From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.1 (2015-04-28) on sa.local.altlinux.org X-Spam-Level: X-Spam-Status: No, score=-3.3 required=5.0 tests=BAYES_00,RP_MATCHES_RCVD autolearn=ham autolearn_force=no version=3.4.1 Date: Thu, 5 Sep 2019 11:44:32 +0200 From: Konstantin Lepikhov To: ALT Linux sysadmins' discussion Message-ID: <20190905094432.GA5978@lks.home> References: <40808878-0e05-c465-f9f5-cb28d0e0598d@mail.ru> <20190904073644.GA32096@lks.home> <5e0e3e21-06db-7abe-22ff-e7ff13d73b27@mail.ru> <20190904091455.GA16790@lks.home> <65dccceb-68be-559d-9246-80c6db9bd799@mail.ru> <20190904122256.GA15130@lks.home> <0b7c7e02-0cfa-03ce-bd30-c87f4c6bab67@mail.ru> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <0b7c7e02-0cfa-03ce-bd30-c87f4c6bab67@mail.ru> X-Operation-System: ALT Sisyphus Sisyphus (unstable) (sisyphus) 5.2.0-lks-wks-alt0.3 User-Agent: Mutt/1.10.1 (2018-07-13) Subject: Re: [Sysadmins] p8 -> p9 X-BeenThere: sysadmins@lists.altlinux.org X-Mailman-Version: 2.1.12 Precedence: list Reply-To: ALT Linux sysadmins' discussion List-Id: ALT Linux sysadmins' discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 05 Sep 2019 09:44:40 -0000 Archived-At: List-Archive: Hi Vladimir! On 09/04/2019, at 03:58:22 PM you wrote: > Ой! Действительно. Но теперь идёт ошибка: > > 2019-09-04T15:51:54.397292+03:00 pullet openvpn[13691]: VERIFY ERROR: > depth=0, error=certificate signature failure: ... > 2019-09-04T15:51:54.397446+03:00 pullet openvpn[13691]: OpenSSL: > error:1416F086:SSL routines:tls_process_server_certificate:certificate > verify failed > 2019-09-04T15:51:54.397548+03:00 pullet openvpn[13691]: TLS_ERROR: BIO read > tls_read_plaintext error > 2019-09-04T15:51:54.397639+03:00 pullet openvpn[13691]: TLS Error: TLS > object -> incoming plaintext read error > 2019-09-04T15:51:54.397768+03:00 pullet openvpn[13691]: TLS Error: TLS > handshake failed Потому что md5 выпилен из libssl? Я не знаю, что там в сборке p9, если там возможность включить md5, как это сделано в RH через переменную окружения OPENSSL_ENABLE_MD5_VERIFY=1 -- WBR et al.