{"id":3037,"date":"2020-02-25T12:41:40","date_gmt":"2020-02-25T18:41:40","guid":{"rendered":"http:\/\/www.incredigeek.com\/home\/?p=3037"},"modified":"2020-02-25T12:42:23","modified_gmt":"2020-02-25T18:42:23","slug":"create-certificate-on-mikrotik-winbox","status":"publish","type":"post","link":"https:\/\/www.incredigeek.com\/home\/create-certificate-on-mikrotik-winbox\/","title":{"rendered":"Create Certificate on Mikrotik &#8211; WinBox"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Create Certificates<\/h2>\n\n\n\n<p>Open up the Certificates window by going to \/System -> Certificates.  Hit the + to add a new certificate<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Create Certificate Authority Certificate<\/h3>\n\n\n\n<p>First we are going to create a Certificate Authority template<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"626\" height=\"494\" src=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-2.png\" alt=\"\" class=\"wp-image-3039\" srcset=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-2.png 626w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-2-300x237.png 300w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-2-380x300.png 380w\" sizes=\"auto, (max-width: 626px) 100vw, 626px\" \/><figcaption>Setup Certificate Authority template<\/figcaption><\/figure>\n\n\n\n<p>Specify the key usage to &#8220;crl sign&#8221; and &#8220;key cert. sign&#8221; and apply<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"626\" height=\"494\" src=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-3.png\" alt=\"\" class=\"wp-image-3040\" srcset=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-3.png 626w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-3-300x237.png 300w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-3-380x300.png 380w\" sizes=\"auto, (max-width: 626px) 100vw, 626px\" \/><figcaption>Set Certificate Authority Key Usage<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Setup Server Certificate<\/h3>\n\n\n\n<p>Now we are going to create a server template<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"630\" height=\"496\" src=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-6.png\" alt=\"\" class=\"wp-image-3043\" srcset=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-6.png 630w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-6-300x236.png 300w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-6-381x300.png 381w\" sizes=\"auto, (max-width: 630px) 100vw, 630px\" \/><figcaption>Setup Server Template<\/figcaption><\/figure>\n\n\n\n<p>We need to specify &#8220;Digital signature, key encipherment, and tls server&#8221;  You may need to enable\/disable more depending on your use case scenario.  In this case we are setting it up for OpenVPN.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"630\" height=\"496\" src=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-10.png\" alt=\"\" class=\"wp-image-3047\" srcset=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-10.png 630w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-10-300x236.png 300w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-10-381x300.png 381w\" sizes=\"auto, (max-width: 630px) 100vw, 630px\" \/><figcaption>Configure Server Key Usage<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Sign Templates<\/h2>\n\n\n\n<p>First we need to sign the ca-template by opening up the the Certificate and hitting Sign on the right hand side.  Should get the little Sign window pop up.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"630\" height=\"496\" src=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-8.png\" alt=\"\" class=\"wp-image-3045\" srcset=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-8.png 630w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-8-300x236.png 300w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-8-381x300.png 381w\" sizes=\"auto, (max-width: 630px) 100vw, 630px\" \/><figcaption>Sign Certificate Authority<\/figcaption><\/figure>\n\n\n\n<p>Progress will show done when it is finished signing.<\/p>\n\n\n\n<p>Next we need to sign the server-template.  When Signing the server template, specify the ca-template in the CA: field.  See below<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"630\" height=\"496\" src=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-9.png\" alt=\"\" class=\"wp-image-3046\" srcset=\"https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-9.png 630w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-9-300x236.png 300w, https:\/\/www.incredigeek.com\/home\/wp-content\/uploads\/2020\/02\/image-9-381x300.png 381w\" sizes=\"auto, (max-width: 630px) 100vw, 630px\" \/><figcaption>Sign Server Certificate<\/figcaption><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Create Certificates Open up the Certificates window by going to \/System -> Certificates. Hit the + to add a new certificate Create Certificate Authority Certificate First we are going to create a Certificate Authority template Specify the key usage to &hellip; <a href=\"https:\/\/www.incredigeek.com\/home\/create-certificate-on-mikrotik-winbox\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[452],"tags":[922,358,359,923,301,921,388,887,920],"class_list":["post-3037","post","type-post","status-publish","format-standard","hentry","category-mikrotik","tag-ca","tag-cert","tag-certificate","tag-certificate-authority","tag-mikrotik","tag-openvpn","tag-routeros","tag-tls","tag-winbox"],"_links":{"self":[{"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/posts\/3037","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/comments?post=3037"}],"version-history":[{"count":2,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/posts\/3037\/revisions"}],"predecessor-version":[{"id":3049,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/posts\/3037\/revisions\/3049"}],"wp:attachment":[{"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/media?parent=3037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/categories?post=3037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.incredigeek.com\/home\/wp-json\/wp\/v2\/tags?post=3037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}