As most people will notice, by default the OpenVPN Access Server comes with a self-signed SSL/TLS web certificate. This leads to an ominous warning when first accessing the web interface. For technical reasons it is not possible to ensure that the Access Server starts out with a trusted web certificate so that this warning does not occur.

OpenVPN certificate generator

daemon cd /opt/etc/openvpn mode server port 443 proto tcp-server dev tap0 chroot /opt/etc/openvpn/chroot/ ca /tmp/openvpn/ca.crt cert /tmp/openvpn/cert.pem key /tmp/openvpn/key.pem dh /tmp/openvpn/dh.pem tls-auth /tmp/openvpn/ta.key 0 client-config-dir ccd ccd-exclusive status logs/openvpn-status.log log logs//openvpn.log cipher AES-256-CBC OpenVPN - MikroTik Wiki Before using require-client-certificate option, CA and correct server/client certificate must be imported to both OpenVpn server and client. OpenVPN server Instance. At the moment, it looks like, that even though we've specified the vpn-bridge in the profile, RouterOS does not honour that fact. Connect to a VNet using P2S VPN & certificate Certificates are used by Azure to authenticate clients connecting to a VNet over a Point-to-Site VPN connection. Once you obtain a root certificate, you upload the public key information to Azure. The root certificate is then considered 'trusted' by Azure for connection over P2S to the virtual network.