This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN will not connect getting: error=certificate is not yet valid.

First one I set up went pretty smoothly, this one will not connect.

Getting a certificate not yet valid and some 10.255.0.1 address, not sure where that is coming from.

 

Any suggestions will greatly be appreciated. Thanks

 

 

Wed May 16 16:42:20 2018 OpenVPN 2.3.8 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [IPv6] built on Jul  3 2017
Wed May 16 16:42:20 2018 library versions: OpenSSL 1.0.2l  25 May 2017, LZO 2.09
Wed May 16 16:42:20 2018 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Wed May 16 16:42:20 2018 Need hold release from management interface, waiting...
Wed May 16 16:42:20 2018 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Wed May 16 16:42:20 2018 MANAGEMENT: CMD 'state on'
Wed May 16 16:42:20 2018 MANAGEMENT: CMD 'log all on'
Wed May 16 16:42:20 2018 MANAGEMENT: CMD 'hold off'
Wed May 16 16:42:20 2018 MANAGEMENT: CMD 'hold release'
Wed May 16 16:42:25 2018 MANAGEMENT: CMD 'username "Auth" "joeschmoe"'
Wed May 16 16:42:25 2018 MANAGEMENT: CMD 'password [...]'
Wed May 16 16:42:25 2018 Socket Buffers: R=[8192->8192] S=[8192->8192]
Wed May 16 16:42:25 2018 Attempting to establish TCP connection with [AF_INET]aaa.bbb.ccc.ddd:8443 [nonblock]
Wed May 16 16:42:25 2018 MANAGEMENT: >STATE:1526514145,TCP_CONNECT,,,,,,
Wed May 16 16:42:26 2018 TCP connection established with [AF_INET]aaa.bbb.ccc.ddd:8443
Wed May 16 16:42:26 2018 TCPv4_CLIENT link local: [undef]
Wed May 16 16:42:26 2018 TCPv4_CLIENT link remote: [AF_INET]aaa.bbb.ccc.ddd:8443
Wed May 16 16:42:26 2018 MANAGEMENT: >STATE:1526514146,WAIT,,,,,,
Wed May 16 16:42:27 2018 MANAGEMENT: >STATE:1526514147,AUTH,,,,,,
Wed May 16 16:42:27 2018 TLS: Initial packet from [AF_INET]aaa.bbb.ccc.ddd:8443, sid=35395cdf 5b1fb327
Wed May 16 16:42:27 2018 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Wed May 16 16:42:27 2018 VERIFY ERROR: depth=1, error=certificate is not yet valid: C=US, ST=stuff, emailAddress=Email
Wed May 16 16:42:27 2018 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
Wed May 16 16:42:27 2018 TLS Error: TLS object -> incoming plaintext read error
Wed May 16 16:42:27 2018 TLS Error: TLS handshake failed
Wed May 16 16:42:27 2018 Fatal TLS error (check_tls_errors_co), restarting
Wed May 16 16:42:27 2018 SIGUSR1[soft,tls-error] received, process restarting
Wed May 16 16:42:27 2018 MANAGEMENT: >STATE:1526514147,RECONNECTING,tls-error,,,,,
Wed May 16 16:42:27 2018 Restart pause, 5 second(s)
Wed May 16 16:42:32 2018 Socket Buffers: R=[8192->8192] S=[8192->8192]
Wed May 16 16:42:32 2018 Attempting to establish TCP connection with [AF_INET]10.255.0.1:8443 [nonblock]
Wed May 16 16:42:32 2018 MANAGEMENT: >STATE:1526514152,TCP_CONNECT,,,,,,
Wed May 16 16:42:42 2018 TCP: connect to [AF_INET]10.255.0.1:8443 failed, will try again in 5 seconds: The system tried to join a drive to a directory on a joined drive.  
Wed May 16 16:42:42 2018 SIGUSR1[soft,init_instance] received, process restarting
Wed May 16 16:42:42 2018 MANAGEMENT: >STATE:1526514162,RECONNECTING,init_instance,,,,,
Wed May 16 16:42:42 2018 Restart pause, 5 second(s)
Wed May 16 16:42:47 2018 Socket Buffers: R=[8192->8192] S=[8192->8192]
Wed May 16 16:42:47 2018 Attempting to establish TCP connection with [AF_INET]aaa.bbb.ccc.ddd:8443 [nonblock]
Wed May 16 16:42:47 2018 MANAGEMENT: >STATE:1526514167,TCP_CONNECT,,,,,,
Wed May 16 16:42:48 2018 TCP connection established with [AF_INET]aaa.bbb.ccc.ddd:8443
Wed May 16 16:42:48 2018 TCPv4_CLIENT link local: [undef]
Wed May 16 16:42:48 2018 TCPv4_CLIENT link remote: [AF_INET]aaa.bbb.ccc.ddd:8443
Wed May 16 16:42:48 2018 MANAGEMENT: >STATE:1526514168,WAIT,,,,,,
Wed May 16 16:42:48 2018 MANAGEMENT: >STATE:1526514168,AUTH,,,,,,
Wed May 16 16:42:48 2018 TLS: Initial packet from [AF_INET]aaa.bbb.ccc.ddd:8443, sid=d0f9ad3b b9e4bab1
Wed May 16 16:42:48 2018 VERIFY ERROR: depth=1, error=certificate is not yet valid: C=US, ST=stuff, emailAddress=Email
Wed May 16 16:42:48 2018 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
Wed May 16 16:42:48 2018 TLS Error: TLS object -> incoming plaintext read error
Wed May 16 16:42:48 2018 TLS Error: TLS handshake failed
Wed May 16 16:42:48 2018 Fatal TLS error (check_tls_errors_co), restarting
Wed May 16 16:42:48 2018 SIGUSR1[soft,tls-error] received, process restarting
Wed May 16 16:42:48 2018 MANAGEMENT: >STATE:1526514168,RECONNECTING,tls-error,,,,,
Wed May 16 16:42:48 2018 Restart pause, 5 second(s)
Wed May 16 16:42:53 2018 Socket Buffers: R=[8192->8192] S=[8192->8192]
Wed May 16 16:42:53 2018 Attempting to establish TCP connection with [AF_INET]10.255.0.1:8443 [nonblock]
Wed May 16 16:42:53 2018 MANAGEMENT: >STATE:1526514173,TCP_CONNECT,,,,,,
Wed May 16 16:43:03 2018 TCP: connect to [AF_INET]10.255.0.1:8443 failed, will try again in 5 seconds: The system tried to join a drive to a directory on a joined drive.  
Wed May 16 16:43:03 2018 SIGUSR1[soft,init_instance] received, process restarting



This thread was automatically locked due to age.
  • Hi BradD ,

     

    According to the logs , the interface IP address are stored on the Config File, in a way it will try to connect to  all the possible ports on the XG firewall. 

     

    Wed May 16 16:42:47 2018 Attempting to establish TCP connection with [AF_INET]aaa.bbb.ccc.ddd:8443 [nonblock]
    Wed May 16 16:42:47 2018 MANAGEMENT: >STATE:1526514167,TCP_CONNECT,,,,,,
    Wed May 16 16:42:48 2018 TCP connection established with [AF_INET]aaa.bbb.ccc.ddd:8443

     

    As you may observe that 10.255.0.1:8443 would not work as it is an internal address. You may specify the hostname on the SSL VPN configuration and use DYDNS to connect to the external address .

  • I saw that, but never have entered that address anywhere so wasn't sure where it came from.

    Removed and it does work now

    Regular users are not going to be able to figure that out even if given directions though.

    I found that IP, it is the Guest AP for wifi we don't have so i disabled it, but it was still listed in the config download, so I deleted it altogether and the IP was gone from the config file.

    Thanks

  • Hi Brad,

    Thank you for an update , glad the issue is resolved on your end.