What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

OpenVPN Setup, getting an error when starting Server 1

adampk17

Senior Member
Hello! Long time lurker, first time poster. I'm trying to configure OpenVPN and I'm getting an error when attempting to start Server 1. Here are the particulars:

Router: Asus RT-N66U
F/W: Merlin 3.0.0.4.374.32
Error: openvpn[4754]: Cannot load certificate file server.crt: error:0906D06C:lib(9):func(109):reason(108): error:140AD009:lib(20):func(173):reason(9)

openvpn[4754]: Exiting due to fatal error

I have never set up a VPN before, nor a certificate authority. Frankly, I found setting up and creating the certificates difficult. I used easy-rsa on my Windows 8 64 bit computer to create they keys (Certificate Authority, Server Certificate, and Server Key, I have nothing in the Static Key).

Using Notepad++ I copied and pasted the contents of the keys in to the OpenVPN Keys tab on the VPN Server portion of Advanced Settings on the router. I tried both with and without they key headers and footers. I can provide provide screenshots of my configuration settings if those would be helpful.

I'm at a loss with this error. I would be grateful for any assistance.

Thanks in advance.

Adam
 
Hello! Long time lurker, first time poster. I'm trying to configure OpenVPN and I'm getting an error when attempting to start Server 1. Here are the particulars:

Router: Asus RT-N66U
F/W: Merlin 3.0.0.4.374.32
Error: openvpn[4754]: Cannot load certificate file server.crt: error:0906D06C:lib(9):func(109):reason(108): error:140AD009:lib(20):func(173):reason(9)

openvpn[4754]: Exiting due to fatal error

I have never set up a VPN before, nor a certificate authority. Frankly, I found setting up and creating the certificates difficult. I used easy-rsa on my Windows 8 64 bit computer to create they keys (Certificate Authority, Server Certificate, and Server Key, I have nothing in the Static Key).

Using Notepad++ I copied and pasted the contents of the keys in to the OpenVPN Keys tab on the VPN Server portion of Advanced Settings on the router. I tried both with and without they key headers and footers. I can provide provide screenshots of my configuration settings if those would be helpful.

I'm at a loss with this error. I would be grateful for any assistance.

Thanks in advance.

Adam

Make sure you did include the --- BEGIN --- and --- END --- lines when pasting.

You don't need a static key if you are authenticating using certificates, so it's normal for that field to remain empty.

There's a pretty good tutorial for Tomato that can almost directly apply to Asuswrt-Merlin on the Wiki.
 
Thanks for the quick reply. I went back and re-entered all of my keys, making sure to include the headers and footers.

I followed this guide, obviously to no avail, at this point.http://www.howtogeek.com/60774/connect-to-your-home-network-from-anywhere-with-openvpn-and-tomato/

The one thing that bothers me is that the guide's pictures shot the server certificate having a .crt extension, while mine ended up with a .csr extension. Why I do not know.

Same error still.

A CSR is a certificate signing request. That's not the correct file, you really want the .crt file. A CRT is generated by signing a CSR using a KEY.
 
A CSR is a certificate signing request. That's not the correct file, you really want the .crt file. A CRT is generated by signing a CSR using a KEY.

Thanks for the tip, I will do some more googling to figure out how to turn my CSR files in to CRTs.
 
Make sure you do run your command prompt with elevated privileges.

Note that you can also use the easy-rsa installation that's included in the firmware. I believe there's a guide on the wiki explaining a step-by-step based on the router's own easy-rsa.
 
I know I'm digging up an old thread but I just ran in to this same issue. I found that when I opened my server.crt file with plain old notepad that I was not getting the "---end certificate---". So I tried to manually place it in there but still got the same error.

I downloaded Notepad++ and opened my server.crt to find the whole thing is shown there. So I copied and pasted it in to my settings and I'm able to get OpenVPN to work without an issue! So Notepad was cutting it off, even though I used "Ctrl+A" to select all text.

Not sure if this is your problem but worth a look if you haven't solved this issue yet.
 
Make sure you do run your command prompt with elevated privileges.

Note that you can also use the easy-rsa installation that's included in the firmware. I believe there's a guide on the wiki explaining a step-by-step based on the router's own easy-rsa.

Where is this installation?
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!

Members online

Back
Top