Jump to content
Not connected, Your IP: 216.73.216.49

Leaderboard


Popular Content

Showing content with the highest reputation on 10/07/21 in all areas

  1. 4 points
    Hello! The current state of play as well as important clarifications. The issue occurs only in those OpenVPN clients linked against OpenSSL 3 and only to some of our users, see below Since 2017, our system generates CRT signed with SHA512 algorithm. Previously they were signed with SHA1. Regeneration of old CRT is not triggered and forced by us automatically, because it would invalidate any previous OVPN configuration file out there and lock out the user who does not follow our forum, notification e-mails etc. @rprimus you have a client CRT (user.crt) dated 2015. You and anybody else using pre-2017 user certificates: please go to your "Client Area" > "Devices" menu, renew your cert/key pair, re-download your OVPN configuration files from the Configuration Generator, use them and you will be fine. (*) The problem has never been caused by the CA certificate. Replacing the CA.crt is not mandatory, it just avoids warning message (that you can safely ignore and has nothing to do with the main issue of this thread) you may meet in Eddie Android edition, Hummingbird and Bluetit. Anyway, now even ca.crt is SHA512 signed, so you will not get anymore the mentioned warning (*) Yellow rows show certificates which use a signature based on a deprecated for security reasons hash algorithm (SHA1). They are still here to ensure backward compatibility, because we can't know whether you still use them in generated profiles. However, future OpenVPN versions might not allow them anymore. Click 'Renew' or 'Delete' to resolve the issue. After that, re-generate profile(s) with our Configuration Generator. If you run our client software Eddie, you just need to log your account out and in again from the main window. Kind regards
  2. 2 points
    Thu Oct 7 07:49:32 BST 2021 @Clodo > If you have this issue, please try to download this file: https://airvpn.org/static/keys/ca512.crt and replace CA crt in "OpenVPN for Android" config. Have verified the new signature: Signature Algorithm: sha512WithRSAEncryption however, still getting the error: OpenSSL: error:0A00018E:SSL routines::ca md too weak It appears that this is being generated from the embedded client cert: Signature Algorithm: sha1WithRSAEncryption Ref: https://github.com/schwabe/ics-openvpn/issues/1374#issuecomment-935944072 Update: from schwabe: "As for the CA. OpenSSL might also be upset by the CA sent by the server and not just the one used in the profile itself."
  3. 1 point
    Primarily a question to @Qpb22uGL and @kmartinez237, they originally reported this.
  4. 1 point
    zombie1982

    Eddie Desktop 2.21 beta released

    NICE
×
×
  • Create New...