What's new

Asus RT-AC86U - Firmware update 386.9_0 (most recent update) breaks the easy-rsa package as there is no openssl-1.1.1.cnf file

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Like me! If I'm not mistaken, firmware 384.xx didn't have these keys generated by default. That's why I learned this, and I didn't know it had changed.
AFAIK Merlin's firmware has always generated its own OpenVPN keys. Certainly it was doing it as far back as the 378.x firmware eight years ago when they moved from being stored in NVRAM to JFFS.

EDIT: Looks like the automatic certificate and key generation was added November 2013 (374.35).
 
Last edited:
Like me! If I'm not mistaken, firmware 384.xx didn't have these keys generated by default. That's why I learned this, and I didn't know it had changed.

Are the keys and certs generated by the router good enough? If there is no advantage in using easy-rsa, then I have pone less thing to worry about...

How do you have your encryption stuff set up? The defaults give me dialup speeds lmao. If I turn it all the way off, I can watch HD video without issue over 4G. Wouldn't recommend it due to data costs, but I had some dats to burn and it was cool for testing haha

Trying to figure out how to get that sweet spot.
 
All home routers I've seen with OpenVPN Server option are doing everything automatically and the user just has to export the configuration file.
Then I've been doing extra work for nothing... :eek::eek::eek:

Now that I remember, I started configuring openVPN in my RT-N66U, using Tomato firmware... many moons ago.
 
How do you have your encryption stuff set up? The defaults give me dialup speeds lmao. If I turn it all the way off, I can watch HD video without issue over 4G. Wouldn't recommend it due to data costs, but I had some dats to burn and it was cool for testing haha

Trying to figure out how to get that sweet spot.

Just the defaults as you can see in my settings.
 
Just the defaults as you can see in my settings.
Weird, that's what I thought but I wasn't getting above like 5kbps down with the defaults set.

Something with the cypher is killing my connection. So far anything other than ncp-disable is basically unusable.
 
Last edited:
Thank you. My current config is set to allow individual users to connect withoout password (using their private key and cert). I'm assuming this is safe (please let me know if it isn't!).

The question that I have now is how could I generate those user-specific keys and certs in AsusWRT Merlin.
 

Similar threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top