Hello there ) Im trying to connect my router to my OpenVPN server and see this in my OpenWrt router log file:
1 | Fri May 16 16:09:17 2025 | daemon | warn | openvpn(VCT)[30335]: WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless allow-compression yes is also set. |
---|---|---|---|---|
2 | Fri May 16 16:09:17 2025 | daemon | warn | openvpn(VCT)[30335]: DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning. |
3 | Fri May 16 16:09:17 2025 | daemon | notice | openvpn(VCT)[30335]: OpenVPN 2.5.8 aarch64-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] |
4 | Fri May 16 16:09:17 2025 | daemon | notice | openvpn(VCT)[30335]: library versions: OpenSSL 3.0.15 3 Sep 2024, LZO 2.10 |
5 | Fri May 16 16:09:17 2025 | daemon | warn | openvpn(VCT)[30335]: WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info. |
6 | Fri May 16 16:09:17 2025 | daemon | warn | openvpn(VCT)[30335]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts |
7 | Fri May 16 16:09:17 2025 | daemon | warn | openvpn(VCT)[30335]: OpenSSL: error:1C800064:Provider routines::bad decrypt |
8 | Fri May 16 16:09:17 2025 | daemon | warn | openvpn(VCT)[30335]: OpenSSL: error:11800074:PKCS12 routines::pkcs12 cipherfinal error |
9 | Fri May 16 16:09:17 2025 | daemon | warn | openvpn(VCT)[30335]: OpenSSL: error:1C800064:Provider routines::bad decrypt |
10 | Fri May 16 16:09:17 2025 | daemon | warn | openvpn(VCT)[30335]: OpenSSL: error:11800074:PKCS12 routines::pkcs12 cipherfinal error |
11 | Fri May 16 16:09:17 2025 | daemon | warn | openvpn(VCT)[30335]: Cannot load private key file [[INLINE]] |
12 | Fri May 16 16:09:17 2025 | daemon | err | openvpn(VCT)[30335]: Error: private key password verification failed |
13 | Fri May 16 16:09:17 2025 | daemon | notice | openvpn(VCT)[30335]: Exiting due to fatal error |
Its pretty clear, that the problem is in private key password. Im using askpass /etc/openvpn/VCT.auth string in openvpn.conf to make it understand, that my login-pass for private key is in that file specified. But it doesnt work ( So some friendly advice would be great ) Thank you )