FreeBSD Bugzilla – Attachment 259767 Details for
Bug 286263
security/openvpn: requires legacy IP support for ovpn(4) DCO module to be operational
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
connection log
dco_noINET_error.txt (text/plain), 8.06 KB, created by
Marek Zarychta
on 2025-04-21 10:39:00 UTC
(
hide
)
Description:
connection log
Filename:
MIME Type:
Creator:
Marek Zarychta
Created:
2025-04-21 10:39:00 UTC
Size:
8.06 KB
patch
obsolete
>2025-04-21 10:10:52 us=133248 Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers. >2025-04-21 10:10:52 us=133376 Current Parameter Settings: >2025-04-21 10:10:52 us=133382 config = 'mzar.client.conf' >2025-04-21 10:10:52 us=133386 mode = 0 >2025-04-21 10:10:52 us=133389 show_ciphers = DISABLED >2025-04-21 10:10:52 us=133392 show_digests = DISABLED >2025-04-21 10:10:52 us=133395 show_engines = DISABLED >2025-04-21 10:10:52 us=133398 NOTE: --mute triggered... >2025-04-21 10:10:52 us=133408 288 variation(s) on previous 20 message(s) suppressed by --mute >2025-04-21 10:10:52 us=133412 OpenVPN 2.6.14 amd64-portbld-freebsd14.2 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD] [DCO] >2025-04-21 10:10:52 us=133419 library versions: OpenSSL 3.0.16 11 Feb 2025, LZO 2.10 >2025-04-21 10:10:52 us=133443 DCO version: FreeBSD 14.3-PRERELEASE #0 stable/14-n271136-9fe5566f9a8e: Sat Apr 19 11:34:55 CEST 2025 root@hamal.dom.potoki.eu:/usr/obj/usr/src/amd64.amd64/sys/MINTAKA6ONLY >2025-04-21 10:10:52 us=136328 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication >2025-04-21 10:10:52 us=136341 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication >2025-04-21 10:10:52 us=136463 Control Channel MTU parms [ mss_fix:0 max_frag:0 tun_mtu:1250 tun_max_mtu:0 headroom:126 payload:1600 tailroom:126 ET:0 ] >2025-04-21 10:10:52 us=138144 Data Channel MTU parms [ mss_fix:0 max_frag:0 tun_mtu:1500 tun_max_mtu:1600 headroom:136 payload:1768 tailroom:562 ET:0 ] >2025-04-21 10:10:52 us=138209 TCP/UDP: Preserving recently used remote address: [AF_INET6]2001:yyy:xxx::z:1194 >2025-04-21 10:10:52 us=138224 Socket Buffers: R=[42080->42080] S=[9216->9216] >2025-04-21 10:10:52 us=138229 UDPv6 link local: (not bound) >2025-04-21 10:10:52 us=138233 UDPv6 link remote: [AF_INET6]2001:yyy:xxx::z:1194 >2025-04-21 10:10:52 us=152520 TLS: Initial packet from [AF_INET6]2001:yyy:xxx::z:1194, sid=2e3641f9 ae201e81 >2025-04-21 10:10:52 us=171994 VERIFY OK: depth=1, C=PL, ST=podkarpackie, L=Jaroslaw, O=PWSTE w Jaroslawiu, OU=Dzial IT, CN=PWSTE w Jaroslawiu VPN CA, name=PWSTE w Jaroslawiu VPN CA, emailAddress=support@pwste.edu.pl >2025-04-21 10:10:52 us=172724 VERIFY KU OK >2025-04-21 10:10:52 us=172751 Validating certificate extended key usage >2025-04-21 10:10:52 us=172767 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication >2025-04-21 10:10:52 us=172776 VERIFY EKU OK >2025-04-21 10:10:52 us=172785 NOTE: --mute triggered... >2025-04-21 10:10:52 us=193998 2 variation(s) on previous 20 message(s) suppressed by --mute >2025-04-21 10:10:52 us=194030 [vpn.pwste.edu.pl] Peer Connection Initiated with [AF_INET6]2001:yyy:xxx::z:1194 >2025-04-21 10:10:52 us=194072 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1 >2025-04-21 10:10:52 us=194210 TLS: tls_multi_process: initial untrusted session promoted to trusted >2025-04-21 10:10:52 us=218972 PUSH: Received control message: 'PUSH_REPLY,route a.b.c.0 255.255.248.0,route aa.bb.4.0 255.255.252.0,route-ipv6 2001:yyy:xxx::/48,dhcp-option DNS a.b.c.255,dhcp-option DNS a.b.c.8,dns server 1 address a.b.c.255,dns server 1 resolve-domains pwste.edu.pl,dns server 2 address a.b.c.8,dns server 2 resolve-domains pwste.edu.pl,tun-ipv6,route-gateway i.j.k.1,topology subnet,ping 10,ping-restart 60,route e.f.g.0 255.254.0.0,route b.c.d.0 255.254.0.0,route aa.b.d.0 255.255.254.0,ifconfig-ipv6 2001:yyy:xxx:c2:2::1/64 2001:yyy:xxx:c2::1,ifconfig u.v.w.2 255.255.252.0,peer-id 1,cipher AES-256-GCM,protocol-flags cc-exit tls-ekm dyn-tls-crypt,tun-mtu 1400' >2025-04-21 10:10:52 us=219034 Pushed option removed by filter: 'route a.b.c.0 255.255.248.0' >2025-04-21 10:10:52 us=219047 Pushed option removed by filter: 'route aa.bb.4.0 255.255.252.0' >2025-04-21 10:10:52 us=219056 Pushed option accepted by filter: 'route-ipv6 2001:yyy:xxx::/48' >2025-04-21 10:10:52 us=219180 Pushed option removed by filter: 'route-gateway i.j.k.1' >2025-04-21 10:10:52 us=219201 Pushed option removed by filter: 'route e.f.g.0 255.254.0.0' >2025-04-21 10:10:52 us=219209 Pushed option removed by filter: 'route b.c.d.0 255.254.0.0' >2025-04-21 10:10:52 us=219217 Pushed option removed by filter: 'route aa.b.d.0 255.255.254.0' >2025-04-21 10:10:52 us=219226 Pushed option accepted by filter: 'ifconfig-ipv6 2001:yyy:xxx:c2:2::1/64 2001:yyy:xxx:c2::1' >2025-04-21 10:10:52 us=219246 Pushed option removed by filter: 'ifconfig u.v.w.2 255.255.252.0' >2025-04-21 10:10:52 us=219391 OPTIONS IMPORT: --ifconfig/up options modified >2025-04-21 10:10:52 us=219403 OPTIONS IMPORT: route options modified >2025-04-21 10:10:52 us=219411 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified >2025-04-21 10:10:52 us=219419 OPTIONS IMPORT: tun-mtu set to 1400 >2025-04-21 10:10:52 us=219473 GDG6: remote_host_ipv6=2001:yyy:xxx::z >2025-04-21 10:10:52 us=219633 ROUTE6_GATEWAY fe80::360a:98ff:fe1b:404e IFACE=em0 >2025-04-21 10:10:52 us=219660 ROUTE6: 2001:yyy:xxx::/48 overlaps IPv6 remote 2001:yyy:xxx::z, adding host route to VPN endpoint >2025-04-21 10:10:52 us=220189 TUN/TAP device /dev/tun0 opened >2025-04-21 10:10:52 us=220248 do_ifconfig, ipv4=0, ipv6=1 >2025-04-21 10:10:52 us=220291 /sbin/ifconfig tun0 inet6 2001:yyy:xxx:c2:2::1/64 mtu 1400 up >2025-04-21 10:10:52 us=226007 add_route_ipv6(2001:yyy:xxx::z/128 -> fe80::360a:98ff:fe1b:404e%em0 metric 1) dev em0 >2025-04-21 10:10:52 us=226086 /sbin/route add -inet6 2001:yyy:xxx::z/128 fe80::360a:98ff:fe1b:404e%em0 >add host 2001:yyy:xxx::z/128: gateway fe80::360a:98ff:fe1b:404e%em0 fib 0 >2025-04-21 10:10:52 us=230439 add_route_ipv6(2001:yyy:xxx::/48 -> 2001:yyy:xxx:c2::1 metric -1) dev tun0 >2025-04-21 10:10:52 us=230513 /sbin/route add -inet6 2001:yyy:xxx::/48 -iface tun0 >add net 2001:yyy:xxx::/48: gateway tun0 fib 0 >2025-04-21 10:10:52 us=234491 Data Channel MTU parms [ mss_fix:1380 max_frag:0 tun_mtu:1400 tun_max_mtu:1600 headroom:136 payload:1768 tailroom:562 ET:0 ] >2025-04-21 10:10:52 us=234740 Outgoing dynamic tls-crypt: Cipher 'AES-256-CTR' initialized with 256 bit key >2025-04-21 10:10:52 us=234796 Outgoing dynamic tls-crypt: Using 256 bit message hash 'SHA256' for HMAC authentication >2025-04-21 10:10:52 us=234821 Incoming dynamic tls-crypt: Cipher 'AES-256-CTR' initialized with 256 bit key >2025-04-21 10:10:52 us=234882 Incoming dynamic tls-crypt: Using 256 bit message hash 'SHA256' for HMAC authentication >2025-04-21 10:10:52 us=235018 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key >2025-04-21 10:10:52 us=235050 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key >2025-04-21 10:10:52 us=235086 Initialization Sequence Completed >2025-04-21 10:10:52 us=235104 Data Channel: cipher 'AES-256-GCM', peer-id: 1 >2025-04-21 10:10:52 us=235115 Timers: ping 10, ping-restart 60 >2025-04-21 10:10:52 us=235128 Protocol options: explicit-exit-notify 1, protocol-flags cc-exit tls-ekm dyn-tls-crypt >^C2025-04-21 10:23:29 us=6354 event_wait : Interrupted system call (fd=-1,code=4) >2025-04-21 10:23:29 us=6387 SIGTERM received, sending exit notification to peer >2025-04-21 10:23:29 us=6463 SENT CONTROL [vpn.pwste.edu.pl]: 'EXIT' (status=1) >^C2025-04-21 10:23:29 us=716699 event_wait : Interrupted system call (fd=-1,code=4) >2025-04-21 10:23:29 us=717209 TCP/UDP: Closing socket >2025-04-21 10:23:29 us=717280 delete_route_ipv6(2001:yyy:xxx::z/128) >2025-04-21 10:23:29 us=717303 /sbin/route delete -inet6 2001:yyy:xxx::z/128 fe80::360a:98ff:fe1b:404e%em0 >delete host 2001:yyy:xxx::z/128: gateway fe80::360a:98ff:fe1b:404e%em0 fib 0 >2025-04-21 10:23:29 us=721326 delete_route_ipv6(2001:yyy:xxx::/48) >2025-04-21 10:23:29 us=721398 /sbin/route delete -inet6 2001:yyy:xxx::/48 -iface tun0 >delete net 2001:yyy:xxx::/48: gateway tun0 fib 0 >2025-04-21 10:23:29 us=725280 Closing TUN/TAP interface >2025-04-21 10:23:29 us=725375 /sbin/ifconfig tun0 inet6 2001:yyy:xxx:c2:2::1/64 -alias >2025-04-21 10:23:29 us=730411 /sbin/ifconfig tun0 destroy >2025-04-21 10:23:29 us=743423 SIGINT[hard,] received, process exiting >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 286263
: 259767 |
268237
|
268247