NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

RangerX's avatar
RangerX
Apprentice
May 26, 2020

RAX35 - Need to create new OpenVPN CA Cert

I have an RAX35 (similar to RAX40 without the USB port) and have been using it for a few months.

 

I enabled the built-in OpenVPN server and downloaded from the router the ca.crt, client.crt, client.key, and client.opvn files. I setup OpenVPN client on laptop and have been able to access my network remotely.

 

The problem is my certificates have been compromised and I need to generate new ca and client certs for the built-in OpenVPN server. I have disabled/enabled the built-in OpenVPN but it gave me the same compromised certs. I did a factory reset (both via the GUI and pushing the hardware button) and it still gave me the same compromised certs. I tried to telnetenable the RAX35 to see if I could manually replace the compromised certs in the router with new certs I generated manually but telnetenable failed (there may not be a telnet server in the router like some older router models have).

 

How can I force the RAX35 to generate new ca and client certs. If this capability is not possible then Netgear has created a horribly flawed and insecure router leaving users extremely vulnerable if the OpenVPN security is compromised. Not being able to regenerate new OpenVPN certs is no different than having hardcoded passwords on the router to access the GUI locally and remotely that cannot be changed... and I'm sure Netgear wouldn't consider having such a security vulnerability as that.

 

If I cannot generate new certs than this router is of no use and I would like to know who to contact at Netgear to get my money back.

 

Please don't reply back suggesting I build a sotware OpenVPN server on one of my computers. If I wanted to do that I wouldn't have purchased the RAX35 with built-in OpenVPN server capability.