SSTP connection error

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
Omid
Posts: 14
Joined: Mon Oct 10, 2016 5:12 pm

SSTP connection error

Post by Omid » Mon Oct 17, 2016 4:15 pm

Hello,

I am a little puzzled as how to setup SSTP to work properly. I searched the forums and read the manuals but found no clue/answer.

When the client tries to connect, Windows 10 shows the following error message:

"A certificate chain processed, but terminated in a root certificate that is not trusted by the trust provider."

Well, this means the certificate is not valid, and in this case, it is self-signed.

AFAIK, one workaround is to install a valid (real) certificate on the server. But I don't know how to set SoftEther to use that certificate for SSTP connections.

Another workaround is to install the certificate on client's machine (this is preferred as I don't want to spend money for SSL right now), but again I don't know where to see/edit/export the current certificate SoftEther is using for SSTP.

My SoftEther server is installed on Windows 2012 R2 server.

Any help would be much appreciated.

Regards
Omid

fededim
Posts: 2
Joined: Sun Nov 06, 2016 11:34 pm

Re: SSTP connection error

Post by fededim » Sun Nov 06, 2016 11:50 pm

You can import/export the server certificate by clicking "Encryption and network" button from main menu. With export you can save the certificate as file and import it into Windows's trusted root CA. The problem is that even doing this I receive the same error (I am also using Windows 10). Try and let me know.

Is there any way to specify the SSTP listening port ?!? I believe that Softether will listen for sstp connections on any of the tcp listeners listed (like it does for OpenVPN), yet the documentation does not state anything about this.
Last edited by fededim on Mon Nov 07, 2016 5:35 pm, edited 1 time in total.

fededim
Posts: 2
Joined: Sun Nov 06, 2016 11:34 pm

Re: SSTP connection error

Post by fededim » Mon Nov 07, 2016 5:32 pm

Just un update, I managed to make it work. You need to:
- Import the certificate in Windows as a machine certificate (and not user certificate). In order to be sure that the certificate works just browse to https://<your softether domain>:<listening port> it should return an empty page without warning about the invalid certificate.
- Enable Softether SecureNAT and configure dhcp server.

p.s. It can confirm that softether SSTP listens on all defined tcp port listeners.

Post Reply