I've had a bit of a tough time this weekend with X.509 certificates. Vigor routers don't seem to handle anything other than certificates which use SHA1 and 1024-bit keys.
It would be nice if, should the router encountered a certificate it could not cope with, it would say so, rather than simply saying "OK" and then refusing to make a VPN connection.
Or at least put the certificate limitations on the upload page...