Depuis que je suis passé à la version 1.4.10 de IPCOP, mes tunnels openvpn sont morts.
J'utilise zerina dont j'étais jusqu'à présent assez content (jusqu'à 1.4.9).
Côté serveur:
- Code: Tout sélectionner
Nov 12 18:12:37 paris openvpnserver[1184]: OpenVPN 2.0.2 i386-pc-linux [SSL] [LZ
O] built on Aug 31 2005
Nov 12 18:12:37 paris openvpnserver[1184]: WARNING: file '/var/ipcop/ovpn/certs/
serverkey.pem' is group or others accessible
Nov 12 18:12:37 paris openvpnserver[1184]: TUN/TAP device tun0 opened
Nov 12 18:12:37 paris openvpnserver[1184]: /sbin/ifconfig tun0 192.168.128.1 poi
ntopoint 192.168.128.2 mtu 1500
Nov 12 18:12:37 paris openvpnserver[1188]: GID set to nobody
Nov 12 18:12:37 paris openvpnserver[1188]: UID set to nobody
Nov 12 18:12:37 paris openvpnserver[1188]: UDPv4 link local (bound): [undef]:119
4
Nov 12 18:12:37 paris openvpnserver[1188]: UDPv4 link remote: [undef]
Nov 12 18:12:37 paris openvpnserver[1188]: Initialization Sequence Completed
Nov 12 18:13:22 paris openvpnserver[1188]: xx.xxx.xxx.xxx:1194 Re-using SSL/TLS
context
Nov 12 18:13:22 paris openvpnserver[1188]: xx.xxx.xxx.xxx:1194 LZO compression i
nitialized
Nov 12 18:13:23 paris openvpn: stack smashing attack in function tls1_P_hash
Côté client:
- Code: Tout sélectionner
Sat Nov 12 18:13:22 2005 OpenVPN 2.0.2 Win32-MinGW [SSL] [LZO] built on Aug 25 2005
Sat Nov 12 18:13:22 2005 IMPORTANT: OpenVPN's default port number is now 1194, based on an official port number assignment by IANA. OpenVPN 2.0-beta16 and earlier used 5000 as the default port.
Sat Nov 12 18:13:22 2005 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Sat Nov 12 18:13:25 2005 LZO compression initialized
Sat Nov 12 18:13:25 2005 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Sat Nov 12 18:13:25 2005 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Sat Nov 12 18:13:25 2005 Local Options hash (VER=V4): '41690919'
Sat Nov 12 18:13:25 2005 Expected Remote Options hash (VER=V4): '530fdded'
Sat Nov 12 18:13:25 2005 UDPv4 link local (bound): [undef]:1194
Sat Nov 12 18:13:25 2005 UDPv4 link remote: xxx.xx.xx.xx:1194
Sat Nov 12 18:13:25 2005 TLS: Initial packet from xxx.xx.xx.xx:1194, sid=8c369743 62aa07b5
Sat Nov 12 18:13:25 2005 VERIFY OK: depth=1, /C=xx/O=xxxxxxx/CN=xxxxxxxxx
Sat Nov 12 18:13:25 2005 VERIFY OK: depth=0, /C=xx/O=xxxxxxx/CN=xxxxxxxxx
Sat Nov 12 18:14:25 2005 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Sat Nov 12 18:14:25 2005 TLS Error: TLS handshake failed
Sat Nov 12 18:14:25 2005 TCP/UDP: Closing socket
Sat Nov 12 18:14:25 2005 SIGUSR1[soft,tls-error] received, process restarting
Sat Nov 12 18:14:25 2005 Restart pause, 2 second(s)
Sat Nov 12 18:14:27 2005 IMPORTANT: OpenVPN's default port number is now 1194, based on an official port number assignment by IANA. OpenVPN 2.0-beta16 and earlier used 5000 as the default port.
Sat Nov 12 18:14:27 2005 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Sat Nov 12 18:14:27 2005 LZO compression initialized
Sat Nov 12 18:14:27 2005 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Sat Nov 12 18:14:27 2005 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Sat Nov 12 18:14:27 2005 Local Options hash (VER=V4): '41690919'
Sat Nov 12 18:14:27 2005 Expected Remote Options hash (VER=V4): '530fdded'
Sat Nov 12 18:14:27 2005 UDPv4 link local (bound): [undef]:1194
Sat Nov 12 18:14:27 2005 UDPv4 link remote: xxx.xx.xx.xx:1194
Sat Nov 12 18:15:27 2005 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Sat Nov 12 18:15:27 2005 TLS Error: TLS handshake failed
Sat Nov 12 18:15:27 2005 TCP/UDP: Closing socket
Sat Nov 12 18:15:27 2005 SIGUSR1[soft,tls-error] received, process restarting
Sat Nov 12 18:15:27 2005 Restart pause, 2 second(s)
...
Le process openvpn disparait dès la moindre tentative de connection.
Apparement je ne suis pas le seul dans ce cas (http://www.vpnforum.de/viewtopic.php?t=1032) mais je n'ai pas trouvé de solution...
Y aurait-il moyen de retirer l'update de 1.49->1.4.10 sans devoir tout réinstaller?
Qu'en est-il de faire un update manuel de openvpn et de la bibliothèque liblzo?
Moralité, et je l'apprends une fois de plus à mes dépends, toujours être patient avec les updates.
Merci d'avance à l'un ou l'autre grand gourou...