What's new

Site-to-Site OpenVPN CA name?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

distilled

Senior Member
This is probably a really dumb question, but what goes into the Common Name(CN) field, when creating a site-to-site VPN? My site-to-site works just fine with the VPN username, but I am using " Username / Password Auth. Only " and would strongly prefer to use a cert. It keeps throwing auth failure though, and I *think* the problem is the CN field. The host.domain assigned on the router LAN page is not working either. Does anyone have any ideas?
 
CN doesn't matter, unless you use the client-specific options to also validate by CN. The only important thing is that the certificate be signed by the same CA used by the server.
 
I do use client-specific options to enable Client<->Client. The config was exported from the server side and imported it into the client side, so I assume the cert is signed by the same CA.
 
Just for posterity, the magic was adding " --username-as-common-name " to the server configuration. I had no idea, but it works perfectly now with Username / Password Auth. Only set to No.

And now I sleep better.
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top