How to edit legacy configuration file for successful import

My school has overly restrictive firewall rules, effectively blocking all ports used by PIA.  As a result, I'm trying to configure OpenVPN on my iPhone by using one of the legacy configuration files provided on the site here that uses port 443.  I'm trying to use the configuration files associated with "LEGACY-TCP-IP" (located HERE).  Within this .zip file, I want to edit the "US East.ovpn" file so that it can be easily imported using the OpenVPN Connect app on my iPhone.  If I try to simply import it as it is, I get errors because ca.crt and crl.pem are not found.  I tried to edit the .ovpn file on my own and adding the contents of these 2 files (since they are also included in the .zip file), but I must be doing something wrong, because I end up with another error after importing and trying to connect (OpenVPN error: PolarSSL: ca certificate is undefined).

So, I'm basically having no success at all getting this .ovpn file with legacy configuration settings working.

Can someone tell me how to properly edit the "US East.ovpn" file so that I can successfully import it into the OpenVPN app on my iPhone and use it to connect to PIA via TCP port 443?

Thank you very much in advance!
Andrew

Comments

  • Any chance you could post your configuration? 

    I'm also happy to send one to you, if you'd like :)
  • If you wouldn't mind sending or posting a copy of yours, I would greatly appreciate it.  This is the content of my edited "US East.ovpn".  I somewhat modeled it after the new (non-legacy) one that imports just fine.  I pasted the contents of ca.crt and crl.pem into it with tags, and removed references to them that were there before:

    client
    dev tun
    proto tcp
    remote 66.55.134.219 443
    resolv-retry infinite
    nobind
    persist-key
    persist-tun
    <ca>-----BEGIN CERTIFICATE-----
    MIID2jCCA0OgAwIBAgIJAOtqMkR2JSXrMA0GCSqGSIb3DQEBBQUAMIGlMQswCQYD
    VQQGEwJVUzELMAkGA1UECBMCT0gxETAPBgNVBAcTCENvbHVtYnVzMSAwHgYDVQQK
    ExdQcml2YXRlIEludGVybmV0IEFjY2VzczEjMCEGA1UEAxMaUHJpdmF0ZSBJbnRl
    cm5ldCBBY2Nlc3MgQ0ExLzAtBgkqhkiG9w0BCQEWIHNlY3VyZUBwcml2YXRlaW50
    ZXJuZXRhY2Nlc3MuY29tMB4XDTEwMDgyMTE4MjU1NFoXDTIwMDgxODE4MjU1NFow
    gaUxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJPSDERMA8GA1UEBxMIQ29sdW1idXMx
    IDAeBgNVBAoTF1ByaXZhdGUgSW50ZXJuZXQgQWNjZXNzMSMwIQYDVQQDExpQcml2
    YXRlIEludGVybmV0IEFjY2VzcyBDQTEvMC0GCSqGSIb3DQEJARYgc2VjdXJlQHBy
    aXZhdGVpbnRlcm5ldGFjY2Vzcy5jb20wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJ
    AoGBAOlVlkHcxfN5HAswpryG7AN9CvcvVzcXvSEo91qAl/IE8H0knKZkIAhe/z3m
    hz0t91dBHh5yfqwrXlGiyilplVB9tfZohvcikGF3G6FFC9j40GKP0/d22JfR2vJt
    4/5JKRBlQc9wllswHZGmPVidQbU0YgoZl00bAySvkX/u1005AgMBAAGjggEOMIIB
    CjAdBgNVHQ4EFgQUl8qwY2t+GN0pa/wfq+YODsxgVQkwgdoGA1UdIwSB0jCBz4AU
    l8qwY2t+GN0pa/wfq+YODsxgVQmhgaukgagwgaUxCzAJBgNVBAYTAlVTMQswCQYD
    VQQIEwJPSDERMA8GA1UEBxMIQ29sdW1idXMxIDAeBgNVBAoTF1ByaXZhdGUgSW50
    ZXJuZXQgQWNjZXNzMSMwIQYDVQQDExpQcml2YXRlIEludGVybmV0IEFjY2VzcyBD
    QTEvMC0GCSqGSIb3DQEJARYgc2VjdXJlQHByaXZhdGVpbnRlcm5ldGFjY2Vzcy5j
    b22CCQDrajJEdiUl6zAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4GBAByH
    atXgZzjFO6qctQWwV31P4qLelZzYndoZ7olY8ANPxl7jlP3YmbE1RzSnWtID9Gge
    fsKHi1jAS9tNP2E+DCZiWcM/5Y7/XKS/6KvrPQT90nM5klK9LfNvS+kFabMmMBe2
    llQlzAzFiIfabACTQn84QLeLOActKhK8hFJy2Gy6
    -----END CERTIFICATE-----
    </ca>cipher bf-cbc
    auth sha1
    tls-client
    remote-cert-tls server
    auth-user-pass
    comp-lzo
    verb 1
    reneg-sec 0
    <crl-verify>-----BEGIN X509 CRL-----
    MIIBkzCB/TANBgkqhkiG9w0BAQ0FADCBpTELMAkGA1UEBhMCVVMxCzAJBgNVBAgT
    Ak9IMREwDwYDVQQHEwhDb2x1bWJ1czEgMB4GA1UEChMXUHJpdmF0ZSBJbnRlcm5l
    dCBBY2Nlc3MxIzAhBgNVBAMTGlByaXZhdGUgSW50ZXJuZXQgQWNjZXNzIENBMS8w
    LQYJKoZIhvcNAQkBFiBzZWN1cmVAcHJpdmF0ZWludGVybmV0YWNjZXNzLmNvbRcN
    MTYwNzA4MTkwMDQ2WhcNMzYwNzAzMTkwMDQ2WjAmMBECAQEXDDE2MDcwODE5MDA0
    NjARAgEGFwwxNjA3MDgxOTAwNDYwDQYJKoZIhvcNAQENBQADgYEALc0LlIZ8BbDq
    7nyyS6VSiiYv6gKb1H2IV4neLXkiMcij9VLnLFrsO+RRZMXXcWGeE/WssYYVCugO
    OTCCie8HtNRe5UItO59a8f6mhN/WMbZYGKG7qG7pjrnMI34czbrHl0SOuJhOunoJ
    DAVtqbc8RJNEmepIxJfLXgDaUKoJaJs=
    -----END X509 CRL-----
    </crl-verify>

Sign In or Register to comment.