Tutorial: How to Connect Without a Client Certificate
Use a server-locked connection profile to connect to Access Server without a client certificate. This tutorial explains how.
Overview
Access Server typically uses unique client certificates and private keys to secure the OpenVPN connection. Each user-locked, and autologin connection profile downloaded from the Access Server includes a unique public and private key pair to identify the client to the server. However, there are scenarios where you may need to connect without client certificates.
By following these steps, you can connect to your Access Server without needing client certificates, simplifying the connection process for certain use cases while maintaining security and functionality.
Tip
Using server-locked profiles provides a streamlined way to manage connections without client certificates, ensuring compatibility and ease of use in scenarios where client certificates are undesirable.
An installed Access Server.
A user account.
OpenVPN Connect on Windows or macOS.
Sign in to the Admin Web UI.
Click VPN Server.
The Network Settings tab displays.
Click the Security / Encryption tab.
Under OpenVPN client certificate requirements, set it to On to Allow VPN connections without client certificates (server-locked v2).
Click Save and Restart.
Click Web Services.
The Admin Web Server tab displays.
Click the Client Web Server tab.
Under Client Web UI settings, check Server-locked profiles for Profile availability.
Click Save and Restart.
Sign in to the Client Web UI with the user account.
Click the Connection Profiles tab.
Click Add New Profile.
Select Server-locked for Profile type.
Click Save and Download.
The connection profile file (.ovpn) downloads.
Once you've downloaded the necessary file, you can import it into OpenVPN Connect using one of three options:
Browse for file.
Drag and drop.
Double-click on .ovpn file.
Browse for file
Obtain the .ovpn file from the VPN server or provider.
Save it to a location on your device.
Launch OpenVPN Connect.
Tap or click the add icon.
The Import Profile screen displays.
Tap or click the File tab.
Tap or click Browse.
Tip
On Windows or macOS, you can also drag and drop the .ovpn file here.
Navigate to the .ovpn file and upload.
The new profile displays in your app.
Drag and drop (Windows and macOS)
Obtain the .ovpn file from the VPN server or provider.
Save it to a location on your device.
Launch OpenVPN Connect.
Click the add icon.
The Import Profile screen displays.
Click the File tab.
Drag and drop your .ovpn profile to the screen.
The Imported Profile screen displays with the profile name, server hostname, and username.
Click Connect to immediately connect, or click the back icon to return to the Profiles screen.
Double-click on .ovpn file (Windows and macOS)
Obtain the .ovpn file from the VPN server or provider.
Save it to a location on your device.
Double-click on the file.
OpenVPN Connect launches and displays the Import .ovpn profile prompt.
Click OK.
The Imported Profile screen displays with the profile name, server hostname, and username.
Click Connect to immediately connect, or click the back icon to return to the Profiles screen.