Page 1 of 1

Another PolarSSL Issue

Posted: Mon Jun 27, 2016 8:46 pm
by jpk79
Since updating to the latest OpenVPN app on iOS (iPhone and iPad), version 1.0.7 build 199, I am unable to connect to my OpenVPN server on PFSense (2.3.1 Release on SG 2440). The error I am getting is not exactly the same that it seems most others are having. Here is what I am getting:

2016-06-27 10:57:32 Client exception in transport_recv_excode: PolarSSL: SSL read error : SSL - Processing of the Certificate handshake message failed
2016-06-27 10:57:32 Client terminated, restarting in 2...

I have tried disabling "Minimum TLS version" in settings and also Force AES-CBC ciphersuites, which some had suggested on other sites, but this has not yielded any success. I am at a loss on what to fix in my certificate if that is truly the issue. Nothing changed on the server or client end other than the OpenVPN Connec version being updated via the App Store.

There is not much in the server log, just this:

Jun 27 10:57:32 openvpn 19617 192.168.198.8:50016 Connection reset, restarting
Jun 27 10:57:32 openvpn 19617 TCP connection established with [AF_INET]192.168.198.8:50016

Any suggestions from anyone? Thanks

Re: Another PolarSSL Issue

Posted: Mon Jun 27, 2016 8:49 pm
by TinCanTech
This may not be related but please see this thread:
viewtopic.php?f=36&t=21873

Re: Another PolarSSL Issue

Posted: Mon Jun 27, 2016 9:03 pm
by jpk79
TinCanTech wrote:This may not be related but please see this thread:
viewtopic.php?f=36&t=21873
Thanks...I am getting a different error and my cert seems fine.

Re: Another PolarSSL Issue

Posted: Sun Jul 03, 2016 6:14 pm
by jpk79
Any suggestions here? I haven't been able to connect in over a month now and there is no information on the internet about this specific error so I am at a loss on how to resolve this. The only thing that changed on my end was updating the app!

Re: Another PolarSSL Issue

Posted: Mon Jul 04, 2016 1:29 am
by jpk79
OK, this is now working thanks to the help of a guy on the pfsense forum. The issue was my certificate in my VPN Server had two problems 1) It was not a server cert 2) Did not have the same CN as my user cert. I fixed these and now it is working. Why it worked before, not sure.