Page 1 of 1

Specify Certificate Location Instead of Importing it

Posted: Tue Oct 06, 2026 12:44 pm
by mpfrench
Currently, Softether requires importing a certificate to function. I would like to have the option of specifying a file location since I use that file for several different servers.

Re: Specify Certificate Location Instead of Importing it

Posted: Wed Oct 07, 2026 11:06 pm
by solo
The location is already specified. Use an OS scheduled script for updates.

QUESTION
I would like to operate my VPN server using a paid SSL certificate issued by a commercial CA, rather than an automatically generated self-signed certificate. In this case, is it possible for the VPN server to present not only the end certificate for the VPN server to the client during the SSL negotiation phase, but also the intermediate certificate?

ANSWER
Yes, it is possible. You should find a directory called "chain_certs" in your VPN Server directory. Please place your X.509 format intermediate certificate files in this directory. The file extension must be ".cer" or ".crt". If there are multiple intermediate certificates in a chain, please place all of them. The filenames must be ASCII strings. The filenames themselves are not important for processing. There is no need to restart the VPN server. The intermediate certificate will be automatically loaded from the next SSL negotiation onwards.
https://ja.softether.org/4-docs/3-kb/VPNFAQ026