Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Can't connect SSL VPN Remote Access.

Hi all,

I'm trying to set up a VPN SSL for remote access, after regenerate certificate I get this error while trying to connect.

Mon Mar 27 14:21:49 2017 OpenVPN 2.3.8 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [IPv6] built on Dec 9 2016
Mon Mar 27 14:21:49 2017 library versions: OpenSSL 1.0.1u 22 Sep 2016, LZO 2.09
Enter Management Password:
Mon Mar 27 14:21:49 2017 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Mon Mar 27 14:21:49 2017 Need hold release from management interface, waiting...
Mon Mar 27 14:21:50 2017 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Mon Mar 27 14:21:50 2017 MANAGEMENT: CMD 'state on'
Mon Mar 27 14:21:50 2017 MANAGEMENT: CMD 'log all on'
Mon Mar 27 14:21:50 2017 MANAGEMENT: CMD 'hold off'
Mon Mar 27 14:21:50 2017 MANAGEMENT: CMD 'hold release'
Mon Mar 27 14:21:59 2017 MANAGEMENT: CMD 'username "Auth" "administrador"'
Mon Mar 27 14:21:59 2017 MANAGEMENT: CMD 'password [...]'
Mon Mar 27 14:21:59 2017 Socket Buffers: R=[65536->65536] S=[65536->65536]
Mon Mar 27 14:21:59 2017 Attempting to establish TCP connection with [AF_INET]186.64.174.54:8443 [nonblock]
Mon Mar 27 14:21:59 2017 MANAGEMENT: >STATE:1490646119,TCP_CONNECT,,,,,,
Mon Mar 27 14:22:00 2017 TCP connection established with [AF_INET]186.64.174.54:8443
Mon Mar 27 14:22:00 2017 TCPv4_CLIENT link local: [undef]
Mon Mar 27 14:22:00 2017 TCPv4_CLIENT link remote: [AF_INET]186.64.174.54:8443
Mon Mar 27 14:22:00 2017 MANAGEMENT: >STATE:1490646120,WAIT,,,,,,
Mon Mar 27 14:22:00 2017 MANAGEMENT: >STATE:1490646120,AUTH,,,,,,
Mon Mar 27 14:22:00 2017 TLS: Initial packet from [AF_INET]186.64.174.54:8443, sid=de463156 c6977f16
Mon Mar 27 14:22:00 2017 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Mon Mar 27 14:22:00 2017 VERIFY OK: depth=1, C=CR, ST=San José, L=San José, O=Würth, OU=Würth, CN=Würth Costa Rica, emailAddress=carlo.rosales@wurth.cr
Mon Mar 27 14:22:00 2017 VERIFY X509NAME ERROR: C=CR, ST=NA, L=San José, O=Wurth Costa Rica, OU=OU, CN=SophosApplianceCertificate_S1403B221848B3D, emailAddress=carlo.rosales@wurth.cr, must be C=CR, ST=NA, L=San José, O=Wurth Costa Rica, OU=OU, CN=SophosApplianceCertificate_S1403B221848B3D, emailAddress=carlo.rosales@wurth.cr
Mon Mar 27 14:22:00 2017 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
Mon Mar 27 14:22:00 2017 TLS Error: TLS object -> incoming plaintext read error
Mon Mar 27 14:22:00 2017 TLS Error: TLS handshake failed
Mon Mar 27 14:22:00 2017 Fatal TLS error (check_tls_errors_co), restarting
Mon Mar 27 14:22:00 2017 SIGUSR1[soft,tls-error] received, process restarting
Mon Mar 27 14:22:00 2017 MANAGEMENT: >STATE:1490646120,RECONNECTING,tls-error,,,,,
Mon Mar 27 14:22:00 2017 Restart pause, 5 second(s)
Mon Mar 27 14:22:05 2017 Socket Buffers: R=[65536->65536] S=[65536->65536]
Mon Mar 27 14:22:05 2017 Attempting to establish TCP connection with [AF_INET]172.16.16.16:8443 [nonblock]
Mon Mar 27 14:22:05 2017 MANAGEMENT: >STATE:1490646125,TCP_CONNECT,,,,,,
Mon Mar 27 14:22:06 2017 TCP connection established with [AF_INET]172.16.16.16:8443
Mon Mar 27 14:22:06 2017 TCPv4_CLIENT link local: [undef]
Mon Mar 27 14:22:06 2017 TCPv4_CLIENT link remote: [AF_INET]172.16.16.16:8443
Mon Mar 27 14:22:06 2017 MANAGEMENT: >STATE:1490646126,WAIT,,,,,,
Mon Mar 27 14:22:06 2017 MANAGEMENT: >STATE:1490646126,AUTH,,,,,,
Mon Mar 27 14:22:06 2017 TLS: Initial packet from [AF_INET]172.16.16.16:8443, sid=298bc3b2 5cb0532f
Mon Mar 27 14:22:06 2017 VERIFY OK: depth=1, C=CR, ST=San José, L=San José, O=Würth, OU=Würth, CN=Würth Costa Rica, emailAddress=carlo.rosales@wurth.cr
Mon Mar 27 14:22:06 2017 VERIFY X509NAME ERROR: C=CR, ST=NA, L=San José, O=Wurth Costa Rica, OU=OU, CN=SophosApplianceCertificate_S1403B221848B3D, emailAddress=carlo.rosales@wurth.cr, must be C=CR, ST=NA, L=San José, O=Wurth Costa Rica, OU=OU, CN=SophosApplianceCertificate_S1403B221848B3D, emailAddress=carlo.rosales@wurth.cr
Mon Mar 27 14:22:06 2017 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
Mon Mar 27 14:22:06 2017 TLS Error: TLS object -> incoming plaintext read error
Mon Mar 27 14:22:06 2017 TLS Error: TLS handshake failed
Mon Mar 27 14:22:06 2017 Fatal TLS error (check_tls_errors_co), restarting
Mon Mar 27 14:22:06 2017 SIGUSR1[soft,tls-error] received, process restarting
Mon Mar 27 14:22:06 2017 MANAGEMENT: >STATE:1490646126,RECONNECTING,tls-error,,,,,
Mon Mar 27 14:22:06 2017 Restart pause, 5 second(s)

Here is my configuration.

Am I missing something?

This could be due to the certificate regeneration?

Thanks in advance.



This thread was automatically locked due to age.
Parents
  • John Henry Vindas Carballo said:

    Mon Mar 27 14:22:06 2017 VERIFY X509NAME ERROR: C=CR, ST=NA, L=San José, O=Wurth Costa Rica, OU=OU, CN=SophosApplianceCertificate_S1403B221848B3D, emailAddress=carlo.rosales@wurth.cr, must be C=CR, ST=NA, L=San José, O=Wurth Costa Rica, OU=OU, CN=SophosApplianceCertificate_S1403B221848B3D, emailAddress=carlo.rosales@wurth.cr

     

    This could be due to the certificate regeneration? 

    You changed the certs and now they don't match what your client has. As Luk said, login to user portal and download the configuration again.

Reply
  • John Henry Vindas Carballo said:

    Mon Mar 27 14:22:06 2017 VERIFY X509NAME ERROR: C=CR, ST=NA, L=San José, O=Wurth Costa Rica, OU=OU, CN=SophosApplianceCertificate_S1403B221848B3D, emailAddress=carlo.rosales@wurth.cr, must be C=CR, ST=NA, L=San José, O=Wurth Costa Rica, OU=OU, CN=SophosApplianceCertificate_S1403B221848B3D, emailAddress=carlo.rosales@wurth.cr

     

    This could be due to the certificate regeneration? 

    You changed the certs and now they don't match what your client has. As Luk said, login to user portal and download the configuration again.

Children