Joined: 03 Oct 2014
Location: Fayetteville, NC, USA
|Posted: Thu Sep 10, 2020 11:13 pm Post subject: OpenVPN server denying connections incorrectly?
|I am running an OpenVPN server and suddenly it is denying connections, claiming that the certificate has expired when they are good through 2023. I verified my certificates were valid on both the client and server using openssl x509 -in whatever.crt -dates -noout and everything is valid. Heck, the CA is good through 2030! When I try connecting however, I get this.
20200910 16:09:13 220.127.116.11:2721 TLS: Initial packet from [AF_INET]18.104.22.168:2721 sid=70e0b565 24b7f0d1
20200910 16:09:14 N 22.214.171.124:2721 VERIFY ERROR: depth=0 error=CRL has expired: C=US ST=North Carolina L=Fayetteville O=Hidden Company OU=Remote Users CN=Hidden Name emailAddressfirstname.lastname@example.org
20200910 16:09:14 N 126.96.36.199:2721 OpenSSL: error:1417C086:lib(20):func(380):reason(134)
20200910 16:09:14 N 188.8.131.52:2721 TLS_ERROR: BIO read tls_read_plaintext error
20200910 16:09:14 184.108.40.206:2721 NOTE: --mute triggered...
20200910 16:09:14 220.127.116.11:2721 2 variation(s) on previous 3 message(s) suppressed by --mute
20200910 16:09:14 18.104.22.168:2721 SIGUSR1[soft tls-error] received client-instance restarting
20200910 16:09:56 22.214.171.124:2726 TLS: Initial packet from [AF_INET]126.96.36.199:2726 sid=5cfe5ac6 65c6c4f0
20200910 16:09:56 N 188.8.131.52:2726 VERIFY ERROR: depth=0 error=CRL has expired: C=US ST=North Carolina L=Fayetteville O=Hidden Company OU=Remote Users CN=Hidden Name emailAddressemail@example.com
20200910 16:09:56 N 184.108.40.206:2726 OpenSSL: error:1417C086:lib(20):func(380):reason(134)
20200910 16:09:56 N 220.127.116.11:2726 TLS_ERROR: BIO read tls_read_plaintext error
What is going on? The date and time on both the OpenVPN server AND the clients (my laptop and my Galaxy Note 9) are correct.
My God, I can be a dunce sometimes. I was troubleshooting this in a hurry. I just realized that the CRL expired. Why? No clue. Either way I just have to generate a new one and upload it to the server. Sorry for the trouble. Nothing to see here...
Ever picture systemd as what runs "The Borg"?