Please Help: "No server certificate verification method"
Posted: Tue Apr 19, 2011 1:52 pm
Hello,
I have OpenVZ Virtuozzo on Centos 5.5..
Everything was already setup and working, from time to time I got Iptables wiped out
(cleaned for some reason),
so I have to run script to set IP tables again (firewall script).. This time in the morning I have same problem
OpenVPN stop working so, I login to the Server run firewall script to setup IP Tables, then
restart VPN service.. Now I'm able to establish connection but got Error:
"WARNING: No server certificate verification method has been enabled." while login.
I checked all the files Certificates and Key files everything in place as usual
I DIDN'T Touched ANYTHING.. What could cause this??? Here is the Log File
==========================================
Tue Apr 19 09:13:57 2011 OpenVPN 2.1.4 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 8 2010
Tue Apr 19 09:13:57 2011 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Tue Apr 19 09:13:57 2011 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Tue Apr 19 09:13:57 2011 LZO compression initialized
Tue Apr 19 09:13:57 2011 Control Channel MTU parms [ L:1558 D:138 EF:38 EB:0 ET:0 EL:0 ]
Tue Apr 19 09:13:57 2011 Socket Buffers: R=[8192->8192] S=[8192->8192]
Tue Apr 19 09:13:57 2011 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Apr 19 09:13:57 2011 Local Options hash (VER=V4): '66096c33'
Tue Apr 19 09:13:57 2011 Expected Remote Options hash (VER=V4): '691e95c7'
Tue Apr 19 09:13:57 2011 UDPv4 link local: [undef]
Tue Apr 19 09:13:57 2011 UDPv4 link remote: 20.20.16.20:1194
Tue Apr 19 09:13:57 2011 TLS: Initial packet from 20.20.16.20:1194, sid=425c6dfa 1f19934c
Tue Apr 19 09:14:00 2011 VERIFY OK: depth=1, /C=US/ST=NY/L=MewYork/O=Net***.inc/OU=prod/CN=skyvpn/name=Alex23/emailAddress=web***@alt***.org
Tue Apr 19 09:14:00 2011 VERIFY OK: depth=0, /C=US/ST=NY/L=NewYork/O=Net***.inc/OU=prod/CN=skyvpn/name=Alex23/emailAddress=web***@alt***.org
Tue Apr 19 09:14:01 2011 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Apr 19 09:14:01 2011 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Apr 19 09:14:01 2011 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Apr 19 09:14:01 2011 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Apr 19 09:14:01 2011 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Tue Apr 19 09:14:01 2011 [skyvpn] Peer Connection Initiated with 20.20.16.20:1194
Tue Apr 19 09:14:03 2011 SENT CONTROL [skyvpn]: 'PUSH_REQUEST' (status=1)
Tue Apr 19 09:14:03 2011 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,route 10.8.0.1,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.6 10.8.0.5'
Tue Apr 19 09:14:03 2011 OPTIONS IMPORT: timers and/or timeouts modified
Tue Apr 19 09:14:03 2011 OPTIONS IMPORT: --ifconfig/up options modified
Tue Apr 19 09:14:03 2011 OPTIONS IMPORT: route options modified
Tue Apr 19 09:14:03 2011 ROUTE default_gateway=192.168.1.1
Tue Apr 19 09:14:03 2011 TAP-WIN32 device [Local Area Connection 4] opened: \\.\Global\{33029ADD-46AC-4F3A-B775-C9238B12FD9B}.tap
Tue Apr 19 09:14:03 2011 TAP-Win32 Driver Version 9.7
Tue Apr 19 09:14:03 2011 TAP-Win32 MTU=1500
Tue Apr 19 09:14:03 2011 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.8.0.6/255.255.255.252 on interface {33029ADD-46AC-4F3A-B775-C9238B12FD9B} [DHCP-serv: 10.8.0.5, lease-time: 31536000]
Tue Apr 19 09:14:03 2011 Successful ARP Flush on interface [2] {33029ADD-46AC-4F3A-B775-C9238B12FD9B}
Tue Apr 19 09:14:08 2011 TEST ROUTES: 2/2 succeeded len=1 ret=1 a=0 u/d=up
Tue Apr 19 09:14:08 2011 C:\WINDOWS\system32\route.exe ADD 205.209.162.21 MASK 255.255.255.255 192.168.1.1
Tue Apr 19 09:14:08 2011 Route addition via IPAPI succeeded [adaptive]
Tue Apr 19 09:14:08 2011 C:\WINDOWS\system32\route.exe ADD 0.0.0.0 MASK 128.0.0.0 10.8.0.5
Tue Apr 19 09:14:08 2011 Route addition via IPAPI succeeded [adaptive]
Tue Apr 19 09:14:08 2011 C:\WINDOWS\system32\route.exe ADD 128.0.0.0 MASK 128.0.0.0 10.8.0.5
Tue Apr 19 09:14:08 2011 Route addition via IPAPI succeeded [adaptive]
Tue Apr 19 09:14:08 2011 C:\WINDOWS\system32\route.exe ADD 10.8.0.1 MASK 255.255.255.255 10.8.0.5
Tue Apr 19 09:14:08 2011 Route addition via IPAPI succeeded [adaptive]
Tue Apr 19 09:14:08 2011 Initialization Sequence Completed
=======================================================
Connection with the VPN server get established, but I cannot browse anything on the web..
What should I check?
Please help.
Thank you.
I have OpenVZ Virtuozzo on Centos 5.5..
Everything was already setup and working, from time to time I got Iptables wiped out
(cleaned for some reason),
so I have to run script to set IP tables again (firewall script).. This time in the morning I have same problem
OpenVPN stop working so, I login to the Server run firewall script to setup IP Tables, then
restart VPN service.. Now I'm able to establish connection but got Error:
"WARNING: No server certificate verification method has been enabled." while login.
I checked all the files Certificates and Key files everything in place as usual
I DIDN'T Touched ANYTHING.. What could cause this??? Here is the Log File
==========================================
Tue Apr 19 09:13:57 2011 OpenVPN 2.1.4 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 8 2010
Tue Apr 19 09:13:57 2011 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Tue Apr 19 09:13:57 2011 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Tue Apr 19 09:13:57 2011 LZO compression initialized
Tue Apr 19 09:13:57 2011 Control Channel MTU parms [ L:1558 D:138 EF:38 EB:0 ET:0 EL:0 ]
Tue Apr 19 09:13:57 2011 Socket Buffers: R=[8192->8192] S=[8192->8192]
Tue Apr 19 09:13:57 2011 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Apr 19 09:13:57 2011 Local Options hash (VER=V4): '66096c33'
Tue Apr 19 09:13:57 2011 Expected Remote Options hash (VER=V4): '691e95c7'
Tue Apr 19 09:13:57 2011 UDPv4 link local: [undef]
Tue Apr 19 09:13:57 2011 UDPv4 link remote: 20.20.16.20:1194
Tue Apr 19 09:13:57 2011 TLS: Initial packet from 20.20.16.20:1194, sid=425c6dfa 1f19934c
Tue Apr 19 09:14:00 2011 VERIFY OK: depth=1, /C=US/ST=NY/L=MewYork/O=Net***.inc/OU=prod/CN=skyvpn/name=Alex23/emailAddress=web***@alt***.org
Tue Apr 19 09:14:00 2011 VERIFY OK: depth=0, /C=US/ST=NY/L=NewYork/O=Net***.inc/OU=prod/CN=skyvpn/name=Alex23/emailAddress=web***@alt***.org
Tue Apr 19 09:14:01 2011 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Apr 19 09:14:01 2011 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Apr 19 09:14:01 2011 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Apr 19 09:14:01 2011 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Apr 19 09:14:01 2011 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Tue Apr 19 09:14:01 2011 [skyvpn] Peer Connection Initiated with 20.20.16.20:1194
Tue Apr 19 09:14:03 2011 SENT CONTROL [skyvpn]: 'PUSH_REQUEST' (status=1)
Tue Apr 19 09:14:03 2011 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,route 10.8.0.1,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.6 10.8.0.5'
Tue Apr 19 09:14:03 2011 OPTIONS IMPORT: timers and/or timeouts modified
Tue Apr 19 09:14:03 2011 OPTIONS IMPORT: --ifconfig/up options modified
Tue Apr 19 09:14:03 2011 OPTIONS IMPORT: route options modified
Tue Apr 19 09:14:03 2011 ROUTE default_gateway=192.168.1.1
Tue Apr 19 09:14:03 2011 TAP-WIN32 device [Local Area Connection 4] opened: \\.\Global\{33029ADD-46AC-4F3A-B775-C9238B12FD9B}.tap
Tue Apr 19 09:14:03 2011 TAP-Win32 Driver Version 9.7
Tue Apr 19 09:14:03 2011 TAP-Win32 MTU=1500
Tue Apr 19 09:14:03 2011 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.8.0.6/255.255.255.252 on interface {33029ADD-46AC-4F3A-B775-C9238B12FD9B} [DHCP-serv: 10.8.0.5, lease-time: 31536000]
Tue Apr 19 09:14:03 2011 Successful ARP Flush on interface [2] {33029ADD-46AC-4F3A-B775-C9238B12FD9B}
Tue Apr 19 09:14:08 2011 TEST ROUTES: 2/2 succeeded len=1 ret=1 a=0 u/d=up
Tue Apr 19 09:14:08 2011 C:\WINDOWS\system32\route.exe ADD 205.209.162.21 MASK 255.255.255.255 192.168.1.1
Tue Apr 19 09:14:08 2011 Route addition via IPAPI succeeded [adaptive]
Tue Apr 19 09:14:08 2011 C:\WINDOWS\system32\route.exe ADD 0.0.0.0 MASK 128.0.0.0 10.8.0.5
Tue Apr 19 09:14:08 2011 Route addition via IPAPI succeeded [adaptive]
Tue Apr 19 09:14:08 2011 C:\WINDOWS\system32\route.exe ADD 128.0.0.0 MASK 128.0.0.0 10.8.0.5
Tue Apr 19 09:14:08 2011 Route addition via IPAPI succeeded [adaptive]
Tue Apr 19 09:14:08 2011 C:\WINDOWS\system32\route.exe ADD 10.8.0.1 MASK 255.255.255.255 10.8.0.5
Tue Apr 19 09:14:08 2011 Route addition via IPAPI succeeded [adaptive]
Tue Apr 19 09:14:08 2011 Initialization Sequence Completed
=======================================================
Connection with the VPN server get established, but I cannot browse anything on the web..
What should I check?
Please help.
Thank you.