Attention is currently required from: MaxF, syzzer.

plaisthos has posted comments on this change by MaxF. ( 
http://gerrit.openvpn.net/c/openvpn/+/1441?usp=email )

Change subject: Add support for Mbed TLS 4
......................................................................


Patch Set 5: Code-Review-1

(1 comment)

Patchset:

PS5:
There is something wrong with connecting to an OpenSSL based OpeNVPN, e.g. 
against community VPN:

sudo ./src/openvpn/openvpn --config ~/ovpn/confs/community.ovpn    
--script-security 2

Password:
2026-01-21 15:21:34 DEPRECATED OPTION: --persist-key option ignored. Keys are 
now always persisted across restarts.
2026-01-21 15:21:34 OpenVPN 2.7_rc5 [git:review/mbedtls4/2cc00e80bca26c1c+*] 
aarch64-apple-darwin25.2.0 [SSL (mbed TLS)] [LZO] [LZ4] [MH/RECVDA] [AEAD] 
built on Jan 21 2026
2026-01-21 15:21:34 library versions: mbed TLS 4.0.0, LZO 2.10
2026-01-21 15:21:34 TCP/UDP: Preserving recently used remote address: 
[AF_INET]3.69.106.84:1194
2026-01-21 15:21:34 Socket Buffers: R=[786896->786896] S=[9216->9216]
2026-01-21 15:21:34 UDPv4 link local: (not bound)
2026-01-21 15:21:34 UDPv4 link remote: [AF_INET]3.69.106.84:1194
2026-01-21 15:21:34 TLS: Initial packet from [AF_INET]3.69.106.84:1194, 
sid=709f8846 9d2eb04d
2026-01-21 15:21:34 VERIFY OK: depth=1, C=US, ST=CA, L=Pleasanton, 
O=openvpn.net, OU=My Organizational Unit, CN=ChangeMe, 
[email protected]
2026-01-21 15:21:34 Validating certificate key usage
2026-01-21 15:21:34 VERIFY KU OK
2026-01-21 15:21:34 Validating certificate extended key usage
2026-01-21 15:21:34 ++ Certificate has EKU (str) TLS Web Server Authentication, 
expects TLS Web Server Authentication
2026-01-21 15:21:34 NOTE: --mute triggered...
2026-01-21 15:21:34 2 variation(s) on previous 20 message(s) suppressed by 
--mute
2026-01-21 15:21:34 TLS_ERROR: read tls_read_plaintext error: SSL - * Received 
NewSessionTicket Post Handshake Message. This error code is experimental and 
may be changed or removed without notice
2026-01-21 15:21:34 TLS Error: TLS object -> incoming plaintext read error
2026-01-21 15:21:34 TLS Error: TLS handshake failed



--
To view, visit http://gerrit.openvpn.net/c/openvpn/+/1441?usp=email
To unsubscribe, or for help writing mail filters, visit 
http://gerrit.openvpn.net/settings?usp=email

Gerrit-MessageType: comment
Gerrit-Project: openvpn
Gerrit-Branch: master
Gerrit-Change-Id: Ib251d546d993b96ed3bd8cb9111bcc627cdb0fae
Gerrit-Change-Number: 1441
Gerrit-PatchSet: 5
Gerrit-Owner: MaxF <[email protected]>
Gerrit-Reviewer: flichtenheld <[email protected]>
Gerrit-Reviewer: plaisthos <[email protected]>
Gerrit-CC: openvpn-devel <[email protected]>
Gerrit-CC: syzzer <[email protected]>
Gerrit-Attention: syzzer <[email protected]>
Gerrit-Attention: MaxF <[email protected]>
Gerrit-Comment-Date: Wed, 21 Jan 2026 14:22:32 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: Yes
_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

Reply via email to