[Openvpn-users] Issue with single user, implicit ncp-ciphers connections

2017-06-30 Thread openvpn
Hello list, I've come across an issue with my OpenVPN setup with a single client. The single client is allowed to connect multiple times (duplicate-cn on the server side). The server's cipher is configured to AES-256-CBC (cipher AES-256-CBC) and an no ncp-ciphers, so the default of A

Re: [Openvpn-users] Issue with single user, implicit ncp-ciphers connections

2017-07-02 Thread openvpn
this specific case I ca not use --nobind. The client(s) will be updated any day now, but I need to keep --ncp-disable and varying --cipher's as that's a requirement for me. > > > gert > > -- > USENET is *not* the non-clickable part of WWW! >

Re: [Openvpn-users] Issue with single user, implicit ncp-ciphers connections

2017-07-03 Thread openvpn
gt; > g...@net.informatik.tu-muenchen.de-- Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

[Openvpn-users] OpenVPN with mbedTLS default TLS cipher suite list

2017-07-27 Thread openvpn
Hello, I've never used OpenVPN with an alternative to OpenSSL. I've set up OpenVPN with mbedTLS, which is officially supported by OpenVPN and everything appears to be working just fine. The OpenVPN manual states for --tls-cipher:     [...]     The default for --tls-cipher is to use

Re: [Openvpn-users] OpenVPN with mbedTLS default TLS cipher suite list

2017-07-27 Thread openvpn
to > lowest. > > Regards > /Magnus > > On 27.07.2017 14:07, > open...@keemail.me> wrote: >> Hello, >> >> I've never used OpenVPN with an alternative to OpenSSL. I've set up OpenVPN >> with mbedTLS, which is officially supported by OpenVPN

Re: [Openvpn-users] OpenVPN with mbedTLS default TLS cipher suite list (Steffan Karger)

2017-07-31 Thread openvpn
tech sites, Slashdot.org! http://sdm.link/slashdot_______ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

[Openvpn-users] OpenVPN security rating tool

2017-08-15 Thread openvpn
Hello, I've developed a Python script to grade OpenVPN server configurations considering the security. The tool mainly focuses on: auth, cipher, tls-cipher, prng, tls-auth, tls-version-min/max, no-replay, no-iv, key-method, ncp-ciphers, ncp-disable, tls-crypt and key-direction. The resu

Re: [Openvpn-users] OpenVPN security rating tool

2017-08-16 Thread openvpn
> Hello, > > On 16/08/17 14:21, > open...@keemail.me> wrote: >> Hello, >> >> I've developed a Python script to grade OpenVPN server configurations >> considering the security. >> The tool mainly focuses on: auth, cipher, tls-cipher, prng, tls-auth,

Re: [Openvpn-users] OpenVPN security rating tool

2017-08-16 Thread openvpn
blic beta and I can send you a link, to test it, this week. Thank you for the testing and possibly the feedback in advance! 16. Aug 2017 08:43 by chipits...@gmail.com: > > > 2017-08-16 11:21 GMT+05:00 <> open...@keemail.me> >: > >> >> Hello, >

Re: [Openvpn-users] Openvpn-users Digest, Vol 135, Issue 18

2017-08-17 Thread openvpn
That is a very good idea and could help prevent some misinterpretations of the tools results. Thank you very much! 17. Aug 2017 14:05 by openvpn-users-requ...@lists.sourceforge.net: > Send Openvpn-users mailing list submissions to > > openvpn-users@lists.sourceforge.net > &g

[Openvpn-users] Duplicate IP on multiple connections

2018-01-11 Thread openvpn
If I start two OpenVPN connections (with different local ports and tunnel devices) on the client with the same client configuration, the connection is established correctly, but both interfaces are assigned the same IP address. Why does the OpenVPN server not assign a new IP to the second

[Openvpn-users] OpenVPN security advisories mailing list?

2020-09-17 Thread openvpn
Hi I was wondering if there is a mailing list to get notifications about any security advisories for OpenVPN? I know there is a web page https://openvpn.net/security-advisories but we were hoping to subscribe to a mailing list for security advisories. Regards Megan

[Openvpn-users] services on vpn server and client

2022-01-28 Thread openvpn
Hi folks :-) I've my office lan with one server (1) linux lamp 192.168.1.100 and wan interface (static IP) for internet, and another server (2) (internal lan 192.168.1.50) with openvpn server from my home lan (another side) I can ping server 2 in office lan and vice-versa, openvpn

[Openvpn-users] After upgrade Windows 10 client to OpenVPN 2.6, Yubikey PKCS11 PIV fails on server with error 0A00007B:SSL routines::bad

2023-03-09 Thread openvpn
Hi, I'm posting the follow question here as I was redirect to this mailing list for support by OpenVPN forum. https://forums.openvpn.net/viewtopic.php?p=110748&hilit=error+0A7B#p110748 This is a complex issue, and I am unsure whether this is an OpenVPN/OpenSSL/OpenSC issue o

Re: [Openvpn-users] After upgrade Windows 10 client to OpenVPN 2.6, Yubikey PKCS11 PIV fails on server with error 0A00007B:SSL routines::bad

2023-03-10 Thread openvpn
Hi Selva, wow, thanks a lot for your very quick reply, I’m willingly testing the new GHA build and let you know the result as soon as possible. Thank you, Tom Von: Selva Nair Gesendet: Freitag, 10. März 2023 14:43 An: openvpn Cc: openvpn-users@lists.sourceforge.net Betreff: Re: [Openvpn

Re: [Openvpn-users] After upgrade Windows 10 client to OpenVPN 2.6, Yubikey PKCS11 PIV fails on server with error 0A00007B:SSL routines::bad

2023-03-10 Thread openvpn
Hi Selva, thank you so much, for given information and the provided new build, those works like a charm! Thank you, Tom Von: Selva Nair Gesendet: Freitag, 10. März 2023 15:42 An: openvpn Cc: openvpn-users@lists.sourceforge.net Betreff: Re: [Openvpn-users] After upgrade Windows 10 client to

[Openvpn-users] Packet flow and ICMP/MTU question

2017-06-13 Thread Pippin1st via Openvpn-users
first question is, how close am I? I can send the DIA file to the list in case someone has time/is willing to adjust. Second question is, can OpenVPN related (P?)MTU(D?) be broken by one or both iptables rules on eth+ or tun+? -A FORWARD -p icmp -j DROP -A INPUT -p icmp -j DROP Synology NAS does the

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-13 Thread Pippin1st via Openvpn-users
tated, his firewall/router does this for him, >> whether he likes it or not; Exactly, though i do not DROP ICMP myself, i know it`s a bad idea, it depends on type...etc. I asked this question because i`m trying to help a fellow Synology NAS owner. >> however, OpenVPN itself does not n

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-13 Thread Pippin1st via Openvpn-users
> in your diagram, on the sending side, packets cross the > routing/iptables block twice before getting to OpenVPN: > 1) once while going from the app to the tun0 interface > 2) once while going from tun0 to OpenVPN > What you are saying above is correct and it is about point 1)

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-14 Thread Pippin1st via Openvpn-users
Hello, > Same I said would apply to packets coming in: when going from > OpenVPN to tun0 they would not be subject to routing/iptables. > Basically the idea is that OpenVPN and the tun0 interface are > directly attached, so I/O between the two is direct. Ok, modified attache

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-14 Thread Pippin1st via Openvpn-users
Hello, > for client-to-server traffic this looks correct ; > client-to-client traffic is another matter. Yes, that i knew, --client-to-client is internal to OpenVPN. I found this out when i was testing throughput in a client to client setup on pfSense some time ago and then findi

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-14 Thread Pippin1st via Openvpn-users
Hello, > When thinking about firewalls (and routing, for that matter), imagine > OpenVPN as a black box sitting on a "second network card" connected > to the linux machine. > So there's iptables on the tun interface connecting "linux networking" > a

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-16 Thread Pippin1st via Openvpn-users
one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-16 Thread Pippin1st via Openvpn-users
ould someone add OpenVPN`s internal routing, please share. Thanks, Pippin ovpn-flow05.dia Description: application/dia -- Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org

[Openvpn-users] Packet flow, take 2

2017-06-22 Thread Pippin1st via Openvpn-users
paring TCP performance of tunneled and non-tunneled traffic using OpenVPN Authors: Berry Hoekstra bhoekstra@... Damir Musulin dmusulin@... Supervisor: Jan Just Keijser Nikhef August 24, 2011 Version 1.1 | Revision 191" Looking at the picture on page 7, example endpoint 1: Encrypt->Fragment

[Openvpn-users] Packet flow, take 2

2017-06-22 Thread Pippin1st via Openvpn-users
.link/slashdot___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

[Openvpn-users] openvpn client cannot access internet webpages but can access internal website

2017-10-13 Thread James via Openvpn-users
I am working for a company remotely. They set up a openVPN for me to access their SVN and Bugzilla (internal web site). They are working fine from my Windows 7 machine. But whenever I try to access internet web pages, I always got "DNS address could not be found ".   I have two virtua

[Openvpn-users] tcp-client: large ping during transfers (fwd)

2017-10-27 Thread Gof via Openvpn-users
Hi, I have a problem with OpenVPN and I hope you'll be able to help... I have two OpenVPN daemons on one Linux machine - one listening on TCP and one bound to the UDP port. They are using TAP devices that are bridged together, and TCP additionally shares port with ssh via "port-sh

Re: [Openvpn-users] tcp-client: large ping during transfers (fwd)

2017-11-08 Thread Gof via Openvpn-users
Really noone had such problems with VPNs over TCP before? On Fri, 27 Oct 2017, Gof via Openvpn-users wrote: > Hi, > > I have a problem with OpenVPN and I hope you'll be able to help... > > I have two OpenVPN daemons on one Linux machine - one listening on TCP and > on

Re: [Openvpn-users] tcp-client: large ping during transfers (fwd)

2017-11-09 Thread Gof via Openvpn-users
it definitely isn't only encryption/decryption latency... Gert: > With TCP, I expect queueing effects to add up as well - with UDP, > OpenVPN just throws out the packet, but with TCP, there are kernel > buffers involved, and if there's a packet getting lost, retransmits >

Re: [Openvpn-users] Speed / performance issues

2018-12-17 Thread pippin1st--- via Openvpn-users
Hi, Maybe it's a good idea to get an approx. system performance first for involved hosts. [code] openvpn --genkey --secret /tmp/secret time openvpn --test-crypto --secret /tmp/secret --verb 0 --tun-mtu 2 --cipher aes-256-gcm [/code] 3200 / execution_time_seconds ~ max. theoretical

Re: [Openvpn-users] VPN traffic stucks while "auth-user-pass-verify"-script is executed

2019-02-04 Thread pippin1st--- via Openvpn-users
Hi, See here also: https://engineering.freeagent.com/2017/05/22/external-authentication-scripts-in-openvpn-the-right-way/ Pippin Sent with [ProtonMail](https://protonmail.com) Secure Email. ‐‐‐ Original Message ‐‐‐ On Sunday 3 February 2019 18:39, Jonathan Keuser wrote: > He

Re: [Openvpn-users] OpenVPN 2.4.7 released

2019-02-22 Thread tapID via Openvpn-users
Friday, February 22, 2019 4:18:09 PM Thank You. Cheers, (::)tap Sent from my BlackBerry - the most secure mobile device - via the SENTINEL Network   Original Message   From: sam...@openvpn.net Sent: February 21, 2019 5:05 PM To: openvpn-users@lists.sourceforge.net; openvpn-de

Re: [Openvpn-users] cannot locate HMAC in incoming packet

2019-03-15 Thread pippin1st--- via Openvpn-users
right... > These are not my IPs, I guess it is just a result of unsuccessfully > connecting to my public available OpenVPN server which can be ignored. > Am I guessing correctly? > > Wed Feb 6 22:10:41 2019 TLS Error: cannot locate HMAC in incoming > packet from [AF_INET]185.200.118

[Openvpn-users] Fw: Re: Why is the authentication tag transmitted before the encrypted data?

2019-03-15 Thread pippin1st--- via Openvpn-users
in both directions. What this does is make > it possible for the OpenVPN protocol to easily recognize if packets are truly > VPN packets from a known VPN client, or if they are garbage packets from > unknown sources. Every OpenVPN packet by itself contains encrypted > information insi

Re: [Openvpn-users] Bandwidth usage

2019-04-04 Thread Pippin via Openvpn-users
Hi, Please see: https://github.com/OpenVPN/openvpn/blob/a6fd48ba36ede465b0905a95568c3ec0d425ca71/doc/management-notes.txt Sent with [ProtonMail](https://protonmail.com) Secure Email. ‐‐‐ Original Message ‐‐‐ On Thursday 4 April 2019 12:09, saidireddy ranabothu wrote: > Hi, >

Re: [Openvpn-users] No DNS variable pushed

2019-06-08 Thread Pippin via Openvpn-users
> Server is Linux, client is Linux. > > In server.conf, I have this (and more): > push "dhcp-option DNS 10.8.32.1" > > In client.conf, I have this (and more): > client > script-security 2 > up /etc/openvpn/update-resolv-conf > > When I put "printenv > /t

[Openvpn-users] Fw: Re: No DNS variable pushed

2019-06-08 Thread Pippin via Openvpn-users
Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Saturday 8 June 2019 20:39, Pippin wrote: > Hi, > > Can you post the server config, OpenVPN version and OS involved? > Probably better a dev looks at this as I never encountered/read about options > n

Re: [Openvpn-users] No DNS variable pushed

2019-06-08 Thread Pippin via Openvpn-users
we're just guessing. Please > > redact the server address, but post the rest. > > Doug > > Openvpn-users mailing list > > Openvpn-users@lists.sourceforge.net > > https://lists.sourceforge.net/lists/listinfo/openvpn-users __

[Openvpn-users] Fw: Re: OpenVPN-2.4.8 running on new hardware, but is it using the CPU based hardware crypto?

2019-11-07 Thread Pippin via Openvpn-users
Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Thursday 7 November 2019 20:45, Pippin wrote: Hi, To add some info, if want to know a ballpark figure regarding throughput one can do: $ openvpn --genkey --secret /tmp/secret $ time openvpn --test-crypto --secret /tmp

Re: [Openvpn-users] Communicating to OpenVPN

2019-11-11 Thread Pippin via Openvpn-users
via Openvpn-users wrote: > I previously believed that all IP network communication was done at layer 2 > via arp and transmitting to the MAC address of the system responding for it's > IP address. Then I realized that OpenVPN doesn't have MAC addresses, so how > does com

[Openvpn-users] Question regarding removal of broadcast address

2019-11-13 Thread Pippin via Openvpn-users
nks. Sent with [ProtonMail](https://protonmail.com) Secure Email._______ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] Question regarding removal of broadcast address

2019-11-13 Thread Pippin via Openvpn-users
e broadcast address on its own > instead of being us doing the math. Ok, making sense now. Thanks. _______ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] Researcher reports all Linux-based VPNs vulnerable to hijack attack

2019-12-06 Thread Pippin via Openvpn-users
Hi, please see here: https://openvpn.net/no-flaws-found-in-openvpn-software/ Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Friday 6 December 2019 11:52, Kenneth Porter wrote: > https://www.bleepingcomputer.com/news/security/new-linux-vulnerability-lets-attack

[Openvpn-users] OpenVPN 3 cli pull-filter ignore option

2020-02-11 Thread Lorenz via Openvpn-users
Hey there! I'm experimenting with the OpenVPN 3 C++ Class Library, specifically the test client wrapper cli. In OpenVPN 2, I used the pull-filter ignore option in the client configuration to avoid the local ping-restart directive getting overwritten by the push directives of the s

[Openvpn-users] http-encapsulation

2020-02-13 Thread Hans via Openvpn-users
Hi all, Is there anyone around here, that performed a measurement what the impact is of doing http-encapsusation (http-proxy) with openvpn? My case: - Client & servers are on a (huge) LAN - client is 2.4.6, servers are 2.4.7 - Setting up a vpn connection with UDP, doing a ping toward mac

[Openvpn-users] win10client does get the route path but cannot access the subnet

2020-02-18 Thread lejeczek via Openvpn-users
couldn't (Request timed out) just a moment before. I wonder if you can share any thoughts on how to troubleshoot it? many thanks, L. pEpkey.asc Description: application/pgp-keys ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net

Re: [Openvpn-users] Quite a few "Authenticate/Decrypt packet error: bad packet ID (may be a replay)" warnings

2020-06-15 Thread Hans via Openvpn-users
Hi, I noticed those "--mute-replay-warnings" to. But it wondered, is it wise and/or safe to mute those warnings? They were brought up (I presume) for a good reason... Hans. -Original Message- From: Ralf Hildebrandt Sent: Monday, June 15, 2020 4:43 PM To: ope

Re: [Openvpn-users] To Generate IPs by Range

2020-07-26 Thread Hans via Openvpn-users
Multiple vpn-processes, each with their own (udp)-port, and their own subnet. For 16 clients you would need /28, for 32 clients a /27 From: "Fermin Francisco via Openvpn-users" mailto:openvpn-users@lists.sourceforge.net>> Date: Sunday, 26 July 2020 at 00:45:25 To

[Openvpn-users] Forced disconnect on TCP

2020-08-05 Thread Hans via Openvpn-users
transmission of messages. ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] Concatenate CRL's?

2021-01-18 Thread Hans via Openvpn-users
I thought this “feature” was solved some versions ago? Long time ago (version 2.1.4) I was caught off-guard by it, and had to solve it in a different way. From: "Stefan Monnier" mailto:monn...@iro.umontreal.ca>> Date: Monday, 18 January 2021 at 21:32:33 To: "openvpn-users@

Re: [Openvpn-users] Flock of openvpn Servers: how to make one machine stop accepting NEW clients?

2021-02-10 Thread Hans via Openvpn-users
From: "Bogdan Rudas via Openvpn-users" mailto:openvpn-users@lists.sourceforge.net>> Date: Wednesday, 10 February 2021 at 22:42:37 To: "Ralf Hildebrandt" mailto:ralf.hildebra...@charite.de>> Cc: "Openvpn Users" mailto:openvpn-users@lists.sourceforge.n

Re: [Openvpn-users] Can command line take multi parameter options? openvpn --remote "ip port" fails

2021-03-18 Thread 8187--- via Openvpn-users
Hello, list, This is probably obvious to the rest of you, but I am not able to give openvpn multi parameter options on the command line: sudo openvpn --remote "127.0.0.1 10153" --route "162.245.206.244 255.255.255.255 net_gateway" --config=/etc/stunnel/vpn/openvpn.conf fa

[Openvpn-users] Scripts initiated by Windows GUI DO pass data over VPN

2021-04-02 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, I have had to test this myself because I am a little shocked .. Using the Windows GUI and an up script named like so: 'my_vpn_01_up.bat' which is kept in the openvpn\config folder of the users home, DOES allow data to be passed over

Re: [Openvpn-users] Scripts initiated by Windows GUI DO pass data over VPN

2021-04-02 Thread tincantech via Openvpn-users
un > > with user's privileges after the tunnel is established can potentially > > use the tunnel. > > I assume that this part relates to the synchronous nature of OpenVPN - > so, an --up script will not be able to use the VPN because OpenVPN is > not active (= waiti

Re: [Openvpn-users] Scripts initiated by Windows GUI DO pass data over VPN

2021-04-02 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Friday, 2 April 2021 20:51, Selva Nair wrote: > Hi, > > On Fri, Apr 2, 2021 at 3:21 PM tincantech via Openvpn-users > openvpn-users@lists.sourceforge.net wrote: > > > -BEG

Re: [Openvpn-users] Scripts initiated by Windows GUI DO pass data over VPN

2021-04-02 Thread tincantech via Openvpn-users
file downloaded > > > from somewhere, but to get the batch file into the right location they > > > have to deliberately copy it there. One can say that we treat that > > > action as equivalent to "--script-security 2". > > See Zip above.. > > Unsuspecting

Re: [Openvpn-users] Scripts initiated by Windows GUI DO pass data over VPN

2021-04-02 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Saturday, 3 April 2021 01:24, tincantech via Openvpn-users wrote: > Sent with ProtonMail Secure Email. > > ‐‐‐ Original Message ‐‐‐ > On Saturday, 3 A

[Openvpn-users] Compression problems

2021-04-05 Thread tincantech via Openvpn-users
774] pid 46022 (openvpn), jid 0, uid 65534: exited on signal 11 Assuming that the client is using some combination of compression options which cannot be changed, or more likely that it is too much trouble to change all the clients, is there a recommended setting to disable all compression f

Re: [Openvpn-users] Compression problems

2021-04-05 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Monday, 5 April 2021 18:34, Gert Doering wrote: > Hi, > > On Mon, Apr 05, 2021 at 02:51:23PM +, tincantech via Openvpn-users wrote: > > > -BEGIN

Re: [Openvpn-users] Compression problems

2021-04-05 Thread tincantech via Openvpn-users
nMrUhoflYnXUprMSw2Q/uCag== =IwPt -END PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

[Openvpn-users] --tls-verify certificate_depth=1

2021-04-06 Thread tincantech via Openvpn-users
PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ___ Openvpn-users mailing list Openvpn-users

Re: [Openvpn-users] --tls-verify certificate_depth=1

2021-04-06 Thread tincantech via Openvpn-users
SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ___ Openvpn-users mailing list Openvpn-users

Re: [Openvpn-users] --tls-verify certificate_depth=1

2021-04-06 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Tuesday, 6 April 2021 18:14, Gert Doering wrote: > Hi, > > On Tue, Apr 06, 2021 at 04:39:06PM +, tincantech via Openvpn-users wrote: > > > can someb

Re: [Openvpn-users] Compression problems

2021-04-07 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, there has been some updates here: https://forums.openvpn.net/viewtopic.php?f=4&t=32100 I have no idea how to diagnose this problem but if anybody gives me some hints or tips then I will pass them onto the forum. The version of openvpn w

[Openvpn-users] CLI for

2021-04-07 Thread senrabdet--- via Openvpn-users
Hi All: Hoping to get an overview of how to pipe passwords in for "./easyrsa set-rsa-pass" in a bash script for openvpn. I am using  Easy-RSA 3 (windows 10, OpenSSL 1.1.1j  16 Feb 2021).  I think something in this version has changed when using "./easyrsa set-rsa-pass" and p

Re: [Openvpn-users] CLI for

2021-04-16 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Wednesday, 7 April 2021 22:36, senrabdet--- via Openvpn-users wrote: > Hi All: > > Hoping to get an overview of how to pipe passwords in for "./easyrsa > set-rsa-pass" in a bash scr

[Openvpn-users] Help with easy-rsa 3 for windows 10 pro boxes

2021-04-19 Thread senrabdet--- via Openvpn-users
Hi All: Can anyone share for windows 10 pro (both for client and server) and easy-rsa 3 (from OpenVPN-2.5.1-I601-amd64.msi), a working:- commands used in EasyRSA-Start.bat- server.ovpn- client.ovpn or a good "how to" site that outlines these for a windows 10 pro client and server? I

Re: [Openvpn-users] Help with easy-rsa 3 for windows 10 pro boxes

2021-04-19 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Forum: https://forums.openvpn.net/viewtopic.php?f=22&t=32171 ‐‐‐ Original Message ‐‐‐ On Monday, 19 April 2021 14:54, senrabdet--- via Openvpn-users wrote: > Hi All: > > Can anyone share for windows 10 pro (both for clie

[Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-04-30 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Ref: https://forums.openvpn.net/viewtopic.php?f=6&t=32193#p99021 (This also applies to --http-proxy) The question is, how/what does openvpn do in the case that the client is connecting via a proxy server when using --redirect-gateway

Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-04-30 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Friday, 30 April 2021 22:15, tincantech via Openvpn-users wrote: > Hi, > > Ref: https://forums.openvpn.net/viewtopic.php?f=6&t=32193#p99021 > > (This also applies to --http-proxy) >

Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-05-01 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Saturday, 1 May 2021 10:03, Gert Doering wrote: > Hi, > > On Fri, Apr 30, 2021 at 09:15:07PM +, tincantech via Openvpn-users wrote: > &g

[Openvpn-users] firewalling TUN iface - how?

2021-05-02 Thread lejeczek via Openvpn-users
fault & expected behaviour? If yes then how to change it, how to firewall OVPN's server tun ifaces? many thanks, L. _______ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] firewalling TUN iface - how?

2021-05-03 Thread lejeczek via Openvpn-users
On 03/05/2021 02:35, Kenneth Porter wrote: --On Sunday, May 02, 2021 4:02 PM +0100 lejeczek via Openvpn-users wrote: Not being an expert I expected that, on a Linux box, I can firewall 'tun0' of ovpn server. Using 'firewalld' it put 'tun0' into a dedicated

Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-05-03 Thread tincantech via Openvpn-users
g :-) > > > and I now remember the caveat that applies > > mostly when using "socks-proxy", not "http-proxy": > > what I'd normally do when using "socks-proxy" is set up an SSH tunnel to > > a remote host > >   ssh -D 1080 >

Re: [Openvpn-users] firewalling TUN iface - how?

2021-05-03 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Monday, 3 May 2021 11:39, lejeczek via Openvpn-users wrote: > On 03/05/2021 02:35, Kenneth Porter wrote: > > > --On Sunday, May 02, 2021 4:02 PM +0100

Re: [Openvpn-users] --socks-proxy and --redirect-gateway def1

2021-05-03 Thread tincantech via Openvpn-users
e same for --socks-proxy/--http-proxy > > as it does for --remote? Install a route for the server we are connected > > to so that address is not routed into the tunnel. > > So the answer is "yes" So it seems ;-) > > > The bug in this case is that, while open

[Openvpn-users] Tunnelblick and --tls-crypt-v2

2021-05-07 Thread tincantech via Openvpn-users
___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] How to disconnect a user from the server?

2021-05-11 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Tuesday, 11 May 2021 15:07, Houman wrote: > Hello, > > I have been struggling to find a way to disconnect a specific user from the > OpenVPN server. > I believe there is one way to

Re: [Openvpn-users] How to disconnect a user from the server?

2021-05-11 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Tuesday, 11 May 2021 19:50, Selva Nair wrote: > On Tue, May 11, 2021 at 2:04 PM tincantech via Openvpn-users > openvpn-users@lists.sourceforge.net wrote: > > > -BEGIN PGP SIGNED MESSAG

[Openvpn-users] Easy-TLS and Easy-PFP

2021-05-15 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, in Openvpn master branch there now exists Peer-Fingerprint mode. This allows establishing a VPN by simply using self signed certificates, which are identified by their fingerprint. This is very simple to setup, especially if you use Easy-PFP

Re: [Openvpn-users] Easy-TLS and Easy-PFP

2021-05-15 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Saturday, 15 May 2021 20:04, tincantech via Openvpn-users wrote: > Hi, > > in Openvpn master branch there now exists Peer-Fingerprint mode. > This allows establishing a VPN by simply using

Re: [Openvpn-users] Easy-TLS and Easy-PFP

2021-05-15 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, I should note: I have deleted the CA certificate from both server and client configs. This is a basic test to see if openvpn is running in Peer-fingerprint mode, because there is otherwise no indication of that being the case, at verb 4. At

Re: [Openvpn-users] Easy-TLS and Easy-PFP

2021-05-15 Thread tincantech via Openvpn-users
wrote: > Hi, > > I should note: I have deleted the CA certificate from both server and client > configs. > This is a basic test to see if openvpn is running in Peer-fingerprint mode, > because there > is otherwise no indication of that being the case, at verb 4. At least, n

[Openvpn-users] Reneg-sec in peer-fingerprint mode

2021-05-16 Thread tincantech via Openvpn-users
on: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature _______ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] Reneg-sec in peer-fingerprint mode

2021-05-19 Thread tincantech via Openvpn-users
if there is interest I'll trac it .. maybe add it to https://community.openvpn.net/openvpn/ticket/1310 Thanks R ‐‐‐ Original Message ‐‐‐ On Sunday, 16 May 2021 10:35, tincantech via Openvpn-users wrote: > Hi, > > in peer-fingerprint mode during --reneg-sec cycle, there appea

Re: [Openvpn-users] Reneg-sec in peer-fingerprint mode

2021-05-19 Thread tincantech via Openvpn-users
1558' > > Verified both setups are using peer-fingerprint mode, No CA. > > if there is interest I'll trac it .. maybe add it to > https://community.openvpn.net/openvpn/ticket/1310 > > Thanks > R > > ‐‐‐ Original Message ‐‐‐ > On Sunday, 16 May 2021 1

[Openvpn-users] Trac - No email notifications at all

2021-05-19 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, if you have ever reported a bug to openvpn on trac then manually check to see if you have had a reply. I am not receiving any notifications of updates from trac. Most recent missed update: https://community.openvpn.net/openvpn/ticket/1389

[Openvpn-users] --show-curves

2021-05-19 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, curve-ball anomaly .. $ openvpn --show-curves Consider using openssl 'ecparam -list_curves' as alternative to running this command. Available Elliptic curves/groups: secp112r1 .. etc Is the command that openvpn is passing to o

[Openvpn-users] GUI auto-disconnect option

2021-05-20 Thread tincantech via Openvpn-users
ture ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] GUI auto-disconnect option

2021-05-20 Thread tincantech via Openvpn-users
I right now have three connections to different locations > active -- that won't be possible if we were to second guess and > disconnect active connections. Sorry, maybe I did not make myself clear: By "useful switch" i meant as an optional extra in the GUI. User choice.. Som

[Openvpn-users] Windows install 2.5.2 failed OpenVPNMSICA

2021-05-24 Thread tincantech via Openvpn-users
PGP signature ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] Is it possible to mix ccd and non-ccd clients to the same server?

2021-05-27 Thread André via Openvpn-users
; See: --server network netmask [nopool] and: --ifconfig-pool args https://build.openvpn.net/man/openvpn-2.5/openvpn.8.html Example: topology subnet server 192.168.21.0 255.255.255.0 'nopool' ifconfig-pool 192.168.21.16 192.168.21.253 ___

Re: [Openvpn-users] GUI auto-disconnect option

2021-05-27 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Thursday, 27 May 2021 16:25, Gert Doering wrote: > Hi, > > On Thu, May 27, 2021 at 04:33:54PM +0200, Bo Berglund wrote: > > > > In c:\program files\openvpn\bin\ there is a "tapctl

Re: [Openvpn-users] GUI auto-disconnect option

2021-05-27 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 See: https://community.openvpn.net/openvpn/wiki/OpenvpnSoftwareRepos -BEGIN PGP SIGNATURE- Version: ProtonMail wsBzBAEBCAAGBQJgr8jaACEJEE+XnPZrkLidFiEECbw9RGejjXJ5xVVVT5ec 9muQuJ3XUAgAsjCw1/pV8TakkEDP77z6+/1ngpU7rLqP0XUzqYUIs6P8LrHC

Re: [Openvpn-users] Server starts without configuration as a service...

2021-05-27 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Thursday, 27 May 2021 23:35, Bo Berglund wrote: > I have just configured my new OpenVPN server running on a RaspberryPi3B+ with > the latest release of the ope

Re: [Openvpn-users] Server starts without configuration as a service...

2021-05-28 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Friday, 28 May 2021 07:58, Bo Berglund wrote: > On Thu, 27 May 2021 23:26:00 +, tincantech via Openvpn-users > openvpn-users@lists.sourceforge.net wrote: > > > > I have looked a

Re: [Openvpn-users] Server starts without configuration as a service...

2021-05-28 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 There are scripts, such as Nyr and Angristan. And, for Pi users there is pivpn.io ‐‐‐ Original Message ‐‐‐ On Friday, 28 May 2021 11:26, tincantech via Openvpn-users wrote: > Hi, > > ‐‐‐ Original Message ‐‐‐ > On Fr

Re: [Openvpn-users] Openvpn install ubuntu 20.04 compile

2021-06-04 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Friday, 4 June 2021 16:04, Gokan Atmaca wrote: > Hello > > I am getting an error as below in openvpn installation. what would be > the reason ? > > make[5]: Leaving directory '/root/t

Re: [Openvpn-users] Client-to-client setup fails mysteriously...

2021-06-04 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Friday, 4 June 2021 19:17, Bo Berglund wrote: > I have set up an Openvpn server on a Raspberry Pi at a remote location I can > access through another OpenVPN server. So: HOST:Client -> Server:HO

  1   2   3   4   5   6   7   8   >