Skip to main contentIBM ZLPN Documentation

Create and use a VPN certificate

Quick reference


A VPN certificate lets you connect to the ISV Center private network using the OpenConnect client and reach your provisioned instances. You generate the certificate from the dashboard, then use it with OpenConnect from your terminal.

Note: OpenConnect may provide VPN connectivity but it is not supported supported by Cisco or IBM.

Note: This guide covers connecting with a generated certificate using OpenConnect. If you connect with IBMid single sign-on through the Cisco Secure Client instead, see Access Client VPN with IBMid.


Before you begin

↑ Return to Quick reference


Create a VPN certificate

You can create a certificate in two ways. Auto-generate is recommended for most users; the platform creates the private key and certificate bundle for you. Provide CSR is an advanced option where you supply your own Certificate Signing Request and manage your own private key.

  1. Open the Dashboard and go to the VPN Credentials section.
  2. Click Create VPN certificate, leave Auto-generate (Recommended) selected, and click Next.
  3. Fill in the certificate details:
    • Common name — a unique identifier (for example, test). Your company CEID is appended automatically, so test becomes test-<CEID>. Use only letters, numbers, underscores (_), and hyphens (-); no spaces.
    • Organization — your organization name (for example, IBM).
    • Country — a two-letter ISO country code (for example, US).
    • State — your state or province.
    • Organizational unit and Locality are optional.
  4. Click Create. Generation usually completes within 60–90 seconds.
  5. When the VPN certificate created screen appears:
    • ⚠️Copy and save the certificate password immediately! It is shown only once and cannot be recovered. If you lose it, you must revoke the certificate and create a new one.
    • Click Download Certificate (.p12) and save the file somewhere you can find it.

Provide CSR (advanced)

  1. In the Create VPN certificate dialog, select Provide CSR (Advanced) and click Next.

  2. Generate a private key and CSR on your workstation. For detailed OpenSSL guidance, see Manually Generate a Certificate Signing Request (CSR) Using OpenSSL. The CSR key size must be at least 2048 bits, and the common name must include your CEID. For example:

    openssl req -new -newkey rsa:2048 -nodes \
      -keyout vpn-client.key \
      -out vpn-client.csr \
      -subj "/CN=<unique-name>-<CEID>/O=<organization>/C=<country>/ST=<state>"
    

    Replace <unique-name>, <CEID>, <organization>, <country>, and <state> with your own values. Keep vpn-client.key private; the platform never receives or stores this key.

  3. Paste your CSR, or upload the generated .csr file.

  4. Click Create.

  5. On the success screen, download both the Certificate (CRT) and the CA certificate.

  6. Combine the CRT, the CA certificate, and your own private key into a .p12 bundle. The platform does not hold your private key and cannot provide a .p12 file or password for this flow.

↑ Return to Quick reference


Connect to the VPN

  1. Open your terminal and change to the folder where you saved the certificate:

    cd ~/Downloads
    

    Adjust the path if you saved it elsewhere.

  2. Connect with OpenConnect, passing your IBMid and the certificate file:

    sudo openconnect --user=<your-ibm-id> --certificate=<certificate-file> vpn.dfw.ibm.com
    
  3. When prompted:

    • Enter your system password (for sudo).
    • Enter the certificate passphrase — this is the certificate password you saved when the certificate was created.

The connection is established when the terminal reports a successful connection and stays open.

↑ Return to Quick reference


Verify connectivity

  1. In the dashboard, open your list of provisioned instances and expand an active instance.

  2. Copy the instance IP address.

  3. In a new terminal window, ping the instance:

    ping <instance-ip-address>
    

You should receive replies with no packet loss, which confirms the VPN is working.

↑ Return to Quick reference


Disconnect

In the terminal running the VPN connection, press Ctrl+C to close it. The connection terminates and you are disconnected from the private network.

↑ Return to Quick reference


Revoke a certificate

You can revoke a certificate you no longer need. Revoking is permanent — a revoked certificate cannot be reactivated, and you must create a new one to connect again.

  1. In the dashboard, go to the VPN Credentials section and refresh so the list is current.
  2. Find your certificate in the table and click Revoke.
  3. Confirm the action. Revocation completes within about 60–90 seconds, after which the status changes to Revoked.

The Revoke button is available only to the certificate owner and to company managers. If you don't see it, check with your company administrator.

↑ Return to Quick reference


Troubleshooting

Generation takes longer than expected. Allow up to two minutes and check the screen for any error message before retrying.

You didn't save the certificate password. The password cannot be recovered. Revoke the certificate and create a new one.

The VPN connection fails. Confirm you're using the correct certificate file, that the passphrase is entered correctly, and that the certificate status is Active (not Revoked). Make sure the OpenConnect client is installed correctly.

The ping test fails after connecting. Confirm the VPN connection is still active, that the instance IP is correct and the instance is in the Active state, and that firewall settings allow ICMP (ping) traffic.

↑ Return to Quick reference