Jump to content
Not connected, Your IP:
Sign in to follow this  

ANSWERED New CA and Certificate - No access to config generator

Recommended Posts

Posted ... (edited)

Hi everyone!

I have a system up and running for many many years now using the same config file.  I connect to europe.vpn.airdns.org. I suppose my key will still work afterwards anyways.

My tunnel stopped working a few days ago. I saw all the other topics on here, however I do not have access to the config generator - long story. 

I guess i could just update the CA if i could get my hands on that. But iirc the certificate is my client certificate which expired a few days ago. Is there any way to update this?
I tried downloading the CA directly from the servers with

openssl s_client -showcerts -connect europe.vpn.airdns.org:443
But that doesn't seem to be getting a certificate chain from them. I would be happy if someone can point me in the right direction.
  Edited ... by jowlo

Share this post

Link to post


You must enter the Configuration Generator while you are logged in to the web site with an account having a valid plan. If you try to enter with an account that does not have access to AirVPN, the CG can't generate anything because the account does not have an OpenVPN certificate or a WireGuard key etc. To clarify, when you try to enter the CG from an account which does not have any valid certificate and/or key, you get a descriptive error message.

"jowlo" has never had a valid plan to enter AirVPN, probably you have a different account, please check.

Kind regards

Share this post

Link to post


Thanks for the quick answer. I know, but this is a device managed by another account. I do not have access to that account to regenerate the configuration for this device. 

My question was whether there is another way of extending the lifetime of the certificate and getting the new CA without the use of the Configuration Generator. But it appears not, thank you anyways...

Share this post

Link to post
14 minutes ago, jowlo said:


Thanks for the quick answer. I know, but this is a device managed by another account. I do not have access to that account to regenerate the configuration for this device. 

My question was whether there is another way of extending the lifetime of the certificate and getting the new CA without the use of the Configuration Generator. But it appears not, thank you anyways...


Well, very strange case. BTW, ca.crt is just a public certificate and is always the same, so no, the Configuration Generator is not strictly needed, once any account has the ca.crt, it can be sent to any other account. The client certificate and key, on the contrary, are secret and non-sharable files.

Kind regards

Share this post

Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Security Check
    Play CAPTCHA Audio
    Refresh Image
Sign in to follow this  

  • Create New...