

When connecting to the server, the client will check that the public key presented matches the one they have cached for that server (conceptually, this is the same as SSH's fingerprint id method). The server generates a keypair, you copy this to every client machine (manually, through a script, etc). using the dedicated Kerio VPN app, which requires a certificate(?), or setting up via Mac Preferences/ Network / add VPN L2TP, which seems to be the only way to set up with a Pre-Shared Secret).


This article provides answers to generally asked questions by the customers regarding the Kerio VPN certificates and the optimal use of security.
