A year ago I set up a new environment for a company who decided to host everything in Azure.
I set up the virtual machines, the storage, the backups and everything that came along with that. I also gave them a Point to Site VPN connection so they could independently make changes and modify / add data as needed.
Today that VPN connection stopped working. Why? Simple. The cert expired. Microsoft have written great documentation on this topic but by default, the root and client certificates only last for one year. That’s for security reasons of course. Each year, you renew your certificates and if someone has a certificate that should no longer be allowed, that cert becomes invalid. Nice and easy.
However, in addition to using certs, I also have accounts that I can modify on the local machines and each group of people have a different route cert so replacing certs isn’t a major problem.
That said, I wanted the certs to last longer than 1 year. I could have made them last 10 years but I thought 3 years was a happy medium.
You could of course create the scripts using a GUI but here’s a faster way that uses Powershell.
$date_now = Get-Date
$extended_date = $date_now.AddYears(3)
$cert = New-SelfSignedCertificate -Type Custom -KeySpec Signature
-Subject "CN=P2SRootCert" -KeyExportPolicy Exportable
-HashAlgorithm sha256 -KeyLength 2048
-CertStoreLocation "Cert:\CurrentUser\My" -KeyUsageProperty Sign -KeyUsage CertSign -Notafter $extended_date
Now create the client cert using this.
New-SelfSignedCertificate -Type Custom -DnsName P2SChildCert -KeySpec Signature
-Subject “CN=P2SChildCert” -KeyExportPolicy Exportable
-HashAlgorithm sha256 -KeyLength 2048
-CertStoreLocation “Cert:\CurrentUser\My” `
-Signer $cert -TextExtension @(“2.5.29.37={text}1.3.6.1.5.5.7.3.2”) -Notafter $extended_date
When you’re ready, open the route cert. Remove the lines at the top and bottom of the file that indicate the start and end of the certificate then in Azure, browse to All Resources \ Your VPN Gateway, Configure Point to Site VPN
Now add the new root certificate.
When you’re ready, download the VPN client. ON the same Screen in the Azure portal, click Download VPN client.
If needed, remember to export your certificate. Include to private key and give the exprrted PFX file a good strong password.

About a year ago, Nama, my guide dog had a few negative encounters with other dogs. He was attacked a few times by loose dogs and after a few of these encounters, he decided that he would attack before they attacked him.
Another Christmas is over. Christmas is my favourite time of the year. I hate the marketing side of things. But fortunately we very rarely have a television on in this house and when we do, we tend to stick to streaming services such as Netflix so advertisements have minimal impact on our household. The reason I enjoy Christmas is it’s always a great opportunity to spend far too much time with family and friends. I say far too much time because invariably we gravitate to a particular house each year. Recently it’s because Méabh and Rían are getting enjoyment from the other children in that house. I hear some people say that after the hype leading up to Christmas they are just tired of it and within a few days they don’t know what to do. I’ve never found that. I managed to take just over two weeks off this year. I spent a lot of time with the children, the dogs and my wife. I also got to spend about two days working on things that I wanted to spend time on. I could easily spend another two weeks doing the same. No day is boring. There’s always something to be done, someone to visit or somewhere interesting to travel to. IT’s the lack of defined things to do that makes Christmas so enjoyable for me.
Tomorrow, I’m back to work, the children are back to school and life will return to normal. I’m reasonably okay with that. There are a few things that I want to get stuck into in work and I’m looking forward to ramping up the music side of things in anticipation of the Fleadh in Drogheda in August. It’s going to be a busy 8 months until the next decent block of time off. It’s an eight months where I’ll have a lot to do but if I play my cards right, the hard work will be rewarding and the commitment will pay off.
Anyway, getting to the point of all this, the Cobblestone session was as inviting as always. As soon as I walked in the door, a stool was presented and I was welcomed in. The tunes were slow which wouldn’t usually be my style but I enjoy the change so I settled in for a few hours of tunes, stories and craic.
Back to the music. Toales was just getting started when I arrived shortly after ten. But already powerful musicians Andrew Kelly, Graine Smyth, Finien O’Connor and Feargal Mcardle were starting a set. Again I was warmly welcomed and the tunes flowed. About half an hour Sean Conway joined giving an already powerful session another boost. Shortly after that Oisin McCann joined. Then Tadhg Mulligan walked in around 12am and of course a seat materialized and he was promptly told to sit down and play a few tunes. There were others there as well. Caoimhe on the fiddle, Keili on the accordion and more on flutes and fiddles. It was just an amazing night of tunes. Tunes that I’d never dream in weird time signatures like 7 8 were encouraged and enjoyed.
