Choose an existing server to migrate, or create a new one. The portal fills in its certificate references automatically.
STEP 5 OF 6
Sign the Windows installer
Upload an exportable Code Signing certificate with its private key. A VPN client certificate cannot sign installers.
How do I get the PFX from AD CS?
Create a dedicated Code Signing template with RSA 3072, SHA256, and Allow private key to be exported. Restrict enrollment to your build administrator.
Publish it on your issuing CA.
On your build PC, open certmgr.msc → Personal → Certificates → Request New Certificate and enroll that template.
Export the newly issued certificate with its private key as a password-protected PFX. Upload it here.
The earlier non-exportable certificate needs a replacement enrollment; changing its template does not make its existing private key exportable. Its issuer must be trusted by Windows on this build server.
STEP 6 OF 6
Verify access and build your installer
For a new tunnel subnet, make sure LAN routing returns traffic to OPNsense. The portal does not automatically change firewall rules.
Install on one PC and match its approval code in Device access. Test LAN access, reboot, and certificate revocation before wider rollout.
NETWORK ADMINISTRATION
Device access
Awaiting approval0Approved devices0InstallerReady
Device access
Device
Access
Last contact
VPN status
Actions
Install the client on a PC to request approval.
Revoked devices
These devices cannot obtain replacement certificates while revoked. Delete record removes the entry. A running updated agent can request approval again; an uninstalled agent stays absent. Old certificates remain revoked.
Device
Access
Last contact
VPN status
Actions
No revoked devices.
SETTINGS LOCKED
Your deployment is configured
Routine approvals and revocations happen on Devices. You do not need to reopen setup for those.
This changes the password for Unlock administration on approved Windows clients. It does not change your website login. Online PCs receive it on their next policy check; no MSI rebuild is needed.
Device domain restriction
Deploy agent version 1.2.0 or later before enabling this on existing PCs. No AD computer certificate is required.
Agents 1.2.1 and later automatically check for newer signed releases about hourly. Older agents need the updated RMM script or a manual MSI upgrade once. Upgrades preserve the saved pause setting.
Advanced: change deployment settings
Unlock for ten minutes and work through setup again. Connection changes may interrupt devices.