• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfsense 2.6 OpenVPN TLS Handshake error

Scheduled Pinned Locked Moved OpenVPN
6 Posts 2 Posters 987 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mlaustin
    last edited by May 6, 2023, 1:23 AM

    Hi All,

    I'm getting the following errors when connecting to my OpenVPN Server on pfsense 2.6.

    May 5 20:12:54 openvpn 76531 166.199.3.50:56065 WARNING: Failed running command (--tls-verify script): external program exited with error status: 1
    May 5 20:12:54 openvpn 76531 166.199.3.50:56065 OpenSSL: error:1417C086:SSL routines:tls_process_client_certificate:certificate verify failed
    May 5 20:12:54 openvpn 76531 166.199.3.50:56065 TLS_ERROR: BIO read tls_read_plaintext error
    May 5 20:12:54 openvpn 76531 166.199.3.50:56065 TLS Error: TLS object -> incoming plaintext read error
    May 5 20:12:54 openvpn 76531 166.199.3.50:56065 TLS Error: TLS handshake failed

    OpenVPN was working a few months ago. I've added the CRL expiration patch. I've deleted and recreated all certs and servers multiple times. I've changed certificate depth to do not check. Nothing works.

    With cert depth set to do not check, OpenVPN Connect says user authentication failed. But the logs say the user was authenticated.

    OpenVPN Connect is the latest version on iOS. Seems like a lot of people have this problem. Any ideas on fixing this?

    J 1 Reply Last reply May 6, 2023, 1:11 PM Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @mlaustin
      last edited by May 6, 2023, 1:11 PM

      @mlaustin said in pfsense 2.6 OpenVPN TLS Handshake error:

      Seems like a lot of people have this problem. Any ideas on fixing this?

      How so?

      I use connect on my ios phone, I don't recall ever having any issues.. There might of been a time when version of ios connect didn't work with tls-crypt? That was long time ago though..

      What specific version are you running, I just looked and my connect on my iphone is 3.3.3

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      M 1 Reply Last reply May 6, 2023, 4:56 PM Reply Quote 0
      • M
        mlaustin @johnpoz
        last edited by May 6, 2023, 4:56 PM

        @johnpoz said in pfsense 2.6 OpenVPN TLS Handshake error:

        How so?

        My last statement made it sound like many people are having this issue on iOS. That is not what I meant. Searching the web brings up plenty of TLS issues with OpenVPN on the latest pfsense.

        My iOS client is 3.3.3 as well.

        1 Reply Last reply Reply Quote 0
        • M
          mlaustin
          last edited by May 6, 2023, 5:19 PM

          I found the fix for me in this thread

          https://forum.netgate.com/topic/171706/user-auth-failed/12

          I had to go into both files listed there using Diagnostics/ Edit File. Just copy the file path listed in the tread and add the 4 dots before OK as mentioned.

          J 1 Reply Last reply May 6, 2023, 5:26 PM Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator @mlaustin
            last edited by johnpoz May 6, 2023, 5:28 PM May 6, 2023, 5:26 PM

            @mlaustin said in pfsense 2.6 OpenVPN TLS Handshake error:

            https://forum.netgate.com/topic/171706/user-auth-failed/12

            This jumped out to me on why maybe its not wide spread

            "This suggests that the problem will only impact slower or heavily loaded systems."

            While I am not saying people are not running into this, or other things, etc. But I am here quite a bit, too much maybe ;) and I don't recall seeing widespread reports of this at all nor that many issues with opven at all.. Not saying not your typical update bumps where versions of everything change, php, openvpn and the freebsd base, etc..

            Glad you got it sorted.

            You also mention..

            "OpenVPN was working a few months ago" so maybe the load on your system has changed? And now your running into this - if it is in fact somehow related to how long it takes to come back, or load on the system, etc.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            M 1 Reply Last reply May 6, 2023, 5:34 PM Reply Quote 0
            • M
              mlaustin @johnpoz
              last edited by May 6, 2023, 5:34 PM

              @johnpoz

              It doesn't look like my load is that significant. It's been like this since this box has been running.
              947788aa-a1a3-4669-ab8b-c0d3ad215875-image.png

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received