Impossible to export certificate

I was following this guide so that my devices trust the RUTX11 webUI under HTTPS:

I am able to generate the certificates and everything, but the “export” (download) of the “ca.cert.pem” certificate doesn’t work as expected; nothing happens after I confirm to proceed, no file is downloaded to the browser.

My RUTX11 is on the latest firmware version, RUTX_R_00.07.15.2, and was factory reset just a few days ago in order to start fresh in my new setup. I’ve tried downloading the certificate from 3 different web browsers without success.

(Newer FW version “RUTX_R_00.07.15.4” was released just yesterday but contains no fix relevant to certificates according to the changelog)

If any Teltonika staff employee is in the vicinity, could the procedure be tested on a RUTX11 with this firmware? I’d be surprised if the issue was isolated to my instance.

Thank you!

Greetings,

Thank you for reaching out.

I’d like to inform you that we are currently reviewing and investigating your inquiry regarding the certificate exporting on 7.15.2. I’ll get back to you as soon as we have specific details, insights, or a confirmed results.

We sincerely appreciate your patience and understanding in the meantime.

Best regards,

Furthermore, may I ask which browser you are using? Additionally, have you tried clearing the browser cache or refreshing the page before attempting to export the certificate? I’ve tested this on my end using Google Chrome and wasn’t able to replicate the described behavior, after refreshing the page, the export function worked as intended and allowed me to download the certificate.

Best regards,

Hello Martynas,

Thank you for following up and making the test!

I was using a mobile device when I made that attempt (couldn’t use a computer at that time), using Chrome and Opera. I had tried in incognito so I didn’t feel the need to clear the cache.

I just tested on a computer and I was able to download the certificate successfully.

I believe the export button is broken on the mobile version of the site. If I use the dev tools on a desktop browser to simulate the mobile layout, the export button stops working. Are you able to replicate this?

Thank you!

Hello,

Thank you for your follow-up and the additional details. I’ve tested this on my side as well using the mobile WebUI layout and was able to replicate the same behavior.

I’ve forwarded this information to our developers so they can review and analyze the situation further. I’ll make sure to update you as soon as there’s any feedback or resolution from their side.

Thank you very much for bringing this to our attention and for your cooperation.

Best regards,

I truly appreciate it!

Since I was able to export the certificate, I followed the procedure to remove the HTTPS warnings (wiki article included in my original comment) but it doesn’t appear to work. After I upload the “ca.cert.pem” file to my device, the webUI becomes inaccessible with a certificate invalid warning, and which the browser doesn’t allow me to bypass.

After some trial and error, I can only conclude that the procedure doesn’t work on the latest firmware; instead, if I keep the HTTPS server certificate/key to the default values of “uhttpd.crt” and “uhttpd.key” under “Access control”, a button appears at the bottom to download the certificate, and that certificate works as expected when uploaded to the CA certificates store of my device. This wiki article probably needs to be reviewed.

Hello again,

Is it possible that manually adding DNS servers to the section “Network > DNS > General” doesn’t work either on the mobile WebUI? They disappear after I “Save & Apply”. But if I assign them to the WAN interface directly, they are saved.

Hello @Philippe_Choquette,

Apologies for the delay in getting back here. Could you please confirm which safe browsing security setting is enabled in the browser you’re using? If you’re using Google Chrome, try selecting “Standard protection” under the Safe browsing settings. After that, upload the server certificate authority (ca.cert.pem) through Manage user certificates or directly via the browser’s Certificate Manager. This, in my case, removed the HTTPS warnings, and the WebUI connection became trusted.

Regarding your observation with manually adding DNS servers through the mobile WebUI, you are correct, there is a known issue with the mobile layout and some frontend functionalities where settings may not be saved or displayed correctly. Our developers are aware of this and are working on improving mobile interface behavior in upcoming updates. Nevertheless, thank you for highlighting this discrepancy with us.

Feel free to reach out if you have any further questions or need assistance with anything else.

Best regards,

Hello Martynas,

Thank you for following up! I’m using Opera as the browser. “Safe browsing” is enabled, but that’s the default state of that setting, and so most users will have that on.

The “baked-in” certificate that you can download from System > Administration > Access Control > HTTPS > Advanced settings actually doesn’t require any further step than to import it at the OS level. Once you do, it removes the security warning on any web browser you have installed; you don’t have to disable “Safe browsing”, nor manually import the certificate in each browser. Meanwhile, the procedure on your Wiki page doesn’t reference this anywhere, while the procedure listed simply doesn’t work as it should.

It is crystal clear that your firmware team did changes to the way certificates work in the WebUI, and didn’t pass the information along to their peers responsible for keeping the documentation up to date.

Also, for having tried again, the current procedure still doesn’t work after having disable “Safe browsing” on Opera mobile, with no capability to import the certificate at the browser level regardless. The certificate generation tool on the RutOS WebUI appears broken, and only the other way (likely recently implemented) works.

Hello,

Thank you for your detailed clarification regarding the default uhttpd.crt server certificate. You are correct, when accessing the device locally, importing this certificate at the OS level removes the security warning in any web browser without needing to disable “Safe browsing” or manually import it per browser.

However, if you need to remove the warning when accessing the device via the internet, you would still need to follow the steps provided in the wiki article, as the local certificate alone does not cover external access scenarios.

Feel free to reach out if you have any further questions.

Best regards,