Hi,
I have included client as well as server logs below. It seems the Windows
client clock is few seconds off compared to Debian server clock so you may
find minor variation in timestamps between these logs.
Client Log follows: -
Tue Dec 20 22:14:43 2016 OpenVPN 2.3.2 x86_64-w64-mingw32 [SSL (OpenSSL)]
[LZO] [PKCS11] [eurephia] [IPv6] built on Aug 22 2013
Enter Management Password:
Tue Dec 20 22:14:43 2016 MANAGEMENT: TCP Socket listening on
[AF_INET]127.0.0.1:XXXXX
Tue Dec 20 22:14:43 2016 Need hold release from management interface,
waiting...
Tue Dec 20 22:14:44 2016 MANAGEMENT: Client connected from
[AF_INET]127.0.0.1:XXXXX
Tue Dec 20 22:14:44 2016 MANAGEMENT: CMD 'state on'
Tue Dec 20 22:14:44 2016 MANAGEMENT: CMD 'log all on'
Tue Dec 20 22:14:44 2016 MANAGEMENT: CMD 'hold off'
Tue Dec 20 22:14:44 2016 MANAGEMENT: CMD 'hold release'
Tue Dec 20 22:14:44 2016 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Dec 20 22:14:44 2016 MANAGEMENT: >STATE:ZZZZZZZZZZZ,RESOLVE,,,
Tue Dec 20 22:14:44 2016 UDPv4 link local: [undef]
Tue Dec 20 22:14:44 2016 UDPv4 link remote: [AF_INET]XX.XX.XX.XX:YYYY
Tue Dec 20 22:14:44 2016 MANAGEMENT: >STATE:ZZZZZZZZZZZ,WAIT,,,
Tue Dec 20 22:14:44 2016 MANAGEMENT: >STATE:ZZZZZZZZZZZ,AUTH,,,
Tue Dec 20 22:14:44 2016 TLS: Initial packet from
[AF_INET]XX.XX.XX.XX:YYYY, sid=7d3f096c 370b18f7
Tue Dec 20 22:15:06 2016 VERIFY OK: depth=1, C=US, ST=AA, L=BB, O=Personal
Inc, OU=Personal, CN=personal, name=Personal Server,
[email protected]
Tue Dec 20 22:15:06 2016 VERIFY OK: nsCertType=SERVER
Tue Dec 20 22:15:06 2016 VERIFY OK: depth=0, C=US, ST=AA, L=BB, O=Personal
Inc, OU=Personal, CN=server, name=Personal Server,
[email protected]
Tue Dec 20 22:15:44 2016 TLS Error: TLS key negotiation failed to occur
within 60 seconds (check your network connectivity)
Tue Dec 20 22:15:44 2016 TLS Error: TLS handshake failed
Tue Dec 20 22:15:44 2016 SIGUSR1[soft,tls-error] received, process
restarting
Tue Dec 20 22:15:44 2016 MANAGEMENT:
>STATE:1482290144,RECONNECTING,tls-error,,
Tue Dec 20 22:15:44 2016 Restart pause, 2 second(s)
Tue Dec 20 22:15:46 2016 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Dec 20 22:15:46 2016 MANAGEMENT: >STATE:1482290146,RESOLVE,,,
Tue Dec 20 22:15:46 2016 UDPv4 link local: [undef]
Tue Dec 20 22:15:46 2016 UDPv4 link remote: [AF_INET]XX.XX.XX.XX:YYYY
Tue Dec 20 22:15:46 2016 MANAGEMENT: >STATE:1482290146,WAIT,,,
Tue Dec 20 22:15:46 2016 MANAGEMENT: >STATE:1482290146,AUTH,,,
Tue Dec 20 22:15:46 2016 TLS: Initial packet from
[AF_INET]XX.XX.XX.XX:YYYY, sid=14b64e55 20408461
Tue Dec 20 22:15:48 2016 SIGTERM[hard,] received, process exiting
Tue Dec 20 22:15:48 2016 MANAGEMENT: >STATE:1482290148,EXITING,SIGTERM,,
Server log corresponding to above session follows: -
Tue Dec 20 22:14:45 2016 MULTI: multi_create_instance called
Tue Dec 20 22:14:45 2016 XX.XX.XX.XX:PPPP Re-using SSL/TLS context
Tue Dec 20 22:14:45 2016 XX.XX.XX.XX:PPPP LZO compression initialized
Tue Dec 20 22:14:45 2016 XX.XX.XX.XX:PPPP Control Channel MTU parms [
XXXXXXXXXXXXXXXXXXXXXXXXXXXX ]
Tue Dec 20 22:14:45 2016 XX.XX.XX.XX:PPPP Data Channel MTU parms [
XXXXXXXXXXXXXXXXXXXXXXXXXXXX ]
Tue Dec 20 22:14:45 2016 XX.XX.XX.XX:PPPP Local Options hash (VER=V4):
'691e95c7'
Tue Dec 20 22:14:45 2016 XX.XX.XX.XX:PPPP Expected Remote Options hash
(VER=V4): '66096c33'
Tue Dec 20 22:14:45 2016 XX.XX.XX.XX:PPPP TLS: Initial packet from
[AF_INET]XX.XX.XX.XX:PPPP, sid=afa2ff27 76db1e46
Tue Dec 20 22:15:45 2016 XX.XX.XX.XX:PPPP TLS Error: TLS key negotiation
failed to occur within 60 seconds (check your network connectivity)
Tue Dec 20 22:15:45 2016 XX.XX.XX.XX:PPPP TLS Error: TLS handshake failed
Tue Dec 20 22:15:45 2016 XX.XX.XX.XX:PPPP SIGUSR1[soft,tls-error] received,
client-instance restarting
Tue Dec 20 22:15:46 2016 MULTI: multi_create_instance called
Tue Dec 20 22:15:46 2016 XX.XX.XX.XX:PPPP Re-using SSL/TLS context
Tue Dec 20 22:15:46 2016 XX.XX.XX.XX:PPPP LZO compression initialized
Tue Dec 20 22:15:46 2016 XX.XX.XX.XX:PPPP Control Channel MTU parms [
XXXXXXXXXXXXXXXXXXXXXXXXXXXX ]
Tue Dec 20 22:15:46 2016 XX.XX.XX.XX:PPPP Data Channel MTU parms [
XXXXXXXXXXXXXXXXXXXXXXXXXXXX ]
Tue Dec 20 22:15:46 2016 XX.XX.XX.XX:PPPP Local Options hash (VER=V4):
'691e95c7'
Tue Dec 20 22:15:46 2016 XX.XX.XX.XX:PPPP Expected Remote Options hash
(VER=V4): '66096c33'
Tue Dec 20 22:15:46 2016 XX.XX.XX.XX:PPPP TLS: Initial packet from
[AF_INET]XX.XX.XX.XX:PPPP, sid=c60aa604 8b16db1b
Tue Dec 20 22:16:46 2016 XX.XX.XX.XX:PPPP TLS Error: TLS key negotiation
failed to occur within 60 seconds (check your network connectivity)
Tue Dec 20 22:16:46 2016 XX.XX.XX.XX:PPPP TLS Error: TLS handshake failed
Tue Dec 20 22:16:46 2016 XX.XX.XX.XX:PPPP SIGUSR1[soft,tls-error] received,
client-instance restarting
*From:* Sumit Dahiya [mailto:[email protected]]
*Sent:* Tuesday, December 20, 2016 10:08 PM
*To:* 'Selva Nair'
*Cc:* 'openvpn users list ([email protected])'
*Subject:* RE: [Openvpn-users] TLS Key negotiation failed
Thank you for looking into it. I do not have server logs for that time
period but I can produce new logs right now and respond back both logs
shortly.
The 24 second delay means that server is slow or is my client slow?
*From:* Selva Nair [mailto:[email protected] <[email protected]>]
*Sent:* Tuesday, December 20, 2016 9:54 PM
*To:* Sumit Dahiya
*Cc:* openvpn users list ([email protected])
*Subject:* Re: [Openvpn-users] TLS Key negotiation failed
Hi,
On Tue, Dec 20, 2016 at 8:10 PM, Sumit Dahiya <[email protected]>
wrote:
Tue Dec 20 19:50:57 2016 TLS: Initial packet from
[AF_INET]XX.XX.XX.XX.XX:YYYY, sid=eabd11fd 751826f4
Tue Dec 20 19:51:21 2016 VERIFY OK: depth=1, C=US, ST=AA, L=BB, O=Personal
Inc, OU=Personal, CN=personal, name=Personal Server,
[email protected]
24 seconds between initial TSL packet and certificate verification? At that
rate it will indeed need more than 60 seconds for handshake. Why is it so
slow?
Tue Dec 20 19:51:21 2016 VERIFY OK: nsCertType=SERVER
Tue Dec 20 19:51:21 2016 VERIFY OK: depth=0, C=US, ST=AA, L=BB, O=Personal
Inc, OU=Personal, CN=server, name=Personal Server,
[email protected]
Tue Dec 20 19:51:56 2016 TLS Error: TLS key negotiation failed to occur
within 60
Do you have the server logs for the same time period?
Selva
------------------------------------------------------------------------------
Developer Access Program for Intel Xeon Phi Processors
Access to Intel Xeon Phi processor-based developer platforms.
With one year of Intel Parallel Studio XE.
Training and support from Colfax.
Order your platform today.http://sdm.link/intel
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users