Page 1 of 1
Openvpn SSL error
Posted: Sat Jun 21, 2014 7:44 am
by mesa57
Some strange behaviour. If I import the openvpn settings om android it works perfectly. Until after a few days I cannot connect to my server anymore : Polar SSL error.
In the Openvpn log : error verifying CA certificate.
Strange because initialy it did work.
What I do see is that the CN=name differs from my server URL. But openvpn does not tell if that is the problem.
I am using latest version of Softether server : softether-vpnserver-v4.09-9451-beta-2014.06.09-linux-arm_eabi-32bit.tar.gz (5.01 MB)
Anyone a clue ?
Re: Openvpn SSL error
Posted: Tue Jun 24, 2014 7:41 am
by mesa57
*bump* Nobody ?
Re: Openvpn SSL error
Posted: Tue Jun 24, 2014 1:43 pm
by cedar
Please try to re-create the server certificate.
Especially if you update the server from an older version.
Re: Openvpn SSL error
Posted: Tue Jun 24, 2014 1:52 pm
by mesa57
Thanks for you're reply :)
I regenerated the certificates about 10 times now.
Everytime I import the .ovpn profile in openvpn connect it works.
For one day and then it says the embedded certificate is not valid.
Re: Openvpn SSL error
Posted: Wed Jun 25, 2014 3:24 pm
by dnobori
Is your SoftEther VPN Server running VPN Gate relay service?
Re: Openvpn SSL error
Posted: Wed Jun 25, 2014 6:07 pm
by mesa57
No, it is running as a normal server (on a raspberry PI).
Re: Openvpn SSL error
Posted: Sat Jul 26, 2014 6:58 am
by mesa57
Finally a solution (I hope). I have changed the dns adres (xxxxxx.softether.net) in the generated .ovpn file to the IP adres of the server.
Until now openvpn (connect) seems to connect and does not run into the Polar SSL error.
I will keep on testing for the comming days.
If somebody has an explanation for this behaviour ?
Re: Openvpn SSL error
Posted: Sat Aug 09, 2014 7:31 am
by mesa57
That was indeed the solution. It appears that the softether DNS server sometimes switches to an other IP address if I use xxxxxxx.softether.net
If I restart the server the DNS entry is apparently corrected, but after a while it changes to an other IP.