What's new

[Issue RT-N66R] Reset SSL certs to default without deleting router

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Bluefalcon13

New Around Here
Hey everyone, I have been attempting to get computer clients to be able to openvpn into my home router, but , due to the DH params being smaller than 768 on the default certs, I have attempted to load newly generated, self-signed certs, and a new DH params config. Now I either get a problem with DH or a problem with cert/keys.

Any easy way to reset the original certs without wiping the whole router? If not, how am I jacking up this procedure? Seems simple enough. I have both Linux and Windows clients available to generate certs.

Side note: I have an RT-N66R, with the latest AsusWRT image (the beta one on asus's support site).

Sent from my HP 10 using Tapatalk
 
Yup, that's what I was doing roughly, but replacing all the certs/keys. Gonna try and regen the stuff tonight.

Sent from my Nexus 6 using Tapatalk

Just replace the DH. The rest can be left there.
 
Just replace the DH. The rest can be left there.
Yeah... It's a hair late for that. I was originally following another guide that said generate all the things, rather than replace the DH params.

So now that I have mucked it up... Any easy non factory default method to return the default certs?

Sent from my Nexus 6 using Tapatalk
 
Yeah... It's a hair late for that. I was originally following another guide that said generate all the things, rather than replace the DH params.

So now that I have mucked it up... Any easy non factory default method to return the default certs?

Sent from my Nexus 6 using Tapatalk

Those are all dynamically generated by the router. If you erase them all, then new ones will be created. You might still need to replace the DH with your own however, if your firmware is too old and still generates a 512-bit one.
 
Awesome, so just wipe the blocks clean, load a >768 DH, save, and reboot. Thanks a ton :)

Sent from my Nexus 6 using Tapatalk
 
Just as a follow up, this worked perfectly. Generated a 2048 dhparam on my Debian install, and blanked out the certs and keys. Everything works now :)

Sent from my Nexus 6 using Tapatalk
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top