Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN clients can`t connect

    Scheduled Pinned Locked Moved 2.3-RC Snapshot Feedback and Issues - ARCHIVED
    7 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      maverick_slo
      last edited by

      Hi!

      I dont know which snap borked it, but now none of my 30 vpn clients cant connect.

      Server logs show:

      Mar 15 18:19:46 	openvpn 	69413 	EXTERNALIP:36553 TLS Error: TLS handshake failed
      Mar 15 18:19:46 	openvpn 	69413 	EXTERNALIP:36553 TLS Error: TLS object -> incoming plaintext read error
      Mar 15 18:19:46 	openvpn 	69413 	EXTERNALIP:36553 TLS_ERROR: BIO read tls_read_plaintext error: error:140890B2:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned
      Mar 15 18:19:46 	openvpn 	69413 	EXTERNALIP:36553 WARNING: Failed running command (--tls-verify script): external program exited with error status: 1
      Mar 15 18:19:04 	openvpn 	69413 	EXTERNALIP:41915 TLS Error: TLS handshake failed
      Mar 15 18:19:04 	openvpn 	69413 	EXTERNALIP:41915 TLS Error: TLS object -> incoming plaintext read error
      Mar 15 18:19:04 	openvpn 	69413 	EXTERNALIP:41915 TLS_ERROR: BIO read tls_read_plaintext error: error:140890B2:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned 
      

      I havent changed absolutely anything. Any idea Im in real trouble here…

      Thanks!

      1 Reply Last reply Reply Quote 0
      • M
        maverick_slo
        last edited by

        Ummm clicked save on openvpn server, updated to latest snap, rebooted and all is fine again.
        What???

        1 Reply Last reply Reply Quote 0
        • M
          maverick_slo
          last edited by

          Rebooted and same thing with ssl.
          One connection was succesful others with same errors.

          How can I troubleshoot this?

          1 Reply Last reply Reply Quote 0
          • M
            maverick_slo
            last edited by

            I even created NEW CA, new openvpn server cert and new client cert and same results.

            1 Reply Last reply Reply Quote 0
            • M
              maverick_slo
              last edited by

              Hmmm found how to replicate.

              Wait for new snapshot (must include kernel too). Update and wait for box to reboot.
              Try to connect openvpn = no go

              Reboot the box again and we can connect.

              Huh?

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                Check your clock on each boot, see what it is doing.

                Also compare the contents of /var/etc/openvpn when it works vs when it doesn't.

                Given the other problems your system seems to have (like the package startup issue) it's possible some boot-time task is failing to work 100%.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • M
                  maverick_slo
                  last edited by

                  Hi Jimp, I will check it.

                  P.S.
                  This system has no other issues :)
                  Other 2 have startup issues.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.