Page 1 of 1

Nexus 5 Certificate verification failed

Posted: Fri May 09, 2014 11:40 am
by kQLAeQ
Getting the following error when attempting to connect:
OpenVPN server certificate verification failed : PolarSSL: SSL read error : X509 - Certifcate verification failed, e.g. CRL, CA or signature check failed
Log shows:
VERIFY FAIL CERT_NOT_TRUSTED : depeth=1
(Can't find where to copy the log from.)
Server is OpenVPN on Ubuntu Trusty.
The same certificates (server and client) work fine (and same config except TAP settings for windows) with OpenVPN client under Window 8.1.

Any ideas?

Re: Nexus 5 Certificate verification failed

Posted: Tue May 20, 2014 3:15 pm
by Guest
The same problem.
OpenVPN Connect 1.1.14 (build 56)
Probably the problem has arisen after updating (the previous version worked fine)

Re: Nexus 5 Certificate verification failed

Posted: Tue May 20, 2014 3:43 pm
by kQLAeQ
I tried "OpenVPN for Android" instead (https://play.google.com/store/apps/deta ... kt.openvpn) and that appears to work fine. Although I haven't done much testing with it.

Re: Nexus 5 Certificate verification failed

Posted: Tue May 20, 2014 8:23 pm
by jamesyonan
kQLAeQ,

OpenVPN Connect 1.1.14 (build 56) does include a PolarSSL update to 1.3.7.

If you can email additional details such as the problem certificate chain on the server side to our support email at android@openvpn.net, we will investigate further.

Thanks,
James

Re: Nexus 5 Certificate verification failed

Posted: Wed May 21, 2014 8:05 am
by kQLAeQ
Thanks. I'll give it another try in a week or so. My Nexus 5 stop charging, so I'm waiting for warranty replacement.

Re: Nexus 5 Certificate verification failed

Posted: Wed May 21, 2014 6:51 pm
by panik105
Hi,

Similar issue here since updating to App-Version 1.1.4
Clients: Nexus4 and Nexus7
Server: Debian Wheezy (OpenVpn 2.2.1)
key-,crt- and crl-files created using easy-rsa coming with that version.
Used to work on a daily base for several month.
Nothing changed except the Android-App.
Other App "OpenVPN for Android" still works with same keys.
ErrorMessage: OpenVPN core error : PolarSSL: error parsing CRL :
X509 The CRT/CRL/CSR format is invalid, e.g. different type expected
When removing the crl-verify from the config, it seems to work.

Bye..
Michael

Re: Nexus 5 Certificate verification failed

Posted: Thu May 22, 2014 8:02 am
by pjbakker
Hi,

In order to track down the underlying issue I'd like to ask anyone with a key, crt, crl combination that works with the old version and not with the new version to share it with us at "support at polarssl dot org".. If you do send it to us, please put it in a tarball / zip and do not use it for secure communication again and generate a new set to work with..

Thanks in advance and with your help we hope to be able to track this down real soon!

Paul Bakker
Lead Maintainer PolarSSL.

Re: Nexus 5 Certificate verification failed

Posted: Mon Jun 02, 2014 9:38 am
by sophitus
Hello

I have the same problem with the new OpenVPN connect 1.1.12. Certificate cannot be verified on Android.

With OpenVPN connect 0.6.11 from my backup I have no problem.

I use TLS-AUTH key, CA and Client-Certs but no CRL. The whole config works fine from iOS devices!

Re: Nexus 5 Certificate verification failed

Posted: Wed Jun 18, 2014 1:37 pm
by digital0
pjbakker wrote:In order to track down the underlying issue I'd like to ask anyone with a key, crt, crl combination that works with the old version and not with the new version to share it with us at "support at polarssl dot org".. If you do send it to us, please put it in a tarball / zip and do not use it for secure communication again and generate a new set to work with..
I sent an email with a link to a cert as requested.

Re: Nexus 5 Certificate verification failed

Posted: Wed Jun 25, 2014 8:11 am
by mesa57
Any news on this subject ?

Re: Nexus 5 Certificate verification failed

Posted: Wed Jun 25, 2014 10:17 am
by digital0
It will be fixed in a next PolarSSL 1.3.8 release. Then OpenVPN Connect will have to release a new version as well.

Re: Nexus 5 Certificate verification failed

Posted: Wed Jun 25, 2014 12:15 pm
by mesa57
Ok, thank you for the reply (and the fix) :)

Re: Nexus 5 Certificate verification failed

Posted: Fri Jul 11, 2014 9:04 pm
by nbr23
PolarSSL 1.3.8 was just released :)
https://github.com/polarssl/polarssl/bl ... /ChangeLog

Hopefully the OPenVPN Connect app will be updated soon!

Re: Nexus 5 Certificate verification failed

Posted: Mon Oct 13, 2014 11:12 am
by michael@dacova.co.uk
Same issue with the New S5, anyone know when the update will happen

Re: Nexus 5 Certificate verification failed

Posted: Tue Dec 30, 2014 9:32 am
by digital0
Could you please release a new version with updated PolarSSL?

Re: Nexus 5 Certificate verification failed

Posted: Fri Jan 02, 2015 11:01 am
by michael@dacova.co.uk
same issue on a Acer 4.4.4 tablet any updates ? or has any one have a work around

Re: Nexus 5 Certificate verification failed

Posted: Thu Jan 08, 2015 4:08 pm
by digital0
Workaround would be to use an older version. Just download apk file by searching google OpenVPN Connect 1.1.13

Re: Nexus 5 Certificate verification failed

Posted: Thu Jan 08, 2015 4:52 pm
by michael@dacova.co.uk
digital0 wrote:Workaround would be to use an older version. Just download apk file by searching google OpenVPN Connect 1.1.13
thanks.