We are working on testing the Microsoft’s Always On VPN solution. It is recommended to use the ECC certificates (Elliptic-curve cryptography) for performance and security reasons (256-bit ECC versus 2028 bit RSA key I’m assuming improves the performance, but I’m not sure how it is more secure).
After generating the CSR for the certificate using these instructions we pasted the CSR into GoDaddy to generate the certificate. However after submitting the CSR we got the following error message:
“This CSR was created with an invalid algorithm”
After a call with GoDaddy Support, they confirmed that they do not currently support ECC or ECDSA or DSA keys on certificates and only support RSA keys. If you use GoDaddy and need an ECC certificate, please give GoDaddy Support a call to ask for these keys to be supported going forward. Hopefully enough people will contact them that they add this feature in the future.