Re: easy-rsa

Antonio Quartulli <[email protected]>
Newsgroups gmane.network.openvpn.user
Message-ID <[email protected]>
Hi,

On 28/12/2023 21:15, Richard Couture wrote:

the following is the actual reason for clients to not be able to connect:

> 2023-12-28 14:01:01 187.251.133.221:1194 VERIFY ERROR: depth=0, 
> error=CRL signature failure: C=MX, ST=Jalisco, L=Tlaquepaque, O=Vame 
> Vehiculos, CN=rrc, [email protected], serial=7
> 2023-12-28 14:01:01 187.251.133.221:1194 OpenSSL: error:0A000086:SSL 
> routines::certificate verify failed
> 2023-12-28 14:01:01 187.251.133.221:1194 TLS_ERROR: BIO read 
> tls_read_plaintext error
> 2023-12-28 14:01:01 187.251.133.221:1194 TLS Error: TLS object -> 
> incoming plaintext read error
> 2023-12-28 14:01:01 187.251.133.221:1194 TLS Error: TLS handshake failed
> 2023-12-28 14:01:16 187.251.133.221:1194 VERIFY ERROR: depth=0, 
> error=CRL signature failure: C=MX, ST=Jalisco, L=Tlaquepaque, O=Vame 
> Vehiculos, CN=rrc, [email protected], serial=7
> 2023-12-28 14:01:16 187.251.133.221:1194 OpenSSL: error:0A000086:SSL 
> routines::certificate verify failed

did you create a new CRL after having created the new CA?
If the verification is failed, I can imagine two reasons:
1) CRL not signed with the current CA
2) CRL signed with a legacy algorithm which is not accepted by the more 
recent OpenSSL.


Regards,


-- 
Antonio Quartulli
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.