Re: Question on a sporadic OpenVPN errors:"AEAD Decrypt error", "tls-crypt unwrap error"

Gert Doering <[email protected]> Wed, 7 Jan 2026 17:06:07 +0100
Newsgroups gmane.network.openvpn.user
Message-ID <[email protected]>
--===============6795499340639477652==
Content-Type: multipart/signed; micalg=pgp-sha256;
	protocol="application/pgp-signature"; boundary="FI9XnRFnBbrVjwyv"
Content-Disposition: inline


--FI9XnRFnBbrVjwyv
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi,

On Wed, Jan 07, 2026 at 01:24:30PM +0000, Stefan Grauvogl wrote:
> tls-version-min 1.2
> tls-ciphersuites TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_=
AES_128_GCM_SHA256:TLS_AES_128_CCM_SHA256
> tls-cipher ECDHE+AESGCM:ECDHE+AESCCM:DHE+AESGCM:DHE+AESCCM:!AESCCM8
> tls-groups X25519:brainpoolP256r1:secp256r1:X448:brainpoolP384r1:secp384r=
1:brainpoolP512r1:secp521r1
>=20
> data-ciphers CHACHA20-POLY1305:AES-256-GCM
> data-ciphers-fallback AES-256-GCM
>
> auth sha512

Don't.

Unless you have a very specific need, and understand the full implications,
do not configure anything here.  OpenVPN and OpenSSL defaults are likely
good enough, and worse, in 10 years from now on, your configs are likely
overtaken by time and creating compatibility problems.

> lport 2196

Don't, unless there is a very specific need.

(Having a restarting client on the same port as a previous client=20
connection is known to upset the server.  Sometimes.  Depending on
the current TLS state in the server... nobody has really had time to
dig into this, so the recommendation is to just use dynamic ports on
the client)

gert

--=20
"If was one thing all people took for granted, was conviction that if you=
=20
 feed honest figures into a computer, honest figures come out. Never doubte=
d=20
 it myself till I met a computer with a sense of humor."
                             Robert A. Heinlein, The Moon is a Harsh Mistre=
ss

Gert Doering - Munich, Germany                             [email protected]=
=2Ede

--FI9XnRFnBbrVjwyv
Content-Type: application/pgp-signature; name=signature.asc

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCAAdFiEEti5qK05WVwt73GvgHYKe/spWKBIFAmlehGwACgkQHYKe/spW
KBI0MAwAoXhruUEHy8uYXfG1ZHDElTsLoCFYorNNCxomlMw2JObdKMlSqXcKdhCM
1VX1Z8/+P597ZiYmULAQXDwuoWee2j/xuvQgGCUMotCCT8u2PP49Klass2Zxg3Mu
74hNyKoiOeOCL9lFibS1BM94caQ+imuBtqKoFu4jp0bWXWIf5DEngQaD75KVt/5j
VBCUTvkEQdDlQCrxdJh5lCbWlbMCV1ajBIHggxkrxZvt+5DazQKYLZnI3ivOHa7a
P5/cCtRLYI/fLTYWjyW+FSIIKU+/N89s1tncPz7dA4lEhK7C3mNtrqrOqfz2Pi6/
Lv4J4XHw9khHNQIf2DDSCf9zdDv36speN7OAXemYf95iaytrPH9bJGvqfzvWk0IP
GaK0Pcasu2E/rhVLvsodeiXAGM3D4Nm4mV5VsiwRt5tKbO4msIa+WUV8h4eN3JnA
m71E4RmhYEsESwutJrS9CUolZx42PcrPExXvt14/mKPcSfr2GosaruCD04+wgKXt
hb7A468I
=UrlF
-----END PGP SIGNATURE-----

--FI9XnRFnBbrVjwyv--


--===============6795499340639477652==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============6795499340639477652==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

--===============6795499340639477652==--