No server certificate verification method has been enabled

This forum is for all inquiries relating to the installation of OpenVPN from source and with binaries.

Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech

Forum rules
Please visit (and READ) the OpenVPN HowTo http://openvpn.net/howto prior to asking any questions in here!
Post Reply
nerode
OpenVpn Newbie
Posts: 1
Joined: Sat Mar 12, 2016 11:48 am

No server certificate verification method has been enabled

Post by nerode » Sat Mar 12, 2016 2:15 pm

Please can anybody help me. I have no experience with VPN at all.

I have installed OpenVPN 2.3.10 on Windows7 (server), Windows 10 (client).
I have disabled Firewall on server.
But there is no VPN Connection.

Server configuration:

# certificate
ca "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\ca.crt"
cert "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\OpenVPN-OB.crt"
key "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\OpenVPN-OB.key"
dh "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\dh1024.pem"

# Server
local 192.168.2.20
port 1194
proto udp
dev tun
server 10.18.14.0 255.255.255.0
ifconfig-pool-persist ipp.txt
comp-lzo
persist-key
persist-tun
keepalive 10 120

# Log
status "C:\\Program Files\\OpenVPN\\log\\openvpn-status.log"
log "C:\\Program Files\\OpenVPN\\log\\openvpn.log"
log-append "C:\\Program Files\\OpenVPN\\log\\openvpn.log"
verb 3

Client configuration:

# certificate
ca "C:\\Program Files\\OpenVPN\\config\\ca.crt"
cert "C:\\Program Files\\OpenVPN\\config\\Client1.crt"
key "C:\\Program Files\\OpenVPN\\config\\Client1.key"

# Client-Setup
client
dev tun #tap
proto udp
remote x.x.x.x 1194 #Hostname
resolv-retry infinite
nobind
persist-key
persist-tun
#route-metric 512
#route 0.0.0.0 0.0.0.0
comp-lzo
verb 3


And the error:

Sat Mar 12 14:50:09 2016 OpenVPN 2.3.10 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on Feb 1 2016
Sat Mar 12 14:50:09 2016 Windows version 6.2 (Windows 8 or greater)
Sat Mar 12 14:50:09 2016 library versions: OpenSSL 1.0.1r 28 Jan 2016, LZO 2.09
Enter Management Password:
Sat Mar 12 14:50:09 2016 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Sat Mar 12 14:50:09 2016 Need hold release from management interface, waiting...
Sat Mar 12 14:50:09 2016 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Sat Mar 12 14:50:10 2016 MANAGEMENT: CMD 'state on'
Sat Mar 12 14:50:10 2016 MANAGEMENT: CMD 'log all on'
Sat Mar 12 14:50:10 2016 MANAGEMENT: CMD 'hold off'
Sat Mar 12 14:50:10 2016 MANAGEMENT: CMD 'hold release'
Sat Mar 12 14:50:10 2016 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Sat Mar 12 14:50:10 2016 MANAGEMENT: Client disconnected
Sat Mar 12 14:50:10 2016 Cannot load certificate file C:\Program Files\OpenVPN\config\Client1.crt: error:0906D06C:PEM routines:PEM_read_bio:no start line: error:140AD009:SSL routines:SSL_CTX_use_certificate_file:PEM lib
Sat Mar 12 14:50:10 2016 Exiting due to fatal error


Many thanks!

User avatar
Traffic
OpenVPN Protagonist
Posts: 4066
Joined: Sat Aug 09, 2014 11:24 am

Re: No server certificate verification method has been enabl

Post by Traffic » Sat Mar 12, 2016 3:25 pm

nerode wrote:WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info
See the URL ..
nerode wrote:Cannot load certificate file C:\Program Files\OpenVPN\config\Client1.crt: error:0906D06C:PEM routines:PEM_read_bio:no start line: error
Check your client certificate is correct ..

Post Reply