Skip to main content

Overview

Aviatrix UserVPN uses a Certificate Authority (CA) to issue and manage the client and server certificates required for secure VPN authentication. When the Controller is first initialized, it creates a self-signed RSA CA with a 10-year validity period. Rotate this CA before it expires or whenever re-keying is required. CA rotation replaces the existing CA certificate and private key with new ones. Rotation includes re-keying, issuing a new CA certificate, and re-issuing UserVPN client and server certificates under the new CA. This guide describes two UserVPN certificate lifecycle workflows: Simple Rotation and Staged Rotation.

When to Rotate the CA

Rotate the CA when:
  • The CA is approaching expiration.
  • The active CA key is compromised or must be rotated.
Rotating the CA invalidates previously issued UserVPN files.

Rotation Options

  • Simple Rotation: one-pass rotation with a brief interruption (recommended).
  • Staged Rotation: staged rollout with minimal downtime.

Perform a Simple Rotation

Use this method when a short downtime window is acceptable. During the simple rotation, the admin distributes (re-issues) client VPN files (.ovpn) once to all VPN users.

Prerequisites

  • Access to Settings > Configuration > Certificate Store on the CoPilot UI.
  • VPN users must be attached to their UserVPN gateway or Load Balancer.
  • Ensure all VPN gateways are up and running before each step.

Step 1: Prepare a New CA in Certificate Store

1

Open the Certificate Store

Go to Settings > Configuration > Certificate Store.
2

Add a certificate

Click + Certificate.
3

Generate or upload the CA

Choose Generate Certificate or Upload Certificate. Generating a new certificate is recommended.
  • For Generate Certificate (recommended):
    1. Enter a name for the new CA.
    2. Select a validity period.
  • For Upload Certificate:
    1. Enter a name for the new CA.
    2. Upload the CA certificate file in PEM format.
    3. Upload the CA private key file in PEM format.
4

Save

Click Add.

Step 2: Add the New CA to UserVPN

1

Open UserVPN Settings

Go to Cloud Fabric > UserVPN > Settings.
2

Start rotation

Click Rotate Certificate.
3

Prepare the new CA

Select the new CA and click Prepare.

Step 3: Verify User Attachments

Ensure all users are attached to their gateways or Load Balancers.
1

Open the Users list

Go to Cloud Fabric > UserVPN > Users.
2

Confirm each user is attached

For each user, ensure the VPN Gateway column is not set to Detached.
If any users are detached, they must be attached to a gateway or Load Balancer before proceeding with the rotation.

Step 4: Activate the New CA

This step takes some time. Do not close the browser window, navigate to other pages, or refresh the page while this process is running.
1

Locate the prepared CA

From Cloud Fabric > UserVPN > Settings, locate the newly Prepared CA entry in the Certificate table.
2

Activate

Click Activate.
After the new CA is activated, take the actions described below.
After activation:
  • All previously issued UserVPN files become invalid. Client certificates signed by the old CA are revoked.
  • All attached VPN users with an email configured automatically receive newly issued VPN files via email.
  • For attached VPN users without an email configured, distribute the new VPN files manually:
    1. Go to Cloud Fabric > UserVPN > Users.
    2. Download the client VPN file for each user without an email address:
      1. Select the user.
      2. Click the three-dot menu on the right side.
      3. Click Download Client Certificate.
      4. Distribute the downloaded client VPN files to the respective users through your own admin channel.

Step 5: Notify Users to Install New VPN Files

Inform all VPN users to download and install the newly issued VPN files from the UserVPN portal.
Users cannot connect to the UserVPN server until they install the newly issued client VPN file.

Step 6: Remove the Old CA

1

Locate the deactivated CA

From Cloud Fabric > UserVPN > Settings, locate the Deactivated CA.
2

Remove the old certificate

Click Remove Old Certificate to delete the old CA from the Certificate table and complete the rotation process.
Failure to remove the old CA may allow authentication using old VPN files.

Perform a Staged Rotation

Use this method for a controlled, low-downtime rotation. This workflow requires additional steps from both administrators and users because the client VPN files (.ovpn) must be distributed two times.

Step 1: Prepare a New CA in Certificate Store

1

Open the Certificate Store

Go to Settings > Configuration > Certificate Store.
2

Add a certificate

Click + Certificate.
3

Generate or upload the CA

Choose Generate Certificate or Upload Certificate. Generating a new certificate is recommended.
  • For Generate Certificate (recommended):
    1. Enter a name for the new CA.
    2. Select a validity period.
  • For Upload Certificate:
    1. Enter a name for the new CA.
    2. Upload the CA certificate file in PEM format.
    3. Upload the CA private key file in PEM format.
4

Save

Click Add.

Step 2: Add the New CA to UserVPN

1

Open UserVPN Settings

Go to Cloud Fabric > UserVPN > Settings.
2

Start rotation

Click Rotate Certificate.
3

Prepare the new CA

Select the new CA and click Prepare.

Step 3: Verify User Attachments

Ensure all users are attached to their gateways or Load Balancers.
1

Open the Users list

Go to Cloud Fabric > UserVPN > Users.
2

Confirm each user is attached

For each user, ensure the VPN Gateway column is not set to Detached.
If any users are detached, they must be attached to a gateway or Load Balancer before proceeding with the rotation.

Step 4: Distribute New Client VPN Files to All Users

Before distributing new VPN files, ensure all users are attached to the correct VPN gateway or Load Balancer. Users who are detached will not receive the updated client VPN file. For users without email addresses:
1

Open the Users list

From Cloud Fabric > UserVPN > Users, select the user.
2

Open the actions menu

Click the three-dot menu.
3

Download the client VPN file

Click Download Client Certificate to save the file locally.
4

Distribute the file

Distribute the VPN file to the user through your preferred admin communication channel.
For users with email addresses:
1

Re-issue client certificates

From Cloud Fabric > UserVPN > Users, click Re-issue Client Certificate.
The system sends the re-issued VPN file to each user’s email inbox. This action does not revoke any certificates. It adds both the new and current CA certificates to the VPN file’s trust bundle.
The re-issued files include both the old and new CA in the trust bundle, allowing a seamless transition for existing users. However, the embedded client certificate is still signed by the old CA. Users must install the second set of files (issued after the new CA is activated in Step 6) before the old CA can be safely removed in Step 7.

Step 5: Notify Users to Install New VPN Files

Inform all VPN users to download and install the newly issued VPN files from the UserVPN portal.
During this phase of the staged rotation, users can continue using their existing VPN connections. The new VPN files become necessary after the CA is activated in the next step.

Step 6: Activate the New CA

1

Open UserVPN Settings

Go to Cloud Fabric > UserVPN > Settings.
2

Activate the prepared CA

Locate the Prepared CA entry in the Certificate table and click Activate.
After the activation, re-issue the client VPN files so that each user receives a client certificate signed by the new CA.
To distribute the post-activation client VPN files:
  • For attached VPN users with email addresses, go to **Cloud Fabric > UserVPN
    Users** and click **Re-issue Client Certificate**. Each user receives a second email containing the newly issued client VPN file, whose embedded certificate is signed by the new CA.
  • For attached VPN users without email addresses, repeat the manual distribution process from Step 4 to provide the second (post-activation) client VPN file through your admin channel.
  • Both client VPN files (issued in Step 4 and after activation) remain valid until the old CA is removed. Any older client VPN files (issued before Step 4) are now invalid.

Step 7: Remove the Old CA

Before removing the old CA, confirm that all VPN users have installed the VPN files distributed after Step 6 (the second distribution). The VPN files issued in Step 4 (first distribution) contain a client certificate signed by the old CA — these profiles stop working immediately when the old CA is removed. Users who only installed the Step 4 files will lose VPN connectivity.If any users have not installed the post-Step 6 files, re-send those files before proceeding.
After confirming all users have installed the latest client VPN files, remove the old CA entry.
1

Open UserVPN Settings

Go to Cloud Fabric > UserVPN > Settings.
2

Remove the deactivated CA

Locate the Deactivated CA entry and click Remove Old Certificate.
This step is critical for maintaining security. If you do not remove the old CA, users with previously issued client VPN files (signed by the old CA) may still be able to authenticate and connect.
If any users report loss of connectivity after this step, they are still using the Step 4 profile. Re-issue their VPN file (it will be signed by the new CA) and have them reinstall it.