[Eisfair_dev] openvpn2 1.0.6 testing für eisfair1 released

Olaf Jaehrling eisfair at ojaehrling.de
So Okt 29 18:07:51 CET 2017


Hallo Benjamin,

Benjamin Heide schrieb am 28.10.2017 um 12:41:
> Hi Ihr beiden,
> 

> siehe:
> 
> ...
> Sat Oct 28 12:37:12 2017 Validating certificate key usage
> Sat Oct 28 12:37:12 2017 ++ Certificate has key usage  00e0, expects 00a0
> Sat Oct 28 12:37:12 2017 ++ Certificate has key usage  00e0, expects 0088
> Sat Oct 28 12:37:12 2017 VERIFY KU ERROR
> Sat Oct 28 12:37:12 2017 OpenSSL: error:14090086:SSL
> routines:ssl3_get_server_certificate:certificate verify failed
> Sat Oct 28 12:37:12 2017 TLS_ERROR: BIO read tls_read_plaintext error
> Sat Oct 28 12:37:12 2017 TLS Error: TLS object -> incoming plaintext
> read error
> Sat Oct 28 12:37:12 2017 TLS Error: TLS handshake failed
> Sat Oct 28 12:37:12 2017 Fatal TLS error (check_tls_errors_co), restarting
> Sat Oct 28 12:37:12 2017 SIGUSR1[soft,tls-error] received, process
> restarting
> Sat Oct 28 12:37:12 2017 MANAGEMENT:
>> STATE:1509187032,RECONNECTING,tls-error,,
> Sat Oct 28 12:37:12 2017 Restart pause, 5 second(s)

Auf meine PM hast Du ja leider nicht reagiert. Also langwierig per NG.

"VERIFY KU ERROR" deutet auf ein Problem beim Hash hin.
Was sagt:
openssl x509 -in /usr/local/openvpn/keys/openvpn.crt -text | grep Algor
openssl x509 -in /usr/local/openvpn/keys/CLIENTZERTIFIKAT.crt -text |
grep Algor






Gruß

Olaf



Mehr Informationen über die Mailingliste Eisfair_dev