Nexus 5 Certificate verification failed

Official client software for OpenVPN Access Server and OpenVPN Cloud.
Post Reply
kQLAeQ
OpenVpn Newbie
Posts: 3
Joined: Fri May 09, 2014 11:30 am

Nexus 5 Certificate verification failed

Post by kQLAeQ » Fri May 09, 2014 11:40 am

Getting the following error when attempting to connect:
OpenVPN server certificate verification failed : PolarSSL: SSL read error : X509 - Certifcate verification failed, e.g. CRL, CA or signature check failed
Log shows:
VERIFY FAIL CERT_NOT_TRUSTED : depeth=1
(Can't find where to copy the log from.)
Server is OpenVPN on Ubuntu Trusty.
The same certificates (server and client) work fine (and same config except TAP settings for windows) with OpenVPN client under Window 8.1.

Any ideas?

Guest
OpenVpn Newbie
Posts: 1
Joined: Tue May 20, 2014 3:07 pm

Re: Nexus 5 Certificate verification failed

Post by Guest » Tue May 20, 2014 3:15 pm

The same problem.
OpenVPN Connect 1.1.14 (build 56)
Probably the problem has arisen after updating (the previous version worked fine)

kQLAeQ
OpenVpn Newbie
Posts: 3
Joined: Fri May 09, 2014 11:30 am

Re: Nexus 5 Certificate verification failed

Post by kQLAeQ » Tue May 20, 2014 3:43 pm

I tried "OpenVPN for Android" instead (https://play.google.com/store/apps/deta ... kt.openvpn) and that appears to work fine. Although I haven't done much testing with it.

User avatar
jamesyonan
OpenVPN Inc.
Posts: 169
Joined: Thu Jan 24, 2013 12:13 am

Re: Nexus 5 Certificate verification failed

Post by jamesyonan » Tue May 20, 2014 8:23 pm

kQLAeQ,

OpenVPN Connect 1.1.14 (build 56) does include a PolarSSL update to 1.3.7.

If you can email additional details such as the problem certificate chain on the server side to our support email at android@openvpn.net, we will investigate further.

Thanks,
James

kQLAeQ
OpenVpn Newbie
Posts: 3
Joined: Fri May 09, 2014 11:30 am

Re: Nexus 5 Certificate verification failed

Post by kQLAeQ » Wed May 21, 2014 8:05 am

Thanks. I'll give it another try in a week or so. My Nexus 5 stop charging, so I'm waiting for warranty replacement.

panik105
OpenVpn Newbie
Posts: 1
Joined: Mon May 19, 2014 9:58 pm

Re: Nexus 5 Certificate verification failed

Post by panik105 » Wed May 21, 2014 6:51 pm

Hi,

Similar issue here since updating to App-Version 1.1.4
Clients: Nexus4 and Nexus7
Server: Debian Wheezy (OpenVpn 2.2.1)
key-,crt- and crl-files created using easy-rsa coming with that version.
Used to work on a daily base for several month.
Nothing changed except the Android-App.
Other App "OpenVPN for Android" still works with same keys.
ErrorMessage: OpenVPN core error : PolarSSL: error parsing CRL :
X509 The CRT/CRL/CSR format is invalid, e.g. different type expected
When removing the crl-verify from the config, it seems to work.

Bye..
Michael

pjbakker
OpenVpn Newbie
Posts: 5
Joined: Thu Nov 15, 2012 12:08 pm
Contact:

Re: Nexus 5 Certificate verification failed

Post by pjbakker » Thu May 22, 2014 8:02 am

Hi,

In order to track down the underlying issue I'd like to ask anyone with a key, crt, crl combination that works with the old version and not with the new version to share it with us at "support at polarssl dot org".. If you do send it to us, please put it in a tarball / zip and do not use it for secure communication again and generate a new set to work with..

Thanks in advance and with your help we hope to be able to track this down real soon!

Paul Bakker
Lead Maintainer PolarSSL.

sophitus
OpenVpn Newbie
Posts: 7
Joined: Mon Jun 02, 2014 9:32 am

Re: Nexus 5 Certificate verification failed

Post by sophitus » Mon Jun 02, 2014 9:38 am

Hello

I have the same problem with the new OpenVPN connect 1.1.12. Certificate cannot be verified on Android.

With OpenVPN connect 0.6.11 from my backup I have no problem.

I use TLS-AUTH key, CA and Client-Certs but no CRL. The whole config works fine from iOS devices!

digital0
OpenVpn Newbie
Posts: 5
Joined: Fri Jan 18, 2013 3:30 pm

Re: Nexus 5 Certificate verification failed

Post by digital0 » Wed Jun 18, 2014 1:37 pm

pjbakker wrote:In order to track down the underlying issue I'd like to ask anyone with a key, crt, crl combination that works with the old version and not with the new version to share it with us at "support at polarssl dot org".. If you do send it to us, please put it in a tarball / zip and do not use it for secure communication again and generate a new set to work with..
I sent an email with a link to a cert as requested.

mesa57
OpenVpn Newbie
Posts: 2
Joined: Wed Jun 26, 2013 6:29 pm

Re: Nexus 5 Certificate verification failed

Post by mesa57 » Wed Jun 25, 2014 8:11 am

Any news on this subject ?

digital0
OpenVpn Newbie
Posts: 5
Joined: Fri Jan 18, 2013 3:30 pm

Re: Nexus 5 Certificate verification failed

Post by digital0 » Wed Jun 25, 2014 10:17 am

It will be fixed in a next PolarSSL 1.3.8 release. Then OpenVPN Connect will have to release a new version as well.

mesa57
OpenVpn Newbie
Posts: 2
Joined: Wed Jun 26, 2013 6:29 pm

Re: Nexus 5 Certificate verification failed

Post by mesa57 » Wed Jun 25, 2014 12:15 pm

Ok, thank you for the reply (and the fix) :)

nbr23
OpenVpn Newbie
Posts: 1
Joined: Fri Jul 11, 2014 9:03 pm

Re: Nexus 5 Certificate verification failed

Post by nbr23 » Fri Jul 11, 2014 9:04 pm

PolarSSL 1.3.8 was just released :)
https://github.com/polarssl/polarssl/bl ... /ChangeLog

Hopefully the OPenVPN Connect app will be updated soon!

michael@dacova.co.uk
OpenVpn Newbie
Posts: 3
Joined: Mon Oct 13, 2014 11:11 am

Re: Nexus 5 Certificate verification failed

Post by michael@dacova.co.uk » Mon Oct 13, 2014 11:12 am

Same issue with the New S5, anyone know when the update will happen

digital0
OpenVpn Newbie
Posts: 5
Joined: Fri Jan 18, 2013 3:30 pm

Re: Nexus 5 Certificate verification failed

Post by digital0 » Tue Dec 30, 2014 9:32 am

Could you please release a new version with updated PolarSSL?

michael@dacova.co.uk
OpenVpn Newbie
Posts: 3
Joined: Mon Oct 13, 2014 11:11 am

Re: Nexus 5 Certificate verification failed

Post by michael@dacova.co.uk » Fri Jan 02, 2015 11:01 am

same issue on a Acer 4.4.4 tablet any updates ? or has any one have a work around

digital0
OpenVpn Newbie
Posts: 5
Joined: Fri Jan 18, 2013 3:30 pm

Re: Nexus 5 Certificate verification failed

Post by digital0 » Thu Jan 08, 2015 4:08 pm

Workaround would be to use an older version. Just download apk file by searching google OpenVPN Connect 1.1.13

michael@dacova.co.uk
OpenVpn Newbie
Posts: 3
Joined: Mon Oct 13, 2014 11:11 am

Re: Nexus 5 Certificate verification failed

Post by michael@dacova.co.uk » Thu Jan 08, 2015 4:52 pm

digital0 wrote:Workaround would be to use an older version. Just download apk file by searching google OpenVPN Connect 1.1.13
thanks.

Post Reply