Клиенты не подключаются к OpenVPN на микротике.
Не подключаются клиенты (linux) к OpenVPN серверу на микротике.
Сертификаты для сервера и клиентов созданы? Сертификат сервера в микротык импортирован? Клиентские сертификаты клиентам розданы? ca.crt и серверу, и клиентам роздан?
Да. Все сертификаты на местах.
А кроме этого ворнинга какая-нибудь еще ругань есть? Микротык в log print что-нибудь говорит?
Если я все правильно понимаю, то клиенту недоступен либо чем-то не нравится ca.crt.
понять бы, чем не нравится..
Может все-таки конфиги покажем?
Микротик настраивался по статье на хабре.
1. Про серверный мы видимо должны догадаться.
2. смотрите что у вас в /etc/openvpn/ca.crt и сравните с серверным
3. Микротик настраивался по статье на хабре. — про которую мы видимо тоже должны догадаться.
ЗЫ Даты на клиенте и сервере все-таки тоже проверьте.
Буквально на днях цеплял еще одного клиента к рабочему ovpn’у. Один момент — клиент на windows. Была точно такая же ошибка, хотя конфиг и все остальное было взято с рабочего клиента. Вопрос решился установкой другой версии openvpn. Скачивал с сайта текущий 2.3.11 — с ним не шло. Поставил 2.3.10 — сразу все подключилось. Что-то они там с SSL в клиенте сделали.
Клиентский конфиг и примеры рабочих корневого и клиентского сертификатов можете скинуть?
Вообще они немного разные, но как минимум ns-cert-type server пробовали раскоментировать?
Клиентский конфиг и примеры рабочих корневого и клиентского сертификатов можете скинуть?
И ключи от квартиры где деньги лежат?
да. результат тот же.
Посмотрите от кого запускается openvpn может ему /etc/openvpn/ca.crt не доступен.
Я и имел ввиду сгенерировать новые, но с теми же параметрами (nsCertType, keyUsage,keyCertSign, authorityKeyIdentifier, и.т.д) как у рабочих.
запускал и от рута и от обычного пользователя.
btw не нулевая вероятность. Сам не сталкивался, но читал про такое.
Хотя больше предполагаю, что проблема была как обычно в самом конфиге (устаревшие/изменившие поведение/добавленные параметры). Вы лог клиента не пробовали читать?
Возможно в самом openvpn (мы же только догадываемся) захаркоден конкретный юзвер:группа, например openvpn:openvpn.
Вообще микротик насколько я слышал, та еще пакость во многих частях. Попробуйте все-таки полностью хотя по одной из инструкций сделать (они реально разные) а у вас если смотреть наискосок вроде как помесь уже.
Как уже выше писал dexpl проблема явно в одном:
Fri Jun 10 21:46:52 2016 TLS_ERROR: BIO read tls_read_plaintext error: error:14094418:SSL routines:SSL3_READ_BYTES:tlsv1 alert unknown ca: error:140940E5:SSL routines:SSL3_READ_BYTES:ssl handshake failure
Что вы сделали не так, честно говоря я хз. Сливаюсь. Может знатоки микротика подтянуться, не нулевая вероятность что вы совсем не ca.crt выложили или не в том формате.
У меня эта проблема вылезла, после того как обновился openvpn-клиент в федоре. Теперь не могу к серверам на микротиках подключаться. А вот к старому серверу на линуксе вполне ок. Буду разбираться.
unixforum.org
РЕШЕНО:OpenVPN crl-verify crl.pem (WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more in)
Модератор: SLEDopit
РЕШЕНО:OpenVPN crl-verify crl.pem
OS-OpenSuse 42.3
OpenVPN-2.3
easyrsa- 3.0.5
Создал тестовый OpenVPN и столкнулся со следующим:
Интерфейс tun подымается
Логи клиента при попытке подключиться к серверу:
Как только я комментирую на сервере строку отвечающую за проверку сертификатов:
#crl-verify crl.pem
Клиент подключается и работает как положено.
Лог клиента после удачного подключения:
Дата и время сервер/клиент не расходятся, полность удалял тестовую среду генерил заново.
Ошибка повторяется.
OpenVPN Support Forum
No server certificate verification method has been enabled.
No server certificate verification method has been enabled.
Post by LonelyPixel » Thu May 31, 2018 9:07 am
When connecting to my OpenVPN server, I get this message on the client in red colour:
WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
I have read that page and acknowledged it. The certificates already have the appropriate settings. How can I make this red line go away?
Re: No server certificate verification method has been enabled.
Post by TinCanTech » Thu May 31, 2018 11:27 am
The HOWTO wrote: Now add the following line to your client configuration:
remote-cert-tls server
Re: No server certificate verification method has been enabled.
Post by LonelyPixel » Thu May 31, 2018 12:53 pm
Re: No server certificate verification method has been enabled.
Post by TinCanTech » Thu May 31, 2018 1:15 pm
Would you prefer there not to be documentation ?
People put a lot of effort into writing it .. but we can delete it all if you prefer
Re: No server certificate verification method has been enabled.
Post by LonelyPixel » Thu May 31, 2018 5:19 pm
If there is no documentation, I’d be annoyed about it not being there. If there’s a documentation that’s hard to find, use and understand, I’d be annoyed about it being hard to find, use and understand. Please understand that incomplete efforts cannot beat psychology. You can’t sell a product by arguing that you couldn’t do it any better. I’m just giving you feedback on that, other’s won’t and turn somewhere else. I guess you still don’t care because we’re all not paying any money.
And yes, deleting the outdated part of the documentation might indeed be helpful! It just doesn’t look too professional if I turn to the forums about a documentation page from a prominent FAQ list only to hear that it’s long outdated. You see where my impression comes from?
WARNING: No server certificate verification method has been enabled. #453
Mon Sep 13 09:10:53 2021 OpenVPN 2.4.8 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Oct 31 2019
Mon Sep 13 09:10:53 2021 Windows version 6.2 (Windows 8 or greater) 64bit
Mon Sep 13 09:10:53 2021 library versions: OpenSSL 1.1.0l 10 Sep 2019, LZO 2.10
Mon Sep 13 09:10:55 2021 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Does anybody know how to handle this warning?
The text was updated successfully, but these errors were encountered:
Add remote-cert-tls server to your client config. That will ensure that the server must present a certificate meant to be used on a server and a client doesn’t impersonate as the server.
@selvanair please excuse my ignorance — how do you add that line to the client config — don’t even know where it is or how to find it and google is not helping — all these linux solutions are so techincially vague they need solutions themselves — is there a real laymans way of doing this step by step — almost like i’m a baby
«Add remote-cert-tls server to your client config» = do something — I need to know the how to do something.
would you be able to assist. pls pls.
@selvanair please excuse my ignorance — how do you add that line to the client config — don’t even know where it is or how to find it and google is not helping — all these linux solutions are so techincially vague they need solutions themselves — is there a real laymans way of doing this step by step — almost like i’m a baby
«Add remote-cert-tls server to your client config» = do something — I need to know the how to do something.
If you do not know what that means, point your server administrator to this thread so that they can provide a fixed configuration.