Specify Certificate Location Instead of Importing it

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
mpfrench
Posts: 6
Joined: Fri Jan 23, 2026 5:01 pm

Specify Certificate Location Instead of Importing it

Post by mpfrench » Tue Oct 06, 2026 12:44 pm

Currently, Softether requires importing a certificate to function. I would like to have the option of specifying a file location since I use that file for several different servers.

solo
Posts: 1912
Joined: Sun Feb 14, 2021 10:31 am

Re: Specify Certificate Location Instead of Importing it

Post by solo » Wed Oct 07, 2026 11:06 pm

The internal location is already specified. Use an OS-scheduled script for updates.

QUESTION
I would like to operate my VPN server using a paid SSL certificate issued by a commercial CA, rather than an automatically generated self-signed certificate. In this case, is it possible for the VPN server to present not only the end certificate for the VPN server to the client during the SSL negotiation phase, but also the intermediate certificate?

ANSWER
Yes, it is possible. You should find a directory called "chain_certs" in your VPN Server directory. Please place your X.509 format intermediate certificate files in this directory. The file extension must be ".cer" or ".crt". If there are multiple intermediate certificates in a chain, please place all of them. The filenames must be ASCII strings. The filenames themselves are not important for processing. There is no need to restart the VPN server. The intermediate certificate will be automatically loaded from the next SSL negotiation onwards.
https://ja.softether.org/4-docs/3-kb/VPNFAQ026

Post Reply