Closed GoogleCodeExporter closed 9 years ago
That really sounds as if your certificate is not in PEM format.
Original comment by arne@rfc2549.org
on 26 Jul 2014 at 8:40
Honestly, I'm not sure what I'm doing for the most part. Just following the
tutorial
http://openvpn.net/index.php/open-source/documentation/howto.html#pki
For the client key I'm using, I did build-key-pass and I do remember having to
enter a PEM pass phrase.
Original comment by unknowns...@gmail.com
on 26 Jul 2014 at 11:35
Can you send me your generated config?
Original comment by arne@rfc2549.org
on 26 Jul 2014 at 11:47
Config on the phone or the server? Where do I find the file, or what type of
file am I looking for?
Original comment by unknowns...@gmail.com
on 26 Jul 2014 at 11:55
When editing a vpn profile there should be a generated config menu item
Original comment by arne@rfc2549.org
on 26 Jul 2014 at 12:10
# Enables connection to GUI
management /data/data/de.blinkt.openvpn/cache/mgmtsocket unix
management-client
management-query-passwords
management-hold
setenv IV_GUI_VER "de.blinkt.openvpn 0.6.17"
machine-readable-output
client
verb 4
connect-retry-max 5
connect-retry 5
resolv-retry 60
dev tun
remote <address removed> b 1194 udp
<ca>
-----BEGIN CERTIFICATE-----
MIIExDCCA6ygAwIBAgIJAPxE0XrFS2iwMA0GCSqGSIb3DQEBBQUAMIGcMQswCQYD
VQQGEwJVUzELMAkGA1UECBMCSUwxDzANBgNVBAcTBkpvbGlldDEQMA4GA1UEChMH
T3BlblZQTjERMA8GA1UECxMIY2hhbmdlbWUxDTALBgNVBAMTBEhvbWUxETAPBgNV
BCkTCGNoYW5nZW1lMSgwJgYJKoZIhvcNAQkBFhl1bmtub3duc29sZGllcnhAZ21h
aWwuY29tMB4XDTE0MDcyNTE3NDk0MFoXDTI0MDcyMjE3NDk0MFowgZwxCzAJBgNV
BAYTAlVTMQswCQYDVQQIEwJJTDEPMA0GA1UEBxMGSm9saWV0MRAwDgYDVQQKEwdP
cGVuVlBOMREwDwYDVQQLEwhjaGFuZ2VtZTENMAsGA1UEAxMESG9tZTERMA8GA1UE
KRMIY2hhbmdlbWUxKDAmBgkqhkiG9w0BCQEWGXVua25vd25zb2xkaWVyeEBnbWFp
bC5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDE/ZNxFATq8dMN
UsrN4JU5c2IrsHep2r4nAeBchiSmvUcGi4aqOYTOkzcZ9hdRaP570H5SF7+Oec7D
pMERT6p6QVDNAaUvqxQvqi8c188H0w6Ec6wIym/N7e7Mjn8u7A7NQuAyxHE1zRP9
Hx74W5J+Pwtiz7YxExZ9BpAjyoC47GEFdVLchK1x40lK8hvRF+Nx/vL08g/xcmHt
36vTx/m7v0VpGqKv6qoZoNgugb90A8j0Yc7W9evoshH5aH0dLAspsxZtO1yIQVqo
cUSAyDtgGnK5H1REq36cgvxhju1BQLlp+Yfa2M+HWA137oPcwAks2TqYWkI+ZeE5
oJmpMpbzAgMBAAGjggEFMIIBATAdBgNVHQ4EFgQUjllztnm0xDxYakQIzHogv6Qd
LcgwgdEGA1UdIwSByTCBxoAUjllztnm0xDxYakQIzHogv6QdLcihgaKkgZ8wgZwx
CzAJBgNVBAYTAlVTMQswCQYDVQQIEwJJTDEPMA0GA1UEBxMGSm9saWV0MRAwDgYD
VQQKEwdPcGVuVlBOMREwDwYDVQQLEwhjaGFuZ2VtZTENMAsGA1UEAxMESG9tZTER
MA8GA1UEKRMIY2hhbmdlbWUxKDAmBgkqhkiG9w0BCQEWGXVua25vd25zb2xkaWVy
eEBnbWFpbC5jb22CCQD8RNF6xUtosDAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEB
BQUAA4IBAQCqSumJmZ+82Uwv4jrLFUYHwkJlxybe5MTaBf9Zy9uRKSpvsCGqfh8D
OYoMbYu2stjIwdM2XZbo7lWEqsOKjJSnPBrRsZh+vDWfi3lh4l92A52FWkrVraW3
R/klZINPtcRskdzmm+h5BC7Wh6rSzewLUpr5VgRsgxqI2PaRgE5dCuGqoJnwuFPW
+IDZiN6ddGcQv/Bo9wL8Tx0MVt5P08O3kbpIRx9GE1VfMNb/OKhBX4swPnEJmaFV
7gD1xE3qjdSjDSPOO7rHqYdxdxWaIo4rbaul7Hdak3g0LAd60+lv9xWy1h8woyl3
EnXUponpFGodcgqTUni/hx4uNwTLr2jK
-----END CERTIFICATE-----
</ca>
<key>
-----BEGIN ENCRYPTED PRIVATE KEY-----
MIIFDjBABgkqhkiG9w0BBQ0wMzAbBgkqhkiG9w0BBQwwDgQI/6TAb405uiMCAggA
MBQGCCqGSIb3DQMHBAhcH8kGScFsUgSCBMh66ridyktsiuDM8p6ygMDgmL07tWAB
aVpMoPlzLRERSedxEe8xUxji7zSl+FpyyRRiJJhb95fIUnoHrihgvC7rgLR19kP0
4WUZtB6RM5IL4kBUOdus1WJ0WeVhSj8kT0oFeZGPMIrJkPugmReQ+LtXCdyR5m6A
Y1NioW5bRK8M5y6VHeDXmXi5Mc9oUiqoH5HuUWlv7pGTIEAL/aVdLk7sU5/Va3ae
IHE5TJwmonhqQbGdmVU/uc4gtSjhaZ71Wwx5crNHQgkXiHa0qxporKzWKaFiXTY4
50RBbapD0d7T+VRAvsfJ7SLYeD9H+0OZYF6rAbqTh57pBgpOqF5SkAsz5JOiVPBd
0X3F+Hoi0f5wOrMvfXeyHXodEOMnHlkUfCwSAKDpHcYxlbzyqmdh2AAjzdlRZ0Fs
K5D9devrEtrcUIs1wt/vo/sjl/jNndpVxxiyDZnix6BPV61qGT2r4LQwR8AEoozL
3H0EG4GWtsnj4tmPBo4jyG1TF2ihL2ydf8VhnIB6aUK3SFrcsNdRQ0RSJTkUyjO0
mDdJIbe9jmIT7m4mODf+gMVxkXqdTqVvVJFBX9jeE0u7jbqMiC28v2i2aGlJFg5M
TEFHs9NZHuFFdcwWv6NxcSpcPlDBKdnq7RmbYVluDq3k0793STbBAGy6lypa/GE0
qrpDOpb/VP8Iat7cozJJo/OWp8mN1AOxHGwCMkx4fYOaLQCOJ4QSNL4+5OhXTCm6
neiNbT4gGkgE/iG0GHfavGzcpLGUFakpoMPCLZJ96BW6YrYUr/0x7GaNrUWa4j0Z
ldU8q+ZOVUhueKoCVWNdfU6ciYIDcf4M/I2ZL7c5YjxJ8N3PoT54ua/jb2ur/vgv
uno1qHAaQcbT6K1qRlX20YNCGZYnZYm/BUqFkMWAVWZeNCHv12hYoXFTgYZR4JaD
YiXum3Zm5a/RZO1YjKhtMjNuxRMvl1QUGHMtBlZKbBnYXBLGXlcCFwnJyt3Ty636
3TKasG1zSSrLrPPFpXwBx4BbCPRWIhLJnOdHVzq7kfTjGhYUSh9kggNdLUW7W1Ui
i8F3FKYuOqbEVABJIXEcViamvE/rSKzrxRWh//Gv6WineVmi58j+uQgHCfFHkstv
v3SgXlkSPV/6zbpOw2gYuTWSNCzKiKS+2aPHyLkNknkiHIXp9FzK6CJruBMtj2IM
G1H3rIC1GBOUfy6TIHY6oJ+4vqysfGglWyoYRGrzW8DsbYVGChLsEzdEA9czeR4X
SLL4+JKqL6l2YY09+Nem1lZs1Sc8QT0pKTsYYUFWxJwR3BGTZ/6gfyFsAlMA0jfM
rR4k5B1q9K1ZYA+V6kj8PGXknrohS67i0WGCs/I48vh/8e0YZw6jx7qihNa02eZN
ObDDC9sPoPE6vUewfB5tlU88u0jrZP9DXwPqui+s9cICjzpT3GkjHGXIgfqj03c9
mwwWIZ33bZeH+XzY3pHz7OSlrePQWZCa7W6q7ioQ7mGNbAgNyrLmGVq8V3r3AxwT
4JFafLvuJlgNkl1+WC7un56vOLUHtQw/MV2K1etkKmqR68sjZX6RSTlA7LgfD+p7
o4hVFtJtM7bqVRoTuol2FLV3N+WppfKmRq2CNbvJiY/wjydTTPyuHMbdmncZO27a
R+Q=
-----END ENCRYPTED PRIVATE KEY-----
</key>
<cert>
-----BEGIN CERTIFICATE REQUEST-----
MIIC+zCCAeMCAQAwgZ0xCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJJTDEPMA0GA1UE
BxMGSm9saWV0MRAwDgYDVQQKEwdPcGVuVlBOMREwDwYDVQQLEwhjaGFuZ2VtZTEO
MAwGA1UEAxMFUGhvbmUxETAPBgNVBCkTCGNoYW5nZW1lMSgwJgYJKoZIhvcNAQkB
Fhl1bmtub3duc29sZGllcnhAZ21haWwuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOC
AQ8AMIIBCgKCAQEAqLY2+Z8rW6CjbZIup4vqCmAV7Sg9+aOi9VGN148ZdzbZn1cK
Q+E+MuZDIPjrbAHgWkvUWZY/O9lhoqzJnC89cIKryx7wG2p7TVXIaDnsOw794Bre
D530lqvthoviO/Od1OAGhy3iZBR3mwmNhF+oBE1oi8UAEifu/ibRRzwxmPehqHyk
W+ZMoR5AWxlZ1tQKrjmivn+QWqv8PC2GD5H0P1dASui6qYJzSJ2WLnHgOCwJZR80
d7QcT3ItqmF1oCgUORYNyAvX+dDYJooVM1Vlr+PN9tFkh5gz9ZVDJ4RhdjgF/cxB
QRRAKeaQ4tiO8NgoFNvIa3d6IlqtSzUh9tEdWwIDAQABoBgwFgYJKoZIhvcNAQkH
MQkTBzdwMXQwejIwDQYJKoZIhvcNAQEFBQADggEBAFUszdxSEyfUY6M+d2AoZYq5
h5zxN+3htVYMO2Z8JvgDvT0kT5u07NSbxlAhQmpKmBSnNIZeC3iY6Dh1cmCEiMGr
NPio8/BMiS25JXdyXIi3IpYZ5pJR7EjiQ4aaycgPFg0ykOZbsGaxzuMbJCCQm1XW
0CmLXqftKhkVhQ8CnpnOE+MpuD1LHZlEPANQQ5MENgMeqov0kMMZ0VEsz0j2mFjm
YXl+rl+zwVRmFnnoPutvLqQOnXNudrKuQ4o02NJ00SkLoVGBd/ce2J43bc0WeTUm
44uI6QmtpbmRhMpY7Wef7FSnsIDJH0lMdTS+LAMLQlq5e/whxZdBiS19Bd6hwnY=
-----END CERTIFICATE REQUEST-----
</cert>
comp-lzo
redirect-private block-local
route-ipv6 ::/0
route 0.0.0.0 0.0.0.0 vpn_gateway
remote-cert-tls server
# Use system proxy setting
management-query-proxy
Original comment by unknowns...@gmail.com
on 26 Jul 2014 at 12:36
Redid all my certs. I think I may have entered a challenge password for my
client cert, but not for my server cert. I started from scratch and made sure
not to enter any challenge passwords. Just a PEM password for the phone
credentials.
Now it seems to attempt to connect, but it sits at "waiting for server reply",
and the log shows "TLS key negotiation failed to occur within 60 seconds".
Original comment by unknowns...@gmail.com
on 31 Jul 2014 at 9:30
Attachments:
Closing this since it was probably broken certficates
Original comment by arne@rfc2549.org
on 22 Sep 2014 at 9:17
Original issue reported on code.google.com by
unknowns...@gmail.com
on 25 Jul 2014 at 11:44