Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenSSL: error:0201502D:system library:ioctl:Operation

    Scheduled Pinned Locked Moved 21.02.2/2.5.1 Snapshots (Retired)
    7 Posts 3 Posters 936 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mloiterman
      last edited by

      I just updated to 2.5.1.r.20210405.0300

      Now my OpenVPN client won't connect and I see this error:

      Apr  5 11:29:09 pfsense openvpn[66140]: Using peer cipher 'AES-256-CBC'
      Apr  5 11:29:09 pfsense openvpn[66140]: OpenSSL: error:0201502D:system library:ioctl:Operation not supported
      Apr  5 11:29:09 pfsense openvpn[66140]: EVP cipher init #2
      Apr  5 11:29:09 pfsense openvpn[66140]: Exiting due to fatal erro
      
      K 1 Reply Last reply Reply Quote 1
      • K
        kossie @mloiterman
        last edited by

        @mloiterman

        Same issue here, I ended up having to move back to 2.5.0 to get things working normally.

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          Was there any other error after that in the logs? Or was that the end of it?

          Does it still happen on today's snapshot?

          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by jimp

            I found a VM here where I can reproduce that. It appears to be tied to having AES-NI+cryptodev enabled. If you disable that, it should run. It works with AES-NI alone loaded, but not cryptodev.

            https://redmine.pfsense.org/issues/11785

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            M 1 Reply Last reply Reply Quote 1
            • M
              mloiterman @jimp
              last edited by

              @jimp

              That was the full error.

              I haven't tried today's snap shot, but it definitely started in 2.5.1.r.20210405.0300, but I didn't see the error in 2.5.1.r.20210326.0300

              I have tried disabling hardware crypto, but that did not resolve it.

              I have NOT yet tried disabling hardware crypto and AES yet, but I will try later today.

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                This is OK for me now on the latest snapshot. Update and give it a try and confirm if it's also working for you.

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                M 1 Reply Last reply Reply Quote 0
                • M
                  mloiterman @jimp
                  last edited by

                  @jimp

                  Yup. I just updated to the latest snapshot and it's been fixed.

                  Jim, you're awesome. Thanks so much.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.