From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.1 (2015-04-28) on sa.local.altlinux.org X-Spam-Level: X-Spam-Status: No, score=-2.0 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FROM autolearn=ham autolearn_force=no version=3.4.1 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=mail.ru; s=mail2; h=Content-Transfer-Encoding:Content-Type:In-Reply-To:MIME-Version:Date:Message-ID:References:To:From:Subject; bh=gfNhFVTXLREd8FwEwPyyQPCnuY4CoHCaLzH9zM3ZogQ=; b=kxhIAlRF8rtgpmf7wbzVXxTD2cfqZ+7/aJTu7dXSMIxnJRToq18tEnGV8JQkTeQX4sdxqMPc74bMQ1W3KwGBvgFTEnO4iuD9sCHIDEY+5wkf/LCIOKzTJIyc0NwO3UDBtv80ODQU28hNGa1WY9Jw1ewEutzKUX7N7X/BOiKgaDk=; From: Vladimir Karpinsky To: sysadmins@lists.altlinux.org References: Message-ID: <6ee8cbc3-79f3-7226-67b6-cf5d6c9168c8@mail.ru> Date: Thu, 7 Jun 2018 23:27:16 +0300 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.8.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: Russian-English Content-Transfer-Encoding: 8bit Authentication-Results: smtp33.i.mail.ru; auth=pass smtp.auth=vkarpinsky@mail.ru smtp.mailfrom=vkarpinsky@mail.ru X-7FA49CB5: 0D63561A33F958A5204E6D6068E9651467D26E417A9D15A1E2306354423C37DD725E5C173C3A84C3F6A27782D0527605B20CC0A9DB2D90466436AE5DD6441DC7C4224003CC836476C0CAF46E325F83A50BF2EBBBDD9D6B0FF045C6A0F83C8214574AF45C6390F7469DAA53EE0834AAEE X-Mailru-Sender: 47CC51BD8988F12311C17B824601663D9E97330F63881B92A364B0277E3392B3AF38E0997304DB7E189086648D43AF80C77752E0C033A69E9629CB05D30F4213116F0678BC710751AE208404248635DF X-Mras: OK Subject: Re: [Sysadmins] OpenVPN cert error X-BeenThere: sysadmins@lists.altlinux.org X-Mailman-Version: 2.1.12 Precedence: list Reply-To: ALT Linux sysadmins' discussion List-Id: ALT Linux sysadmins' discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 07 Jun 2018 20:27:18 -0000 Archived-At: List-Archive: 07.06.2018 23:10, Vladimir Karpinsky пишет: > Здравствуйте! > > При обновлении виндового клиента OpenVPN до версии 2.4.6 он перестал > подключаться с руганью: > OpenSSL: error:140AB18E:SSL routines:SSL_CTX_use_certificate:ca md too weak > > На сервере (Альт p8) перегенерировал через альтератор сертификат, но > безрезультатно. В /etc/openssl/openssl.cnf написано: > > default_md      = sha256 > > М.б. альтератор откуда-то из другого места конфиг читает? Нашёл md5 в /usr/share/alterator-ca/CA.cnf, поменял на sha256: default_md = sha256 Теперь получаю: VERIFY ERROR: depth=0, error=CA signature digest algorithm too weak: C=RU, ... OpenSSL: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed -- С уважением, Владимир.