NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
pyrmont
Feb 22, 2018Guide
MD5-Signed Certificate Warning with OpenVPN on iOS
As of version 1.2.8 of the OpenVPN app on iOS, OpenVPN issues the following warning:
> WARN TLS: received certificate signed with MD5.
> Please inform your admin to upgrade to a
> stronger algorithm. Support for MD5 will be
> dropped at end of Apr 2018
The warning appears as a modal dialog that interrupts use of the device. If the device is unlocked after a short period of time with the VPN connected, there will typically be multiple modal dialogs. This is an extremely frustrating experience.
There appears to be no way to disable this warning and nothing router owners can do. A similar issue arose earlier for Android users (https://community.netgear.com/t5/Nighthawk-WiFi-Routers/Netgear-R7000-and-OpenVPN-for-Android-App/m-p/1310857). It is still unresolved at the time of writing.
Netgear needs to issue a firmware update that changes the certificate used for OpenVPN.
> WARN TLS: received certificate signed with MD5.
> Please inform your admin to upgrade to a
> stronger algorithm. Support for MD5 will be
> dropped at end of Apr 2018
The warning appears as a modal dialog that interrupts use of the device. If the device is unlocked after a short period of time with the VPN connected, there will typically be multiple modal dialogs. This is an extremely frustrating experience.
There appears to be no way to disable this warning and nothing router owners can do. A similar issue arose earlier for Android users (https://community.netgear.com/t5/Nighthawk-WiFi-Routers/Netgear-R7000-and-OpenVPN-for-Android-App/m-p/1310857). It is still unresolved at the time of writing.
Netgear needs to issue a firmware update that changes the certificate used for OpenVPN.
FYI, I documented the steps to required to replace the certificates here. Unfortunately it the steps are written for users of Windows, but it also uses mostly cross-platform OpenSource tools and explains what's going on so I think it should be pretty translatable if you don't have access to any Windows boxes.
Just posting this so you have at least one go-forward path.
108 Replies
- bteeuwenInitiate
+100
This is extremely annoying when using the netgear vpn service.
I read "As soon as we have it working before 31 april 2018, it is ok. So that OpenVPN is not broken" at https://community.netgear.com/t5/Nighthawk-WiFi-Routers/OpenVPN-update-breaks-R7000-and-probably-other-routers-VPN/m-p/1435672/highlight/true. With the openvpn update I'd say from a user experience it is severly broken from 21st of february.
Please provide a solution as soon as possible.
- pyrmontGuideOpenVPN 1.2.9 has changed the message to only appear once per session which makes this slightly less frustrating.
Nevertheless, it continues to defy explanation why Netgear is taking so long to fix this.- golf06222Aspirant
This update resolved my issues with mulitple prompts per session.
I'm not extremly savy on certificates so was hoping someone could help. Is there another option other than MD5 certificate that Netgear offers or are we all waiting for Netgear to come up with something before the end of April?
Thanks!
-Cameron
- pyrmontGuideNo, there's nothing users can do to change the system's certificate. You can install an alternative firmware but that comes with its own negatives.
This honestly doesn't seem like a particularly difficult change. Netgear needs to change the settings in the OpenVPN files they generate and seed a new certificate to devices.
They say to never attribute to malice what can be explained by incompetence but either way, it's an experience which has me questioning whether I'd buy a Netgear product again.
- whataboutbobAspirant
Does anyone know if Netgear is issuing a fix for this before April 2018 EOL deadline or do I need to manually upgrade my certificate?
- Diggie3LuminaryThey have claimed that they will elsewhere in the forums. Based on their ability to deliver fixes for other critical product issues, I would be skeptical.
- whataboutbobAspirant
Fingers crossed but if they don't deliver close to the deadline, I'll install the certificate. Hopefully it doesn't get to that. Thanks for your writeup, I might have to go your route with some slight tweaks for Mac but it should be siimilar.
- whataboutbobAspirant
I just installed V1.0.1.44_10.0.28 for my R6900, not sure if it fixes the VPN issue, release notes said it fixes security issues, whatever that means. I'll test it later.
https://kb.netgear.com/000055156/R6900-Firmware-Version-1-0-1-44
I have the same isssue. MD5 warning when connecting to the VPN on an iOS device.
Netgear are you looking at this issue? It won't work anymore from 30th of april 2018.
- schumakuGuru - Experienced User
axelsegerswrote:I have the same isssue. MD5 warning when connecting to the VPN on an iOS device.
Current firmware version on your R8900 / Nighthawk X10?
axelsegers wrote:
Netgear are you looking at this issue? It won't work anymore from 30th of april 2018.
A Netgear moderator has already answered a few replies before -> JamesGL in port #6.
- martijn76Aspirant
Hasn't this been solved by the latest 1.0.2.46 firmware? Haven't installed it yet, but the changelog does say:
New Features and Enhancements: Supports the VPN client feature.
And this would suggest a fix in the VPN department. Don't want to install unless this is the case though, all is running well at the moment (at least until end of April haha).
- JamesGLMaster
Hi All,
Resolution will be released prior to the deadline.
- RepiukTutor
Any news on this update? It's April 1st and I need VPN up and running
- ablineInitiate
I just purchased my D7800 from Amazon Prime UK yesterday and received it today (26th April). Having purchased it for, amongst other things it's VPN Server capabilities, I was astounded to see the MD5 Support warning for OpenVPN when I set it up this evening (using OpenVPN Connect for my iPhone). What are Netgear playing at? They are completely hopeless and I see JamesGL the NETGEAR Moderator has gone very quiet this month - very ominous!
Well, for me at least I can return it straight back to Amazon if the firmware to correct this is not delivered by the end of next Monday (30th April). I'll then have to look for alternative modem/routers from another brand. Shame, but it seems the Netgear software guys are hopeless at their job.
If they don't fix it in the next 4 days across all their applicable routers and modem/routers I guess they will have to provide many "not fit for purpose" return refunds in the coming weeks, and also change all their online web advertising/marketing claims and packaging/boxing to remove their claim of OpenVPN Server capability. I’m sure they would not want to be accused of false advertising!
- spopielaGuide
What is going on? Please let me know if anything is going to get updated in the R7000 to resolve yhis issue. Time is running out!!!
If Netgear can't comply, with some or all the routers, just say so. I need to move on!!!
- AJ123Aspirant
For people reading this thread and infuriated that there is no response from Netgear, please file a complain with BBB (I just did) and highlight that fact that Netgear is involved in deceptive advertising because their product webpages still claim OpenVPN support even though that is ending on Apr-30-2018.
cheers,
AJ.
- ablineInitiate
As a followup to my earlier post, interestly the manual I original saw when making my decision to buy had sections:
⦁ Specify VPN Service in the Modem Router
⦁ Install OpenVPN Software on a Windows Computer
⦁ Install OpenVPN Software on a Mac Computer
⦁ Install OpenVPN Software on an iOS Device
⦁ Install OpenVPN Software on an Android DeviceNow I see online it only has the following sections:
⦁ Specify VPN Service in the Modem Router
⦁ Install OpenVPN Software on a Windows Computer
⦁ Install OpenVPN Software on a Mac Computer....with a box out in the "Set Up a VPN Service" section saying:
"Note The modem router does not support iOS or Android VPN client software."Doesn't look like they intend to do anything about it. Even though the latest Firmware V1.0.1.34 Netgear Genie web setup page still has OpenVPN Client Setup instructions for Windows, MacOSX, iphone/iPad and Android, along with an OpenVPN configuration package download button "For Smart Phone". Who are they trying to kid?
I'm returning mine to Amazon UK after only 3 days. What a waste of time! I'll buy from a manufacturer that actually cares about it's customer base next time.
Even the Netgear Moderators can't be bothered to respond. I can't be bothered with Netgear anymore!
- schumakuGuru - Experienced User
abline wrote:
As a followup to my earlier post, interestly the manual I original saw when making my decision to buy had sections:
⦁ Specify VPN Service in the Modem Router
⦁ Install OpenVPN Software on a Windows Computer
⦁ Install OpenVPN Software on a Mac Computer
⦁ Install OpenVPN Software on an iOS Device
⦁ Install OpenVPN Software on an Android DeviceNow I see online it only has the following sections:
⦁ Specify VPN Service in the Modem Router
⦁ Install OpenVPN Software on a Windows Computer
⦁ Install OpenVPN Software on a Mac Computer....with a box out in the "Set Up a VPN Service" section saying:
"Note The modem router does not support iOS or Android VPN client software."Doesn't look like they intend to do anything about it. Even though the latest Firmware V1.0.1.34 Netgear Genie web setup page still has OpenVPN Client Setup instructions for Windows, MacOSX, iphone/iPad and Android, along with an OpenVPN configuration package download button "For Smart Phone". Who are they trying to kid?
Checking the Netgear Support / D7800 Docs as well as the Web Archive does show the very same D7800_UM_15Sep2015 as retrieved in November 2015 and July 2017:
https://web.archive.org/web/20151106151755/http://www.downloads.netgear.com/files/GDC/D7800/D7800_UM_15Sep2015.pdf
https://web.archive.org/web/20170709015341/http://www.downloads.netgear.com:80/files/GDC/D7800/D7800_UM_15Sep2015.pdf
All versions have the same - what was at the time of this documentation creation (15 Sep 2015) correct..You must have seen ie. the R7800 User Manual. The Note is still correct, kind of: The iOS and Android VPN clients are supporting IPsec, L2TP, and PPTP only.
Still, this is not intended ot be an excuse for Netgear's silence on this subject.
- golf06222Aspirant
I will never again purchase a Netgear product... No word from Netgear for weeks leading up to today.
I called their support line and this is the "first time of being made aware of the issue". She made it sound like the router is functioning as designed and it's an issue with my iphone. The only thing they will do is replace the router (you pay shipping) which we all know is not the issue.
I'm extremely disappointed and I'm now in possession of a very expensive router that doesn't do what I purchased it to do.
- shamarinVirtuoso
For R7000 beta firmware is available to public with RSA OpenVPN support. I've checked it, OpenVPN is working now.
- Tyree42Initiate
I don't have time or capacity to beta test properly (router is in US, I'm in Taiwan currently). But for those wanting the solution, it's listed in the downloads under hotfix (beta):
https://kb.netgear.com/000057097/R7000-Firmware-Version-1-0-9-30-Hot-Fix
Anyone know if this hotfix works with the entire R7XXX series, or is this for a specific R7000 model router?
Thanks
- JZDallasAspirant
Wow, some people here are just whinning to much. Netgear support said that they are working on a fix. It is in Beta testing right now. I assume you would want a fix that is working and does not have bugs in it. Also, it was stated earlier that the date OpenVPN was saying is not a hard date. It was a soft date. You can still use the app and connect to your home router. As for the person that said he would be taking his back to Costo, and buying a Cisco one. I did a Cisco router, and the first chance it was hit with a surge, the router died. It was connected to a surge protector, and when I bought the Netgear and still was hit, the Netgear router still turned back on and is still kicking.
So I would say, that I have Netgear's back. If you don't like the product, just take it back and get your money or go somewhere else. Also, the person that said that only one router is updated with the fix and what about the little people with other routers, I have a Nighthawk R8500 and I don't have the fix yet. But I am not complaining......
Sounds like you just don't take security as seriously as others, which is fine. Some folks really won't lose anything in the event of a data breach, or don't really care. Sounds like that may be you.
But when you buy a device for its security features, and the vendor refuses to implement a fix on time to responding to things such as expring security certificates it's a serious problem.
- jcw265Tutor
news flash: never post just to see your post on a forum. Your lack of information may confuse users that have true product issues. Here are some facts you may want to verify on your own since you are surely highly educated (not)
1) The VPN issue was announced months in advance from OpenVPN.Most if not all Netgear routers using that solution are no longer providing VPN. This was a hard date and netgear knew about it.
2) People are not whinning on this forum they are expressing a total lack of customer service to the end user from Netgear that states VPN services exist through OpenVPN
3) There are business that no longer have the encryption layer they need for security promised from netgear
4) Routers are used for more then gaming in your moms basement
5) Before you attack a group of users get your facts straight.