OpenVPN CA
-
- Posts: 39
- Joined: Mon Oct 28, 2019 8:35 am
OpenVPN CA
Is it possible to replace the Billion default OpenVPN CA for the purpose of OpenVPN server? If so how is this done. On this page a new certificate can be pasted over the default CA but this doesn't save. So how do we get a unique certificate into the router for OpenVPN server. Adding certificates on the certificates page does not change the OpenVPN CA.
-
- Posts: 5398
- Joined: Tue Jul 19, 2011 4:30 pm
Re: OpenVPN CA
I'll check with our engineers and get back to you.SPAU00 wrote: ↑Sun Dec 20, 2020 1:25 am Is it possible to replace the Billion default OpenVPN CA for the purpose of OpenVPN server? If so how is this done. On this page a new certificate can be pasted over the default CA but this doesn't save. So how do we get a unique certificate into the router for OpenVPN server. Adding certificates on the certificates page does not change the OpenVPN CA.
-
- Posts: 5398
- Joined: Tue Jul 19, 2011 4:30 pm
Re: OpenVPN CA
After checking with our engineers the default OpenVPN CA can not be adjusted.billion_fan wrote: ↑Mon Dec 21, 2020 10:51 amI'll check with our engineers and get back to you.SPAU00 wrote: ↑Sun Dec 20, 2020 1:25 am Is it possible to replace the Billion default OpenVPN CA for the purpose of OpenVPN server? If so how is this done. On this page a new certificate can be pasted over the default CA but this doesn't save. So how do we get a unique certificate into the router for OpenVPN server. Adding certificates on the certificates page does not change the OpenVPN CA.
-
- Posts: 39
- Joined: Mon Oct 28, 2019 8:35 am
Re: OpenVPN CA
Thanks for checking.billion_fan wrote: ↑Tue Dec 22, 2020 9:02 amAfter checking with our engineers the default OpenVPN CA can not be adjusted.billion_fan wrote: ↑Mon Dec 21, 2020 10:51 amI'll check with our engineers and get back to you.SPAU00 wrote: ↑Sun Dec 20, 2020 1:25 am Is it possible to replace the Billion default OpenVPN CA for the purpose of OpenVPN server? If so how is this done. On this page a new certificate can be pasted over the default CA but this doesn't save. So how do we get a unique certificate into the router for OpenVPN server. Adding certificates on the certificates page does not change the OpenVPN CA.
I own several billion routers located in various locations. The system OpenVPN CA is identical on all VPN routers so is basically a public certificate making the OpenVPN Server extremely vulnerable. I don't see why the server should work any differently than the client side of things where you can select your uploaded CA's, keys etc.
-
- Posts: 5398
- Joined: Tue Jul 19, 2011 4:30 pm
Re: OpenVPN CA
I'll pass on your suggestions to our engineersSPAU00 wrote: ↑Wed Dec 23, 2020 12:59 amThanks for checking.billion_fan wrote: ↑Tue Dec 22, 2020 9:02 amAfter checking with our engineers the default OpenVPN CA can not be adjusted.
I own several billion routers located in various locations. The system OpenVPN CA is identical on all VPN routers so is basically a public certificate making the OpenVPN Server extremely vulnerable. I don't see why the server should work any differently than the client side of things where you can select your uploaded CA's, keys etc.
-
- Posts: 1
- Joined: Tue Jan 19, 2021 12:38 pm
- Contact:
Re: OpenVPN CA
I want to same request for suggest
-
- Posts: 5398
- Joined: Tue Jul 19, 2011 4:30 pm
Re: OpenVPN CA
I've checked with our engineers again and they stated the following
1. Although each 8900AX-2400 uses the same “Root CA” , but the OpenVPN Server settings for each 8900AX-2400 device will be different i.e.: Cipher Encryption and HMAC Authentication.
2. Also our BiPAC 8900AX-2400 OpenVPN Server using the VPN Account for authentication.
You do not have the required permissions to view the files attached to this post.
-
- Posts: 39
- Joined: Mon Oct 28, 2019 8:35 am
Re: OpenVPN CA
Thanks for your reply.billion_fan wrote: ↑Tue Jan 19, 2021 2:47 pmI've checked with our engineers again and they stated the following
1. Although each 8900AX-2400 uses the same “Root CA” , but the OpenVPN Server settings for each 8900AX-2400 device will be different i.e.: Cipher Encryption and HMAC Authentication.
2. Also our BiPAC 8900AX-2400 OpenVPN Server using the VPN Account for authentication.
OpenVPN account password is encrypted yes but this isn't utilizing OpenVPN security.
Consider this scenario....
You want to connect to a remote Billion router network through OpenVPN with no remote host computer. You would need to use the Billion Root CA certificate as client (which is a public certificate) because the remote Billion Root CA cannot be replaced.
The Billion Root CA is useless leaving only password security which isn't what OpenVPN is about.
The client side of the Billion router for OpenVPN is customizable and as mentioned previously, I don't see why the server side should work any differently which would give Billion customers connection options fully utilizing OpenVPN security.
-
- Posts: 68
- Joined: Sat Nov 03, 2012 2:50 pm
Re: OpenVPN CA
After I read through this thread, I disabled the Billion OpenVPN server and reverted to another device on my network where you can change the root cert. I'm no security expert but surely a cooked-in certificate is a big 'no no'?