Hi!
On Mon, 2022-05-30 at 19:41:08 +0200, [EXT] Bernhard Schmidt wrote:
> Control: tags -1 + moreinfo
> > Just upgraded openvpn the other day and could not connect anymore to the
> > VPN. Reverting back to 2.5.6-1 makes it work again. I checked #1011473
> > and nothing there seemed relevant. Here's an (edited) excerpt from the
> > log (from today's retry):
> >
>
> > 2022-05-30 18:07:08 us=863166 AUTH: Received control message: AUTH_FAILED
>
> This one looks weird, do you have any chance to check the logs on the other
> side?
I've asked our admin, and I'm told the client authenticates correctly
but fails on the push request, but I'll try to ask for the actual
logs.
> > The auth setting is locally set to SHA512, I'm assuming OpenSSL remaps
> > it, but that's just a warning. It just seems to be failing at the
> > PUSH_REQUEST step. Setting «compat-mode 2.5.6» did not help either.
>
> This (different name between OpenSSL 1.1 and OPenSSL 3.0 for the same algo)
> has been fixed upstream already, but not yet imported into the dco tree.
Ah great, thanks.
> Unless you run opt-verify on the other side that should not matter though.
I'm also told we are not using opt-verify on the server side.
I've asked whether we can enable more verbose output on the server
side to try to see what might be going on there, but that will not be
possible until next week or so. If you have no other suggestions or
ideas what I could try from the client side, I'll try to come back with
some better logs from the server side around next week or so.
Thanks,
Guillem