Renew Certificates Without Disconnecting Anyone

Certificate management in Access Server is built for continuity –– rotate Certificate Authorities and reprovision client profiles on your own schedule, with no dropped connections while old and new certificates remain valid side by side.

Stop managing certificate renewals like a fire drill

Certificate expirations, especially in some self-managed deployments, can be operationally disruptive. Renewing a Certificate Authority (CA) can require restarting the VPN server, disconnecting active sessions, and redistributing profiles before users can reconnect.

OpenVPN Access Server is designed to help administrators easily plan for that transition by supporting multiple active CAs at the same time. You can create a new CA alongside the existing one, issue new profiles at your own pace, and keep the previous CA available until users have updated their profiles.

No emergency redistribution. No last-minute disruption.

Built-in tools that make certificate management routine

From automatic annual renewal to planned CA rotation, Access Server helps reduce operational risk in certificate lifecycle management, so your team can plan ahead before certificates expire.

Icon Route

Keep users connected during CA rotation

Access Server can trust multiple active CAs at the same time, so previous and new client certificates can coexist while you phase in updated profiles.

Icon Double Avatar

Per-user certificate profiles

Each user account can have multiple connection profiles, giving administrators user-level control over who has migrated and who needs an updated profile.

Use an industry standard

Profile continuity with CA cross-signing

For manual CA rotations, Access Server can cross-sign the previous CA so existing client profiles remain usable while new profiles move to the new CA.

Guided configuration

Automatic annual CA renewal

Access Server automatically creates new CA and server certificates after your configured renewal interval (or 365 days by default). Your PKI stays current without routine manual maintenance.

Improve performance

Full visibility into the certificate lifecycle

See each user’s active profiles, signing CA, and expiration dates from the User Profiles section in the Admin Web UI to easily plan renewals before certificates expire.

FAQs

If you have any difficulties, we have collected all of the useful materials for this product in our video library, tutorials, and documentation. You can also browse Access Server's features.

See what nearly 20,000 customers, hundreds of partners, and all major cloud providers already know.

  1. Jason K.Jason K. REPAY
    Easy to configure options, add users, and that it has two factor authentication built in. You can configure the system to allow connections on common ports so that you're able to connect from pretty much anywhere in the world.
  2. Johnathan B.Johnathan B. Surry Telephone
    Configuring and updating my own server is super simple. In my experience, I've always had some difficulty setting up hardware VPN appliances, but OpenVPN was no-nonsense.
  3. Alex H.Alex H. DGDean
    The OpenVPN Access Server AMI is a great out of the box VPN solution for your AWS VPC...
  4. John G.John G. Anovys, LLC
    OpenVPN offers users a very simple and secure VPN option that is both economical and quick to install. Users are able to easily install it on their client devices.
  5. Jeremy F.Jeremy F. Intelligent Pathways
    The availability of client software for all operating systems and mobile devices means my customers can connect regardless of their setup.
  6. Josh Wc.Josh Wc. nexgen|packaging, LLC
    Excellent, flexible solution for our Azure environment.