Buat CA Certificate
/certificate/add name=CA common-name=CA key-usage=crl-sign,key-c
ert-sign
Sign
/certificate/sign CA ca-crl-host=103.1.2.3
Buat Server Certificate
/certificate/add name=server common-name=server key-usage=digita
l-signature,key-encipherment,tls-server
Sign
/certificate/sign server ca=CA
Trusted
/certificate/set trusted=yes server
Buat Client Certificate
/certificate/add name=client common-name=client key-usage=tls-cl
ient
Sign
/certificate/sign client ca=CA
Sampai sini pembuatan certificate sudah selesai, selanjutnya adalah mengeksport certificate agar bisa dipakai oleh OVPN Client
Export Certificate
/certificate/export-certificate CA type=pem file-name=CA
Certificate CA digunakan hanya untuk OVPN Client Android, Jika client yang akan tersambung adalah perangkat mikrotik maka tidak perlu export CA Certificate
/certificate/export-certificate client type=pem export-passphras
e=password file-name=client
Setelah export selesai akan muncul fila yang bernama client.crt
dan client.key
Konfigurasi OVPN Client (Mikrotik)
Upload certificate client, setelah file ter upload lakukan import
/certificate import file
-name=client.crt passphrase=password
/certificate import file
-name=client.key passphrase=password