Create and use a VPN certificate
Quick reference
- Before you begin
- Create a VPN certificate
- Connect to the VPN
- Verify connectivity
- Disconnect
- Revoke a certificate
- Troubleshooting
A VPN certificate lets you connect to the ISV Center private network using the OpenConnect client and reach your provisioned instances. You generate the certificate from the dashboard, then use it with OpenConnect from your terminal.
Note: OpenConnect may provide VPN connectivity but it is not supported supported by Cisco or IBM.
Note: This guide covers connecting with a generated certificate using OpenConnect. If you connect with IBMid single sign-on through the Cisco Secure Client instead, see Access Client VPN with IBMid.
Before you begin
- A valid IBMid with platform access.
- The OpenConnect VPN client installed on your machine.
- At least one active provisioned instance, if you want to test connectivity.
Create a VPN certificate
You can create a certificate in two ways. Auto-generate is recommended for most users; the platform creates the private key and certificate bundle for you. Provide CSR is an advanced option where you supply your own Certificate Signing Request and manage your own private key.
Auto-generate (recommended)
- Open the Dashboard and go to the VPN Credentials section.
- Click Create VPN certificate, leave Auto-generate (Recommended) selected, and click Next.
- Fill in the certificate details:
- Common name — a unique identifier (for example,
test). Your company CEID is appended automatically, sotestbecomestest-<CEID>. Use only letters, numbers, underscores (_), and hyphens (-); no spaces. - Organization — your organization name (for example,
IBM). - Country — a two-letter ISO country code (for example,
US). - State — your state or province.
- Organizational unit and Locality are optional.
- Common name — a unique identifier (for example,
- Click Create. Generation usually completes within 60–90 seconds.
- When the VPN certificate created screen appears:
- ⚠️Copy and save the certificate password immediately! It is shown only once and cannot be recovered. If you lose it, you must revoke the certificate and create a new one.
- Click Download Certificate (.p12) and save the file somewhere you can find it.
Provide CSR (advanced)
-
In the Create VPN certificate dialog, select Provide CSR (Advanced) and click Next.
-
Generate a private key and CSR on your workstation. For detailed OpenSSL guidance, see Manually Generate a Certificate Signing Request (CSR) Using OpenSSL. The CSR key size must be at least 2048 bits, and the common name must include your CEID. For example:
openssl req -new -newkey rsa:2048 -nodes \ -keyout vpn-client.key \ -out vpn-client.csr \ -subj "/CN=<unique-name>-<CEID>/O=<organization>/C=<country>/ST=<state>"Replace
<unique-name>,<CEID>,<organization>,<country>, and<state>with your own values. Keepvpn-client.keyprivate; the platform never receives or stores this key. -
Paste your CSR, or upload the generated
.csrfile. -
Click Create.
-
On the success screen, download both the Certificate (CRT) and the CA certificate.
-
Combine the CRT, the CA certificate, and your own private key into a
.p12bundle. The platform does not hold your private key and cannot provide a.p12file or password for this flow.
Connect to the VPN
-
Open your terminal and change to the folder where you saved the certificate:
cd ~/DownloadsAdjust the path if you saved it elsewhere.
-
Connect with OpenConnect, passing your IBMid and the certificate file:
sudo openconnect --user=<your-ibm-id> --certificate=<certificate-file> vpn.dfw.ibm.com -
When prompted:
- Enter your system password (for
sudo). - Enter the certificate passphrase — this is the certificate password you saved when the certificate was created.
- Enter your system password (for
The connection is established when the terminal reports a successful connection and stays open.
Verify connectivity
-
In the dashboard, open your list of provisioned instances and expand an active instance.
-
Copy the instance IP address.
-
In a new terminal window, ping the instance:
ping <instance-ip-address>
You should receive replies with no packet loss, which confirms the VPN is working.
Disconnect
In the terminal running the VPN connection, press Ctrl+C to close it. The connection terminates and you are disconnected from the private network.
Revoke a certificate
You can revoke a certificate you no longer need. Revoking is permanent — a revoked certificate cannot be reactivated, and you must create a new one to connect again.
- In the dashboard, go to the VPN Credentials section and refresh so the list is current.
- Find your certificate in the table and click Revoke.
- Confirm the action. Revocation completes within about 60–90 seconds, after which the status changes to Revoked.
The Revoke button is available only to the certificate owner and to company managers. If you don't see it, check with your company administrator.
Troubleshooting
Generation takes longer than expected. Allow up to two minutes and check the screen for any error message before retrying.
You didn't save the certificate password. The password cannot be recovered. Revoke the certificate and create a new one.
The VPN connection fails. Confirm you're using the correct certificate file, that the passphrase is entered correctly, and that the certificate status is Active (not Revoked). Make sure the OpenConnect client is installed correctly.
The ping test fails after connecting. Confirm the VPN connection is still active, that the instance IP is correct and the instance is in the Active state, and that firewall settings allow ICMP (ping) traffic.