From: Maggie C. <Mag...@wh...> - 2007-05-31 15:33:15
|
Please advise. I am new with using openvpn=20 The ca.crt and ca.key were deleted from the linux server that the certs are created on.=20 I had a copy of the cert and the key and just ftp'd them back on the server.=20 But now when I create a new p12 cert it fails to connect to the tunnel using openvpn What do I need to do if anything to the linux box the certs were setup on?=20 Can someone explain to me why the new certs that are created fail to connect thru the tunnel?=20 I know the tunnel works because I have other tokens that were created before the cert and key were deleted and replaced? =20 Here is a short version of the log file. Any help will be greatly appreciated Wed May 30 16:14:32 2007 us=3D492155 OpenVPN 2.1_beta7 Win32-MinGW [SSL] [LZO2] built on Nov 12 2005 Wed May 30 16:14:32 2007 us=3D610903 LZO compression initialized Wed May 30 16:14:32 2007 us=3D611076 Control Channel MTU parms [ L:1560 D:140 EF:40 EB:0 ET:0 EL:0 ] Wed May 30 16:14:32 2007 us=3D615258 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ] Wed May 30 16:14:32 2007 us=3D615323 Local Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client' Wed May 30 16:14:32 2007 us=3D615344 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-server' Wed May 30 16:14:32 2007 us=3D615382 Local Options hash (VER=3DV4): 'bc07730e' Wed May 30 16:14:32 2007 us=3D615407 Expected Remote Options hash (VER=3DV4): 'b695cb4a' Wed May 30 16:14:32 2007 us=3D615446 Attempting to establish TCP connection with 64.140.241.31:443 Wed May 30 16:14:53 2007 us=3D595830 TCP: connect to 64.140.241.31:443 failed, will try again in 5 seconds Wed May 30 16:14:58 2007 us=3D598065 TCP connection established with 64.140.241.32:443 Wed May 30 16:14:58 2007 us=3D598141 TCP/UDP: Dynamic remote address changed during TCP connection establishment Wed May 30 16:14:58 2007 us=3D598190 Socket Buffers: R=3D[8192->8192] S=3D[8192->8192] Wed May 30 16:14:58 2007 us=3D598230 TCPv4_CLIENT link local: [undef] Wed May 30 16:14:58 2007 us=3D598261 TCPv4_CLIENT link remote: 64.140.241.32:443 Wed May 30 16:14:58 2007 us=3D632267 TLS: Initial packet from 64.140.241.32:443, sid=3Dd5f12ff8 b839f240 Wed May 30 16:14:58 2007 us=3D835591 VERIFY OK: depth=3D1, /C=3DUS/ST=3DNH/L=3DPortsmouth/O=3DWhalebackSystems/CN=3DWhalebackSystems= CA/emailA ddress=3D...@wh... Wed May 30 16:14:58 2007 us=3D836734 VERIFY OK: nsCertType=3DSERVER Wed May 30 16:14:58 2007 us=3D836779 VERIFY OK: depth=3D0, /C=3DUS/ST=3DNH/L=3DPortsmouth/O=3DWhalebackSystems/CN=3Dserver/emailAddr= ess=3Dca@wh alebacksystems.com Wed May 30 16:15:05 2007 us=3D59928 Connection reset, restarting [0] Wed May 30 16:15:05 2007 us=3D60301 TCP/UDP: Closing socket Wed May 30 16:15:05 2007 us=3D60389 SIGUSR1[soft,connection-reset] received, process restarting Wed May 30 16:15:05 2007 us=3D60423 Restart pause, 5 second(s) Wed May 30 16:15:10 2007 us=3D60402 Re-using SSL/TLS context Wed May 30 16:15:10 2007 us=3D60520 LZO compression initialized Wed May 30 16:15:10 2007 us=3D60644 Control Channel MTU parms [ L:1560 D:140 EF:40 EB:0 ET:0 EL:0 ] Wed May 30 16:15:10 2007 us=3D62243 Data Channel MTU parms [ L:1560 = D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ] Wed May 30 16:15:10 2007 us=3D62323 Local Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client' Wed May 30 16:15:10 2007 us=3D62356 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-server' Wed May 30 16:15:10 2007 us=3D62510 Local Options hash (VER=3DV4): 'bc07730e' Wed May 30 16:15:10 2007 us=3D63262 Expected Remote Options hash = (VER=3DV4): 'b695cb4a' Wed May 30 16:15:10 2007 us=3D63323 Attempting to establish TCP = connection with 64.140.241.31:443 Wed May 30 16:15:31 2007 us=3D15013 TCP: connect to 64.140.241.31:443 failed, will try again in 5 seconds Wed May 30 16:15:36 2007 us=3D16113 TCP connection established with 64.140.241.32:443 Wed May 30 16:15:36 2007 us=3D16169 TCP/UDP: Dynamic remote address changed during TCP connection establishment Wed May 30 16:15:36 2007 us=3D16199 Socket Buffers: R=3D[8192->8192] S=3D[8192->8192] Wed May 30 16:15:36 2007 us=3D16225 TCPv4_CLIENT link local: [undef] Wed May 30 16:15:36 2007 us=3D16247 TCPv4_CLIENT link remote: 64.140.241.32:443 Wed May 30 16:15:36 2007 us=3D17284 TLS: Initial packet from 64.140.241.32:443, sid=3D184707e5 b8455082 Wed May 30 16:15:36 2007 us=3D253202 VERIFY OK: depth=3D1, /C=3DUS/ST=3DNH/L=3DPortsmouth/O=3DWhalebackSystems/CN=3DWhalebackSystems= CA/emailA ddress=3D...@wh... Wed May 30 16:15:36 2007 us=3D254276 VERIFY OK: nsCertType=3DSERVER Wed May 30 16:15:36 2007 us=3D254302 VERIFY OK: depth=3D0, /C=3DUS/ST=3DNH/L=3DPortsmouth/O=3DWhalebackSystems/CN=3Dserver/emailAddr= ess=3Dca@wh alebacksystems.com Wed May 30 16:15:37 2007 us=3D97022 Connection reset, restarting [-1] Wed May 30 16:15:37 2007 us=3D97358 TCP/UDP: Closing socket Wed May 30 16:15:37 2007 us=3D97444 SIGUSR1[soft,connection-reset] received, process restarting Wed May 30 16:15:37 2007 us=3D97469 Restart pause, 5 second(s) Wed May 30 16:15:42 2007 us=3D97185 Re-using SSL/TLS context Wed May 30 16:15:42 2007 us=3D97288 LZO compression initialized Wed May 30 16:15:42 2007 us=3D97398 Control Channel MTU parms [ L:1560 D:140 EF:40 EB:0 ET:0 EL:0 ] Wed May 30 16:15:42 2007 us=3D97928 Data Channel MTU parms [ L:1560 = D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ] Wed May 30 16:15:42 2007 us=3D97987 Local Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client' Wed May 30 16:15:42 2007 us=3D98013 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-server' Wed May 30 16:15:42 2007 us=3D98054 Local Options hash (VER=3DV4): 'bc07730e' Wed May 30 16:15:42 2007 us=3D98087 Expected Remote Options hash = (VER=3DV4): 'b695cb4a' Wed May 30 16:15:42 2007 us=3D98135 Attempting to establish TCP = connection with 64.140.241.31:443 Maggie Coffey Sr.Systems Administrator=20 Whaleback Systems 72 Pease Blvd=20 Portsmouth NH 03801 Phone 603.812.0430=20 mc...@wh...=20 |