Results 1 to 9 of 9
  1. #1
    Untangler
    Join Date
    Aug 2011
    Posts
    64

    Default 15.1 server issue

    Hi all

    Only one of my 2 boxes was updated to 15.1 and since then 15.0 can't connect to OpenVPN server on 15.1

    Someone's having the same issue ?

  2. #2
    Untangler jcoffin's Avatar
    Join Date
    Aug 2008
    Location
    Sunnyvale, CA
    Posts
    9,013

    Default

    If your 15.0 box has an OpenVPN install which has been around for a long time, it might have a MD5 certificate which are no longer supported since they are insecure.

    https://forums.untangle.com/openvpn/...vpn-users.html

    Check your 15.0 certificate by running on the terminal

    Code:
    openssl x509 -text -noout -in /usr/share/untangle/settings/openvpn/server.crt | grep "Signature Algo"
    Attention: Support and help on the Untangle Forums is provided by
    volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  3. #3
    Untangler
    Join Date
    Aug 2011
    Posts
    64

    Default

    Both are SHA512

  4. #4
    Untangler jcoffin's Avatar
    Join Date
    Aug 2008
    Location
    Sunnyvale, CA
    Posts
    9,013

    Default

    Open a support ticket. Sounds like there is a different problem.
    Attention: Support and help on the Untangle Forums is provided by
    volunteers and community members like yourself.
    If you need Untangle support please call or email support@untangle.com

  5. #5
    Newbie
    Join Date
    May 2015
    Posts
    3

    Default

    Hi, I've the same issue after the 15.0 to 15.1 upgrade: openvpn client won't connect anymore. They do connect to a backup server that is still on 15.0. Have you found a solution?
    My certificate is a old one though..

  6. #6
    Untangle Ninja
    Join Date
    May 2008
    Posts
    1,231

    Default

    My 15.1 is connecting to a 15.0. The 15.0 has the new type cert. FYI

  7. #7
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    24,958

    Default

    If you have an MD5 certificate on any of your Untangles as soon as v15.1 appears you have no choice but to remove all of your OpenVPN modules and reconfigure them from scratch to fix it.
    Rob Sandling, BS:SWE, MCP
    NexgenAppliances.com
    Phone: 866-794-8879 x201
    Email: support@nexgenappliances.com

  8. #8
    Untanglit
    Join Date
    Nov 2019
    Posts
    19

    Default

    Quote Originally Posted by sky-knight View Post
    If you have an MD5 certificate on any of your Untangles as soon as v15.1 appears you have no choice but to remove all of your OpenVPN modules and reconfigure them from scratch to fix it.
    Does that mean that if we don't have any MD5 this should work fine ?

    Sorry if thats a loaded question, we depend on OVPN for our remote workers and also our site to site VPNs.

    Having checked they all state:

    Signature Algorithm: sha512WithRSAEncryption
    Signature Algorithm: sha512WithRSAEncryption

  9. #9
    Untangle Ninja
    Join Date
    Jan 2011
    Posts
    1,284

    Default

    yes, sha512 is good to go

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2