Re: [Openvpn-users] Request for feedback: Unbundling easy-rsa on Windows

2024-02-19 Thread michael
Easy-RSA in the build process which needs to be run unter Windows because of the product. Best regards, Michael Fritscher ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] OpenVPN tunnel reconnection on multihomed device?

2021-10-17 Thread Michael Kress
gt; Will OVPN try to find another interface that has internet connection > in order to re-establish the tunnel or is all lost? OpenVPN will not search anything, it simplyl send its packets. If or how they get transported to the server depends on the routing setu

Re: [Openvpn-users] [ext] Re: Openvpn 2.4.8 on Windows 10: TAP32 Adapter seems to be fubared

2020-03-30 Thread michael
Am 2020-03-30 17:14, schrieb Ralf Hildebrandt: Did that just now, along with some screenshots. Which were scrubed from the mailinglist software it seems... Best regards, Michael Fritscher ___ Openvpn-users mailing list Openvpn-users

Re: [Openvpn-users] High hpet_read overhead

2019-05-26 Thread Michael Fritscher
On 16.05.19 12:17, Jan Just Keijser wrote: > Hi, > > On 14/05/19 18:50, Michael Fritscher wrote: >> On 14.05.19 17:45, Jan Just Keijser wrote: >>> Hi, >>> >>> On 14/05/19 13:47, mich...@fritscher.net wrote: >>>> Am 2019-05-14 09:37, sc

Re: [Openvpn-users] High hpet_read overhead

2019-05-14 Thread Michael Fritscher
On 14.05.19 17:45, Jan Just Keijser wrote: > Hi, > > On 14/05/19 13:47, mich...@fritscher.net wrote: >> Am 2019-05-14 09:37, schrieb mich...@fritscher.net: >>> Am 2019-05-13 23:51, schrieb Michael Fritscher: >>>> On 13.05.19 17:05, Gert Doering wrote: >>&

Re: [Openvpn-users] High hpet_read overhead

2019-05-14 Thread michael
Am 2019-05-14 09:37, schrieb mich...@fritscher.net: Am 2019-05-13 23:51, schrieb Michael Fritscher: On 13.05.19 17:05, Gert Doering wrote: Hi, On Mon, May 13, 2019 at 04:20:41PM +0200, mich...@fritscher.net wrote: I experienced a high system cpu usage of OpenVPN in qemu on Windows. Both

Re: [Openvpn-users] High hpet_read overhead

2019-05-14 Thread michael
Am 2019-05-13 23:51, schrieb Michael Fritscher: On 13.05.19 17:05, Gert Doering wrote: Hi, On Mon, May 13, 2019 at 04:20:41PM +0200, mich...@fritscher.net wrote: I experienced a high system cpu usage of OpenVPN in qemu on Windows. Both with hax and whpx (kvm-like accelerators). Apparently, it

Re: [Openvpn-users] High hpet_read overhead

2019-05-13 Thread Michael Fritscher
e shaper functionality of OpenVPN, and verb is set to 3. But we are indeed using tc-htb... Btw, on VMWare I don't see this calls albeit using exactly the same image. I've uploaded the data of the perf run on https://mifritscher.de/austausch/op

Re: [Openvpn-users] High hpet_read overhead

2019-05-13 Thread michael
Could be a bad time jitter or something cause the problem? Best regards, Michael Fritscher ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

[Openvpn-users] High hpet_read overhead

2019-05-13 Thread michael
Good day, I experienced a high system cpu usage of OpenVPN in qemu on Windows. Both with hax and whpx (kvm-like accelerators). Apparently, it does make calls to hpet_read (or acpi_pm_read if hpet is disabled) with 1 kHz. This makes a overhead ov over 85% regarding the "perf" program. Is that n

Re: [Openvpn-users] Usage of OpenVPN without TUN/TAP? (SOCKS, localhost, plain stdin/out)

2019-05-13 Thread michael
Am 2019-05-07 22:17, schrieb David Sommerseth: On 06/05/2019 19:39, Michael Fritscher wrote: [...snip...] My usecase is to use the whole "backend" of OpenVPN (crypto, authentification, key management, control/data channel management, adaptive compression etc.) for a set of

Re: [Openvpn-users] Usage of OpenVPN without TUN/TAP? (SOCKS, localhost, plain stdin/out)

2019-05-06 Thread Michael Fritscher
On 06.05.19 16:57, Jan Just Keijser wrote: > Hi Michael, > > On 06/05/19 15:18, mich...@fritscher.net wrote: >> Hello, >> >> is there a way to use OpenVPN without a TUN/TAP device? E.g. by having >> a SOCKS server, accept & forward connections to localhost - o

[Openvpn-users] Usage of OpenVPN without TUN/TAP? (SOCKS, localhost, plain stdin/out)

2019-05-06 Thread michael
PX). Best regards, Michael Fritscher ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

[Openvpn-users] Openvpn on android = no download of apps

2018-11-02 Thread Michael Funke
Grüßen | best regards Michael Funke ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] Help testing OpenVPN 2.4-alpha1 preview installers?

2016-10-13 Thread Muenz, Michael
W10 within Virtualbox also worked fine. - Michael -- Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot __

[Openvpn-users] Restart if ping fails?

2016-08-25 Thread Michael Munger
n the tinc service itself. Unless, of course, there is a config setting that does restores connectivity in just such a situation... Michael Munger, dCAP, MCPS, MCNPS, MBSS High Powered Help, Inc. Microsoft Certified Professional Microsoft Certified Small Business Specialist Digium Certified Ast

Re: [Openvpn-users] username-as-common-name not setting username as common_name for plugin

2016-08-04 Thread Michael Hicks
..@gmail.com>> wrote: > On Thu, Aug 4, 2016 at 11:50 AM, Michael Hicks <mailto:michaelhick...@gmail.com>> wrote: > I guess I’ll submit a documentation bug to alter the description in the docs > for "username-as-common-name” to more clearly illustrate this. Maybe jus

Re: [Openvpn-users] username-as-common-name not setting username as common_name for plugin

2016-08-04 Thread Michael Hicks
use username instead of common_name and it works as I expect. I’ll also submit a pull request against the duo_openvpn plugin source to get that changed upstream and see where it goes. Thanks for the reply, Mike > On Aug 3, 2016, at 10:05 PM, Selva Nair wrote: > > > On W

[Openvpn-users] username-as-common-name not setting username as common_name for plugin

2016-08-03 Thread Michael Hicks
Greetings OpenVPN users, I’m having some trouble with openvpn using an auth plugin for DuoSecurity MFA. https://github.com/duosecurity/duo_openvpn server side OpenVPN 2.3.6 x86_64-sun-solaris2.11 [SSL (OpenSSL)] [LZO] [IPv6] built on Dec 5 2015 library versions: OpenSSL 1.0.2e 3 Dec 2015, LZO 2

Re: [Openvpn-users] Bridging config - can't find an understandable HOWTO

2015-02-26 Thread Michael O Holstein
26/2015 8:18 AM, Michael O Holstein wrote: >> I'm looking for encryption that's completely transparent to programs, will >> work properly across multiple servers with IP multicast > > Then what you want is IPSEC. > > OpenVPN has it's advantages, but SSL vpn is d

Re: [Openvpn-users] Bridging config - can't find an understandable HOWTO

2015-02-26 Thread Michael O Holstein
l-vpn-technologies I'm not saying you *can't* do a site-to-site with OVPN since you most certainly can, just like you can use IPSEC for road-warriors .. but at least try to use the proper tool for the job unless there are technical res

Re: [Openvpn-users] "redirect-gateway def1 bypass-dhcp" / Options error: in --iroute: Bad network/subnet specification

2015-01-05 Thread michael
>> Hi, >> >> On 29/12/14 13:25, Erich Titl wrote: >>> Hi MIchael >>> >>> Am 29.12.2014 um 12:05 schrieb mich...@haleyweb.com: >>>> root@interconit:~# tcpdump -i tun0 >>>> tcpdump: verbose output suppressed, use -v or -vv for fu

[Openvpn-users] "redirect-gateway def1 bypass-dhcp" / Options error: in --iroute: Bad network/subnet specification

2014-11-25 Thread michael
Thank you OpenVPN forum for reviewing this opportunity to get my OpenVPN configuration setup correctly. I've been able to connect OK between my OpenVPN client running on Windows 8 to my OpenVPN server 2.3.2 on Ubuntu 14.04.1 LTS. However, I'm unable to configure the setting "redirect-gateway def1

[Openvpn-users] "redirect-gateway def1 bypass-dhcp" / Options error: in --iroute: Bad network/subnet specification

2014-11-25 Thread michael
-- Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server from Actuate! Instantly Supercharge Your Business Reports and Dashboards with Interactivity, Sharing, Native Excel Exports, App Integration & more Get

[Openvpn-users] "redirect-gateway def1 bypass-dhcp" / Options error: in --iroute: Bad network/subnet specification

2014-11-25 Thread michael
-- Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server from Actuate! Instantly Supercharge Your Business Reports and Dashboards with Interactivity, Sharing, Native Excel Exports, App Integration & more Get

Re: [Openvpn-users] OpenVPN in China

2014-10-24 Thread Michael Deynet
n attempts. And: Since I was back from China there were no further connection attempts... Michael - Ursprüngliche Nachricht - Von: "Jason Haar" Gesendet: ‎24.‎10.‎2014 01:51 An: "openvpn-users@lists.sourceforge.net" Betreff: Re: [Openvpn-users] OpenVPN in China On 2

[Openvpn-users] OpenVPN in China

2014-10-23 Thread Michael Deynet
once). Can anyone tell me what exactly happend? Is there a security problem with the VPN server? Regards Michael Part of log file: Sun Oct 12 13:09:33 2014 MULTI: multi_create_instance called Sun Oct 12 13:09:33 2014 116.6.xx.y:52188 Re-using SSL/TLS context Sun Oct 12 13:09:33 2014 116.6.xx.y:

Re: [Openvpn-users] From Windows 7 client to OpenVPN server

2014-09-03 Thread Michael O Holstein
Yes, you need the OpenVPN client, just like you do in Linux. The "built in" one in Windows can use SSTP, L2TP+IPSEC, or PPTP .. OpenVPN uses a (different) proprietary protocol. Regards, Michael Holstein Cleveland State University From: Timo

Re: [Openvpn-users] TLS key negotiation failed to occur within 60 seconds

2014-04-01 Thread Michael Post
time to > that, if later, leave it alone. Precisely for such cases, with > embedded systems with no hardware clock, and possibly unreachable > ntp servers for whatever reason...) That`s sounds for me as a good workaround. Thanks for the hint. Michael -BEGIN PGP SIGNATURE

Re: [Openvpn-users] TLS key negotiation failed to occur within 60 seconds

2014-04-01 Thread Michael Post
All our clients have a installed ntp client. My prob was, that the ntp client does not sync with the internet. Otherwise i does not have this prob. ;-) Thanks a lot, Michael -BEGIN PGP SIGNATURE- Version: GnuPG/MacGPG2 v2.0.22 (Darwin) Comment: GPGTools - http://gpgtools.org Comment:

Re: [Openvpn-users] TLS key negotiation failed to occur within 60 seconds

2014-04-01 Thread Michael Post
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hello David, Am 01.04.14 14:41, schrieb David Sommerseth: > On 01/04/14 08:30, Michael Post wrote: >> The failure was a misadjusted time. The clients has the time >> 1970, but the certificate is valid beginning

Re: [Openvpn-users] TLS key negotiation failed to occur within 60 seconds

2014-03-31 Thread Michael Post
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hello, thanks for your reply. Am 01.04.14 00:56, schrieb Jan Just Keijser: > Hi Michael, > > in 99% of the cases this error is caused by a switch of firewall > that is blocking access; cheap switches are notoriously bad at >

[Openvpn-users] TLS key negotiation failed to occur within 60 seconds

2014-03-30 Thread Michael Post
occur within 60 seconds (check your network connectivity) Sun Mar 30 10:51:58 2014 us=24309 80.187.100.154:20163 TLS Error: TLS handshake failed Does anyone has an idea to solve this problem? Preferred without changing anything on client-side. Thanks a lot for your help, Michael -BEGIN PGP

Re: [Openvpn-users] Extend SSL Certification Problem

2014-03-09 Thread Michael Post
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hello Gert, thanks for your hints and support. Resetting the server date works interestingly. So i do not have to drive through germany and find all clients *puhh!! Thanks a lot. Have a nice night at munich. Michael Am 09.03.14 18:37

Re: [Openvpn-users] Extend SSL Certification Problem

2014-03-09 Thread Michael Post
. Any clue? Thanks a lot, Michael Am 09.03.14 15:11, schrieb Gert Doering: > Hi, > > On Sun, Mar 09, 2014 at 02:39:03PM +0100, Michael Post wrote: >> Is there any possibility to extend the certificates, keys and so >> on server-side WITHOUT any change at client-side? >

[Openvpn-users] Extend SSL Certification Problem

2014-03-09 Thread Michael Post
s are also invalid due the same lack of my scripts. The clients are not accessable per remote maintenance cause they are umts clients with non static ip. Is there any possibility to extend the certificates, keys and so on server-side WITHOUT any change at client-side? Thanks for every hint, Michael

[Openvpn-users] Extend SSL Certificate

2014-03-09 Thread Michael Post
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hello, last year i created my keys, certs and so on with the following steps: openssl req -new -x509 -newkey rsa:2048 -keyout ssl_priv.pem -out ca_cert.pem -days 3650 -config ./openssl.conf openssl x509 -in ca_cert.pem -out ca_cert.crt openssl ge

Re: [Openvpn-users] OpenVPN with auth-user-pass disconnects after 1hr

2013-10-13 Thread Michael Ludvig
On 13/10/13 21:23, Davide Brini wrote: > On Sun, 13 Oct 2013 16:17:00 +1300, Michael Ludvig > wrote: > >> I want it stay connected and don't drop in the first place. >> Reauthenticating every hour is not an option. > Then don't use "auth-nocache", I

Re: [Openvpn-users] OpenVPN with auth-user-pass disconnects after 1hr

2013-10-12 Thread Michael Ludvig
On 13/10/13 16:17, Michael Ludvig wrote: > I don't want it stay connected and don't drop in the first place. I _want_ it stay connected, of course ;) M. -- October Webinars: Code for Performance Free Intel

Re: [Openvpn-users] OpenVPN with auth-user-pass disconnects after 1hr

2013-10-12 Thread Michael Ludvig
On 13/10/13 06:03, Davide Brini wrote: > On Wed, 09 Oct 2013 00:26:45 +1300, Michael Ludvig > wrote: > >> Tue Oct 8 23:08:40 2013 Initialization Sequence Completed >> Wed Oct 9 00:08:38 2013 TLS: soft reset sec=0 bytes=38258/0 pkts=718/0 >> Enter Auth Username:^C &

Re: [Openvpn-users] OpenVPN with auth-user-pass disconnects after 1hr

2013-10-11 Thread Michael Ludvig
On 10/10/13 22:34, Jan Just Keijser wrote: > Hi, > > Michael Ludvig wrote: >> Hi >> >> we use OpenVPN 2.3.2 without client certificate and with >> auth-user-pass instead. What we observe is that the connection always >> drops pretty much exactly after 1 hou

[Openvpn-users] OpenVPN with auth-user-pass disconnects after 1hr

2013-10-08 Thread Michael Ludvig
none" directives. But for the test OTP is not needed, this connection drop after 1 hour happens just as well with system username and password. Any idea why is it happening? Especially with OTP it's very annoying. Thanks! Michael

Re: [Openvpn-users] OTP re-auth solution?

2013-09-10 Thread Michael Ludvig
On 11/09/13 13:17, Jason Haar wrote: > On 11/09/13 12:34, Michael Ludvig wrote: >> We used to do cert-based authentication which was good because on >> connection drop it re-authenticated without any user interaction and >> often users didn't even notice. Now

[Openvpn-users] OTP config settings

2013-09-10 Thread Michael Ludvig
illed manually, but also 2) if it could recover without re-requesting OTP give it enough time to do so. My current cient config has: ping-exit 60 auth-nocache auth-retry none The server config has: keepalive 10 60 But I'm sure there are other parameters to tweak...? Thanks

[Openvpn-users] OTP re-auth solution?

2013-09-10 Thread Michael Ludvig
k if the client IP is still the same use it to re-authenticate without calling to PAM and OTP and all that? That would significantly improve the user experience while keeping the connection secured with OTP. What do you think? Michael ---