<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN - TLS verify error]]></title><description><![CDATA[<p dir="auto">VPN has been working 2 weeks ago.</p>
<p dir="auto">Today connecting fails with a verify error:<br />
<code>VERIFY ERROR: depth=0, error=CRL has expired: CN=MBP</code><br />
<code>OpenSSL: error:1417C086:SSL routines:tls_process_client_certificate:certificate verify failed</code><br />
<code>...</code></p>
<p dir="auto">The device config was created on Aug 16, 2022.</p>
<p dir="auto">Does the CRL not update automatically?</p>
<p dir="auto">Is there a default expiry? I don't see one set in the config file.</p>
<p dir="auto">Ex:<br />
EASYRSA_CRL_DAYS=3650 (10 yrs)</p>
<p dir="auto">Looking at the keys dir in File Manager, it's dated Aug of last year. So is that a 1 year expiry and no update?</p>
]]></description><link>https://forum.cloudron.io/topic/8117/openvpn-tls-verify-error</link><generator>RSS for Node</generator><lastBuildDate>Mon, 11 May 2026 08:11:37 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/8117.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 30 Nov 2022 00:20:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN - TLS verify error on Wed, 30 Nov 2022 13:57:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> Update: after restarting the OpenVPN App, it connects and verifies TLS just fine.</p>
<p dir="auto">Shrug, restart fixed it.</p>
]]></description><link>https://forum.cloudron.io/post/57419</link><guid isPermaLink="true">https://forum.cloudron.io/post/57419</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Wed, 30 Nov 2022 13:57:23 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN - TLS verify error on Wed, 30 Nov 2022 13:49:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nebulon" aria-label="Profile: nebulon">@<bdi>nebulon</bdi></a> I didn't find it in the .ovpn but in the cert.crt file:</p>
<pre><code>    Validity
        Not Before: Aug 16 10:04:48 2022 GMT
        Not After : Aug 13 10:04:48 2032 GMT
</code></pre>
<p dir="auto">So it is configured right, and handing out proper VPN configs, yet the server doesn't like something.</p>
]]></description><link>https://forum.cloudron.io/post/57418</link><guid isPermaLink="true">https://forum.cloudron.io/post/57418</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Wed, 30 Nov 2022 13:49:02 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN - TLS verify error on Wed, 30 Nov 2022 13:25:03 GMT]]></title><description><![CDATA[<p dir="auto">The current cert expiration is indeed set to 10 years: <a href="https://git.cloudron.io/cloudron/openvpn-app/-/blob/master/easyrsa-vars#L15" target="_blank" rel="noopener noreferrer nofollow ugc">https://git.cloudron.io/cloudron/openvpn-app/-/blob/master/easyrsa-vars#L15</a></p>
<p dir="auto">Can you download the .opvn file and double check the expiration there?</p>
]]></description><link>https://forum.cloudron.io/post/57414</link><guid isPermaLink="true">https://forum.cloudron.io/post/57414</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Wed, 30 Nov 2022 13:25:03 GMT</pubDate></item></channel></rss>