
25 Feb, 2022 oneconnect windows howto
10 Mar, 2021 core oneconnect
29 Jun, 2021 core oneconnect
5 Mar, 2021 sslvpn openconnect oneconnect macos windows linux core