Problem connecting after updating to 4.0.1 (build 5970 & 5971)

1,110 views
Skip to first unread message

Anthony Skeens

unread,
Mar 14, 2024, 8:22:06 AM3/14/24
to tunnelblick-discuss
Hello all,

OpenVPN has been working flawless until 2 days ago when I updated to 4.0.1 (build 5970).  Tried following the "Warning" message but was still unable to connect.  Today I updated to 4.0.1 (build 5971) hoping this would fix my issue but still cant get a connection.  I was going to uninstall and reinstall OpenVPN but didnt due to reading notes about not doing this to fix an issue so I didnt.

Any help will be greatly appreciated, and I hope I didnt overlook a conversation that explains how to fix this.

Thanks

*Tunnelblick: macOS 10.15.7 (19H2026); Tunnelblick 4.0.1 (build 5971); prior version 3.8.8g (build 5779.3); Admin user
git commit 2a85efdab228d7d29828ab63061eb59f799f84fa
The Tunnelblick.app process is not being translated (x86_64)
System Integrity Protection is enabled
Model: MacBookPro16,4

================================================================================

Configuration Macaluso

"Sanitized" condensed configuration file for /Users/anthonyskeens/Library/Application Support/Tunnelblick/Configurations/Macaluso.tblk:

client
dev tun
proto udp
remote 134.56.75.70 1194
resolv-retry infinite
nobind
persist-key
persist-tun
verb 3
<ca>
[Security-related line(s) omitted]
</ca>
<cert>
[Security-related line(s) omitted]
</cert>
<key>
[Security-related line(s) omitted]
</key>

================================================================================

Files in Macaluso.tblk:
      Contents/Resources/config.ovpn

================================================================================

Configuration preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
-lastConnectionSucceeded = 0
-tunnelDownSoundName = None

================================================================================

Wildcard preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0

================================================================================

Program preferences:

allowNonAdminSafeConfigurationReplacement = 1 (forced)
launchAtNextLogin = 1
menuIconSet = 3.3.TBMenuIcons
tunnelblickVersionHistory = (
    "4.0.1 (build 5971)",
    "4.0.0 (build 5970)",
    "3.8.8g (build 5779.3)",
    "3.8.8f (build 5779.2)",
    "3.8.8e (build 5779.1)",
    "3.8.8d (build 5779)",
    "3.8.8c (build 5778)",
    "3.8.8b (build 5777)",
    "3.8.8a (build 5776)",
    "3.8.8 (build 5775)"
)
statusDisplayNumber = 0
lastLaunchTime = 732109943.002655
showConnectedDurations = 1
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = Dziak135
keyboardShortcutIndex = 1
updateCheckAutomatically = 1
NSWindow Frame SettingsSheetWindow = 621 274 829 542 0 0 2048 1257
NSWindow Frame ConnectingWindow = 4413 744 389 211 2048 -160 5120 1417
NSWindow Frame SUUpdateAlert = 453 435 620 622 0 0 2048 1257
detailsWindowFrameVersion = 5970
detailsWindowFrame = {{654, 315}, {920, 548}}
detailsWindowLeftFrame = {{0, 0}, {167, 430}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = settings
leftNavSelectedDisplayName = Macaluso
AdvancedWindowTabIdentifier = connectingAndDisconnecting
haveDealtWithOldTunTapPreferences = 1
haveDealtWithAlwaysShowLoginWindow = 1
haveDealtWithOldLoginItem = 1
haveDealtWithAfterDisconnect = 1
SUEnableAutomaticChecks = 1
SUScheduledCheckInterval = 86400
SULastCheckTime = 2024-03-14 11:52:23 +0000
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 16
WebKitStandardFont = Times

================================================================================

Forced preferences:

{
    allowNonAdminSafeConfigurationReplacement = 1;
}

================================================================================

Deployed forced preferences:

(None)

================================================================================

Tunnelblick Kext Policy Data:



================================================================================

Tunnelblick Log:

2024-03-14 07:59:26.910647 *Tunnelblick: macOS 10.15.7 (19H2026); Tunnelblick 4.0.1 (build 5971); prior version 3.8.8g (build 5779.3)
2024-03-14 07:59:27.202608 *Tunnelblick: Attempting connection with Macaluso using shadow copy; Set nameserver = 0x00000301; monitoring connection
2024-03-14 07:59:27.203169 *Tunnelblick: openvpnstart start Macaluso.tblk 62221 0x00000301 0 1 0 0x0010c130 -ptADGNWradsgnw 2.6.9-openssl-3.0.13 <password>
2024-03-14 07:59:27.221987 *Tunnelblick: openvpnstart starting OpenVPN
2024-03-14 07:59:27.590352 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2024-03-14 07:59:27.590724 OpenVPN 2.6.9 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [AEAD]
2024-03-14 07:59:27.590764 library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
2024-03-14 07:59:27.592304 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:62221
2024-03-14 07:59:27.592363 Need hold release from management interface, waiting...
2024-03-14 07:59:27.825515 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully.
     Command used to start OpenVPN (one argument per displayed line):
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.6.9-openssl-3.0.13/openvpn
          --daemon
          --log-append /Library/Application Support/Tunnelblick/Logs/-SUsers-Santhonyskeens-SLibrary-SApplication Support-STunnelblick-SConfigurations-SMacaluso.tblk-SContents-SResources-Sconfig.ovpn.769_0_1_0_1098032.62221.openvpn.log
          --cd /Library/Application Support/Tunnelblick/Users/anthonyskeens/Macaluso.tblk/Contents/Resources
          --machine-readable-output
          --setenv IV_GUI_VER "net.tunnelblick.tunnelblick 5971 4.0.1 (build 5971)"
          --verb 3
          --config /Library/Application Support/Tunnelblick/Users/anthonyskeens/Macaluso.tblk/Contents/Resources/config.ovpn
          --setenv TUNNELBLICK_CONFIG_FOLDER /Library/Application Support/Tunnelblick/Users/anthonyskeens/Macaluso.tblk/Contents/Resources
          --verb 3
          --cd /Library/Application Support/Tunnelblick/Users/anthonyskeens/Macaluso.tblk/Contents/Resources
          --management 127.0.0.1 62221 /Library/Application Support/Tunnelblick/Mips/Macaluso.tblk.mip
          --setenv IV_SSO webauth
          --management-query-passwords
          --management-hold
          --script-security 2
          --route-up /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
          --down /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
2024-03-14 07:59:27.840179 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:58027
2024-03-14 07:59:27.865179 MANAGEMENT: CMD 'pid'
2024-03-14 07:59:27.865226 MANAGEMENT: CMD 'auth-retry interact'
2024-03-14 07:59:27.865245 MANAGEMENT: CMD 'state on'
2024-03-14 07:59:27.865263 MANAGEMENT: CMD 'state'
2024-03-14 07:59:27.865296 MANAGEMENT: CMD 'bytecount 1'
2024-03-14 07:59:27.866638 *Tunnelblick: Established communication with OpenVPN
2024-03-14 07:59:27.867662 *Tunnelblick: >INFO:OpenVPN Management Interface Version 5 -- type 'help' for more info
2024-03-14 07:59:27.869289 MANAGEMENT: CMD 'hold release'
2024-03-14 07:59:27.869372 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2024-03-14 07:59:27.869386 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2024-03-14 07:59:27.871359 OpenSSL: error:0A00018E:SSL routines::ca md too weak:
2024-03-14 07:59:27.871405 MANAGEMENT: Client disconnected
2024-03-14 07:59:27.871415 Cannot load inline certificate file
2024-03-14 07:59:27.871423 Exiting due to fatal error
2024-03-14 07:59:29.226632 *Tunnelblick: Expected disconnection occurred.

================================================================================

Installer log:

Tunnelblick installer started 2024-03-14 07:52:21.076816; getuid() = 501; geteuid() = 0; getgid() = 20; getegid() = 20
currentDirectoryPath = '/'; 1 arguments:
     0x0101
Determined username 'anthonyskeens' from getuid(): 501
renamex_np() test #2 failed for /Applications
Replaced /Library/LaunchDaemons/net.tunnelblick.tunnelblick.tunnelblickd.plist
Used launchctl to load tunnelblickd
Tunnelblick installer succeeded

================================================================================

Down log:

08:48:40 *Tunnelblick:  **********************************************
08:48:40 *Tunnelblick:  Start of output from client.down.tunnelblick.sh
08:48:40 *Tunnelblick:  Cancelled monitoring system configuration changes
08:48:40 *Tunnelblick:  Restored State:DNS
08:48:40 *Tunnelblick:  Removed Setup:DNS
08:48:40 *Tunnelblick:  Removed State:SMB
08:48:40 *Tunnelblick:  Restored DNS and SMB settings
08:48:40 *Tunnelblick:  Re-enabled IPv6 (automatic) for "USB 10/100/1000 LAN 3"
08:48:40 *Tunnelblick:  Flushed the DNS cache with dscacheutil -flushcache
08:48:40 *Tunnelblick:  Notified mDNSResponder that the DNS cache was flushed
08:48:40 *Tunnelblick:  End of output from client.down.tunnelblick.sh
08:48:40 *Tunnelblick:  **********************************************

================================================================================

Previous down log:

17:15:11 *Tunnelblick:  **********************************************
17:15:11 *Tunnelblick:  Start of output from client.down.tunnelblick.sh
17:15:11 *Tunnelblick:  Cancelled monitoring system configuration changes
17:15:11 *Tunnelblick:  Restored State:DNS
17:15:11 *Tunnelblick:  Removed Setup:DNS
17:15:11 *Tunnelblick:  Removed State:SMB
17:15:11 *Tunnelblick:  Restored DNS and SMB settings
17:15:11 *Tunnelblick:  Re-enabled IPv6 (automatic) for "USB 10/100/1000 LAN 3"
17:15:11 *Tunnelblick:  Flushed the DNS cache with dscacheutil -flushcache
17:15:11 *Tunnelblick:  Notified mDNSResponder that the DNS cache was flushed
17:15:11 *Tunnelblick:  End of output from client.down.tunnelblick.sh
17:15:11 *Tunnelblick:  **********************************************

================================================================================

Network services:

An asterisk (*) denotes that a network service is disabled.
Wi-Fi
USB 10/100/1000 LAN
Belkin USB-C LAN
USB 10/100/1000 LAN 2
Millson Patch Panel LAN 3
VPN Testing Router LAN 4
USB 10/100/1000 LAN 3
Thunderbolt Bridge
Bluetooth PAN

Wi-Fi Power (en0): On

================================================================================

ifconfig output:

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
inet 127.0.0.1 netmask 0xff000000
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
nd6 options=201<PERFORMNUD,DAD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
en5: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
ether ac:de:48:00:11:22
inet6 fe80::aede:48ff:fe00:1122%en5 prefixlen 64 scopeid 0x4
nd6 options=201<PERFORMNUD,DAD>
media: autoselect (100baseTX <full-duplex>)
status: active
ap1: flags=8802<BROADCAST,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 36:7d:da:9a:c7:7a
media: autoselect
status: inactive
en0: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 14:7d:da:9a:c7:7a
inet 192.168.1.106 netmask 0xffffff00 broadcast 192.168.1.255
media: autoselect
status: active
p2p0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 2304
options=400<CHANNEL_IO>
ether 06:7d:da:9a:c7:7a
media: autoselect
status: inactive
awdl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1484
options=400<CHANNEL_IO>
ether 16:e6:4c:db:16:ce
inet6 fe80::14e6:4cff:fedb:16ce%awdl0 prefixlen 64 scopeid 0x8
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
llw0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 16:e6:4c:db:16:ce
inet6 fe80::14e6:4cff:fedb:16ce%llw0 prefixlen 64 scopeid 0x9
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
en1: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 82:09:6c:a8:b0:01
media: autoselect <full-duplex>
status: inactive
en2: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 82:09:6c:a8:b0:00
media: autoselect <full-duplex>
status: inactive
en3: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 82:09:6c:a8:b0:05
media: autoselect <full-duplex>
status: inactive
en4: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 82:09:6c:a8:b0:04
media: autoselect <full-duplex>
status: inactive
bridge0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=63<RXCSUM,TXCSUM,TSO4,TSO6>
ether 82:09:6c:a8:b0:01
Configuration:
id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0
maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200
root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0
ipfilter disabled flags 0x0
member: en1 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 10 priority 0 path cost 0
member: en2 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 11 priority 0 path cost 0
member: en3 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 12 priority 0 path cost 0
member: en4 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 13 priority 0 path cost 0
media: <unknown type>
status: inactive
utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::2686:9ccc:f3da:612c%utun0 prefixlen 64 scopeid 0xf
nd6 options=201<PERFORMNUD,DAD>
utun1: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 2000
inet6 fe80::fddf:cf29:5e3a:bebc%utun1 prefixlen 64 scopeid 0x10
nd6 options=201<PERFORMNUD,DAD>
utun2: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::4ce6:d5d5:e66d:da2a%utun2 prefixlen 64 scopeid 0x15
nd6 options=201<PERFORMNUD,DAD>
utun3: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::748f:5dd6:982d:e4af%utun3 prefixlen 64 scopeid 0x16
nd6 options=201<PERFORMNUD,DAD>
utun4: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::d056:3caf:e8df:50f2%utun4 prefixlen 64 scopeid 0x17
nd6 options=201<PERFORMNUD,DAD>
utun5: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::8846:690:50fb:ca5a%utun5 prefixlen 64 scopeid 0x18
nd6 options=201<PERFORMNUD,DAD>
en12: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=6407<RXCSUM,TXCSUM,VLAN_MTU,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
ether 00:e0:4c:68:00:c4
inet 172.16.0.100 netmask 0xffffff00 broadcast 172.16.0.255
media: autoselect (1000baseT <full-duplex>)
status: active
en11: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=6407<RXCSUM,TXCSUM,VLAN_MTU,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
ether 00:e0:4c:68:15:84
media: autoselect (none)
status: inactive
vnic0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=3<RXCSUM,TXCSUM>
ether 00:1c:42:00:00:08
inet 10.211.55.2 netmask 0xffffff00 broadcast 10.211.55.255
media: autoselect
status: active
vnic1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=3<RXCSUM,TXCSUM>
ether 00:1c:42:00:00:09
inet 10.37.129.2 netmask 0xffffff00 broadcast 10.37.129.255
media: autoselect
status: active

================================================================================

Non-Apple kexts that are loaded:

Index Refs Address            Size       Wired      Name (Version) UUID <Linked Against>
  219    1 0xffffff7f876cd000 0x2f000    0x2f000    com.parallels.kext.hypervisor (18.3.2 53621) 8CCF305F-04C6-3B21-89B5-7D9446412DB6 <8 6 5 3 1>
  220    1 0xffffff7f843a3000 0x8000     0x8000     com.parallels.kext.vnic (18.3.2 53621) E812A28F-9C39-3D92-85C2-63A125D5AB38 <6 5 3 1>
  221    0 0xffffff7f8468e000 0xe000     0xe000     com.parallels.kext.netbridge (18.3.2 53621) 3C20030F-226B-306A-9353-E704E05BF574 <220 219 6 5 3 1>

================================================================================

Quit Log:

2024-03-14 07:52:00.275256 cleanup: Entering cleanup
2024-03-14 07:52:00.277645 synchronized user defaults
2024-03-14 07:52:01.311953 applicationShouldTerminate: termination for unknown reason, probably Command-Q; delayed until 'shutdownTunnelblick' finishes)
2024-03-14 07:52:01.316567 shutDownTunnelblick: started.
2024-03-14 07:52:01.316810 shutDownTunnelblick: Starting cleanup.
2024-03-14 07:52:01.317009 cleanup: Entering cleanup
2024-03-14 07:52:01.317196 shutDownTunnelblick: Cleanup already being done.
2024-03-14 07:52:01.317404 Finished shutting down Tunnelblick; allowing termination

================================================================================

Traces Log:


================================================================================

Console Log:


 

Tunnelblick developer

unread,
Mar 14, 2024, 8:27:35 AM3/14/24
to tunnelblick-discuss
Thanks for providing the Diagnostic Info.

Your VPN setup uses weak (unsafe) encryption. Please see Tunnelblick 4.


Anthony Skeens

unread,
Mar 14, 2024, 8:48:46 AM3/14/24
to tunnelblick-discuss
Thank you.  Using version 2.6.9 - OpenSSL v1.1.1w worked.

Thanks again

Tunnelblick developer

unread,
Mar 14, 2024, 9:17:21 AM3/14/24
to tunnelblick-discuss
It's important that you also notify whoever provides your VPN service that they need to update their setup, as it says in Tunnelblick 4.
Reply all
Reply to author
Forward
0 new messages