On Tue, Dec 20, 2016 at 10:31 PM, Sumit Dahiya <[email protected]>
wrote:

> Tue Dec 20 22:14:45 2016 XX.XX.XX.XX:PPPP TLS: Initial packet from
> [AF_INET]XX.XX.XX.XX:PPPP, sid=afa2ff27 76db1e46
>
> Tue Dec 20 22:15:45 2016 XX.XX.XX.XX:PPPP TLS Error: TLS key negotiation
> failed to occur within 60 seconds (check your network connectivity)
>
> Tue Dec 20 22:15:45 2016 XX.XX.XX.XX:PPPP TLS Error: TLS handshake failed
>
> Tue Dec 20 22:15:45 2016 XX.XX.XX.XX:PPPP SIGUSR1[soft,tls-error]
> received, client-instance restarting
>


So the server gets the initial packet, sends the certificate to client
which it verifies. But the server gets no client certificate. I've no idea
why that happens..

As for client taking 20+ seconds from first packet to cert-verify, hard to
say without seeing the full transaction. Take a look at the logs at verb=6
level to see time and size of each udp packet read and written to the
socket on both sides.

Selva
------------------------------------------------------------------------------
Developer Access Program for Intel Xeon Phi Processors
Access to Intel Xeon Phi processor-based developer platforms.
With one year of Intel Parallel Studio XE.
Training and support from Colfax.
Order your platform today.http://sdm.link/intel
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to