Zastoff
Very Senior Member
Updated the VPN-client on my android phone today (OpenVPN for Android by Arne Schwabe)
Now when i try to connect to the vpn-server on my AX-88u i get the following
Any advice on how to solve?
Edit:
Installed OpenVPN Connect app and tested and it works, But would like to use the other one since Openvpn Connect do not seem to support CHACHA20-POLY1305
Edit1: added a bit more from log
Edit2: Looks like it will be solved with the next firmware release
Edit3: From 386.4_alpha2 and forward this is fixed, VPN-Servers need to be set to default and reconfigured to get the new cert and keys.
Now when i try to connect to the vpn-server on my AX-88u i get the following
Code:
2021-10-05 15:28:54 OpenVPN 2.5-icsopenvpn [git:icsopenvpn/v0.7.25-0-g4a9cbd88] arm64-v8a [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] built on Oct 4 2021
2021-10-05 15:28:54 library versions: OpenSSL 3.0.0 7 sep 2021, LZO 2.10
2021-10-05 15:28:54 MANAGEMENT: Connected to management server at /data/user/0/de.blinkt.openvpn/cache/mgmtsocket
2021-10-05 15:28:54 MANAGEMENT: CMD 'version 3'
2021-10-05 15:28:54 MANAGEMENT: CMD 'hold release'
2021-10-05 15:28:54 MANAGEMENT: CMD 'bytecount 2'
2021-10-05 15:28:54 MANAGEMENT: CMD 'username 'Auth' ******'
2021-10-05 15:28:54 MANAGEMENT: CMD 'state on'
2021-10-05 15:28:54 MANAGEMENT: CMD 'password [...]'
2021-10-05 15:28:54 MANAGEMENT: CMD 'proxy NONE'
2021-10-05 15:28:55 OpenSSL: error:0A00018E:SSL routines::ca md too weak
2021-10-05 15:28:55 OpenSSL reported a certificate with a weak hash, please the in app FAQ about weak hashes
2021-10-05 15:28:55 MGMT: Got unrecognized command>FATAL:Cannot load inline certificate file
2021-10-05 15:28:55 MANAGEMENT: Client disconnected
2021-10-05 15:28:55 Cannot load inline certificate file
2021-10-05 15:28:55 Exiting due to fatal error
2021-10-05 15:28:55 Process exited with exit value 1
Edit:
Installed OpenVPN Connect app and tested and it works, But would like to use the other one since Openvpn Connect do not seem to support CHACHA20-POLY1305
Edit1: added a bit more from log
Edit2: Looks like it will be solved with the next firmware release
easy-rsa: re-apply patch to use SHA256 signatures (patch got lost wit… · RMerl/asuswrt-merlin.ng@cbae028
…h the 386 merge of upstream code)
github.com
Edit3: From 386.4_alpha2 and forward this is fixed, VPN-Servers need to be set to default and reconfigured to get the new cert and keys.
RSA-SHA256
Last edited: