On Mon, 2015-02-16 at 21:50 +0100, Bj?rn Ketelaars wrote: > I attempted to build a simple PKI using the examples in ocserv(8). Last step in > the generation of a client certificate is the conversion of a certificate in to > PKCS #12. Unfortunately the resulting file is not compatible with openconnect > (tested in OSX and OpenBSD): [...] > I suspect that openconnect does not like PKCS #12 in PEM format. It does > however like DER format. Easy solution is to change the certtool example in > ocserv(8) to include the --outder switch. Thanks. I've updated the manpage to include that step. regards, Nikos