Re: [Openvpn-users] Problem with Tls mode setup.

  • Subject: Re: [Openvpn-users] Problem with Tls mode setup.
  • From: "Martijn Lievaart" <m@xxxxxxx>
  • Date: Wed, 19 Jan 2005 10:26:05 +0100 (CET)
Joshua Snyder said:
> I have problems setting up a Openvpn tunnel in Tls mode.  I have setup
> Openvpn with pre-shared keysmany times before and I have never had any
> problems.  But Tls mode just isn't working for me.  I think at this point
> that my problem has nothing to do with Openvpn, I think it is a OpenSsl
> issue.  But seeing how I followed the setup documents off of the website I
> figured I would ask here.  What I am getting now is the following.
> Jan 18 16:40:17 mouse openvpn-Tunnel1[19954]: VERIFY ERROR: depth=0,
> error=unable to get local issuer certificate:
> /C=US/ST=Indiana/O=FoxComputers/CN=Josh.Snyder
> Jan 18 16:40:17 mouse openvpn-Tunnel1[19954]: TLS_ERROR: BIO read
> tls_read_plaintext error: error:14090086:SSL
> routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed

I had similar problems when the certificates and keys where transfered
through Outlook. Both as attachments or inline, somehow Outlook managed to
munge something in the contents of the certificates and/or keys.
Downloading the exact same mail with webmail solved the problem. We now
zip everything we send to clients, this also solves the problem.

I don't know if this is your problem, but it sounds exactly the same.


