Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense 2.6 OpenVPN TLS Handshake error

    OpenVPN
    2
    6
    890
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mlaustin
      last edited by

      Hi All,

      I'm getting the following errors when connecting to my OpenVPN Server on pfsense 2.6.

      May 5 20:12:54 openvpn 76531 166.199.3.50:56065 WARNING: Failed running command (--tls-verify script): external program exited with error status: 1
      May 5 20:12:54 openvpn 76531 166.199.3.50:56065 OpenSSL: error:1417C086:SSL routines:tls_process_client_certificate:certificate verify failed
      May 5 20:12:54 openvpn 76531 166.199.3.50:56065 TLS_ERROR: BIO read tls_read_plaintext error
      May 5 20:12:54 openvpn 76531 166.199.3.50:56065 TLS Error: TLS object -> incoming plaintext read error
      May 5 20:12:54 openvpn 76531 166.199.3.50:56065 TLS Error: TLS handshake failed

      OpenVPN was working a few months ago. I've added the CRL expiration patch. I've deleted and recreated all certs and servers multiple times. I've changed certificate depth to do not check. Nothing works.

      With cert depth set to do not check, OpenVPN Connect says user authentication failed. But the logs say the user was authenticated.

      OpenVPN Connect is the latest version on iOS. Seems like a lot of people have this problem. Any ideas on fixing this?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @mlaustin
        last edited by

        @mlaustin said in pfsense 2.6 OpenVPN TLS Handshake error:

        Seems like a lot of people have this problem. Any ideas on fixing this?

        How so?

        I use connect on my ios phone, I don't recall ever having any issues.. There might of been a time when version of ios connect didn't work with tls-crypt? That was long time ago though..

        What specific version are you running, I just looked and my connect on my iphone is 3.3.3

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        M 1 Reply Last reply Reply Quote 0
        • M
          mlaustin @johnpoz
          last edited by

          @johnpoz said in pfsense 2.6 OpenVPN TLS Handshake error:

          How so?

          My last statement made it sound like many people are having this issue on iOS. That is not what I meant. Searching the web brings up plenty of TLS issues with OpenVPN on the latest pfsense.

          My iOS client is 3.3.3 as well.

          1 Reply Last reply Reply Quote 0
          • M
            mlaustin
            last edited by

            I found the fix for me in this thread

            https://forum.netgate.com/topic/171706/user-auth-failed/12

            I had to go into both files listed there using Diagnostics/ Edit File. Just copy the file path listed in the tread and add the 4 dots before OK as mentioned.

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @mlaustin
              last edited by johnpoz

              @mlaustin said in pfsense 2.6 OpenVPN TLS Handshake error:

              https://forum.netgate.com/topic/171706/user-auth-failed/12

              This jumped out to me on why maybe its not wide spread

              "This suggests that the problem will only impact slower or heavily loaded systems."

              While I am not saying people are not running into this, or other things, etc. But I am here quite a bit, too much maybe ;) and I don't recall seeing widespread reports of this at all nor that many issues with opven at all.. Not saying not your typical update bumps where versions of everything change, php, openvpn and the freebsd base, etc..

              Glad you got it sorted.

              You also mention..

              "OpenVPN was working a few months ago" so maybe the load on your system has changed? And now your running into this - if it is in fact somehow related to how long it takes to come back, or load on the system, etc.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              M 1 Reply Last reply Reply Quote 0
              • M
                mlaustin @johnpoz
                last edited by

                @johnpoz

                It doesn't look like my load is that significant. It's been like this since this box has been running.
                947788aa-a1a3-4669-ab8b-c0d3ad215875-image.png

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.