Once the certificates for a server and its clients have been renewed, the new certificates need to be sent to all clients, and activated.
- Log in to ARM600's WHMI as the arctic-adm user.
- On the left pane under the VPN menu, select OpenVPN.
- Go to the OpenVPN Certificate Update tool in one of the alternative ways.
- Click the upload icon as shown in Figure 1.
Figure 1. Certificate upload icon - Click the upload icon next to one OpenVPN client to transfer new certificates only to a specific client.
The tool now shows a list of clients for the chosen OpenVPN server as shown in Figure 2.
Figure 2. OpenVPN peers and certificate status Column Certificate on device expires shows when the certificate installed on the device expires. Since ARM600 might not know how the device is configured, this column might contain "unknown" values. The device status can be queried with the Check certificate status tool.
- Click the upload icon as shown in Figure 1.
- Click the check boxes on the left of the Name column to select the devices that should be updated.
Usually all devices should be updated, unless some devices were already updated.
- Click Continue to start the update process.
- Check the progress of the certificate transfer in one of the alternative ways.
- Click the Return to Management page button.
- Navigate to Management under the Arctic Patrol menu on the left pane.
- On the Patrol Management page, near the top of the running and old batches list, click the title Update client certificate to see the progress of the certificate update.
Figure 3. Certificate update batch details On this page, under Results, the status of the update for each device is shown. For these changes to take effect, the Arctic wireless devices that have been updated need to be rebooted separately. This can be done as described in the Rebooting Arctic devices section in this manual.