Cannot load inline certificate file after recent app update [legacy provideder needed] #1450
Answered
by
schwabe
dnarzi
asked this question in
Configuration problems
Replies: 3 comments 2 replies
-
I realized my config might be useful (cert info filled with garbage for posting):
|
Beta Was this translation helpful? Give feedback.
2 replies
-
2022-02-03 15:39:14 MANAGEMENT: CMD 'proxy NONE'
2022-02-03 15:39:15 OpenSSL: error:0A00018E:SSL routines::ca md too weak
2022-02-03 15:39:15 OpenSSL reported a certificate with a weak hash,
please see the in app FAQ about weak hashes.
2022-02-03 15:39:15 MGMT: Got unrecognized command>FATAL:Cannot load
Have you read the FAQ already?
|
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
schwabe
-
Thanks again. That solved it. I apologize for not thoughtfully checking the FAQ. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
The most recent update on Google Play broke my VPN connections. It will no longer connect, and states that it "Cannot load inline config file." I've been running these for years with the same settings and really appreciate the app and how stable it has been for me. However, I can't seem to get it to work any more. I've seen others mention on the Play Store comments they have the same issue, but that it is resolved be "starting from scratch" and importing configs again. I've tried that with no luck. I'm getting: "Cannot load inline certificate file" before an exit.
The config files I'm importing were generated by pfsense, a BSD-based firewall. I'm running the OpenVPN server there, and pfsense generates client configs for me to export. pfsense gives several options for client configs (most clients, Android, OpenVPN Connect). I've tried all of these and they all give the same error. I have a feeling the configs are not properly formated, or the formatting requirements have changed in the new version of OpenVPN for Android, but I'm not sure what I can do to generate proper configs. Before the most recent update, my old configs worked.
Android 11, Samsung Galaxy S20 5G (Snapdragon)
App version 0.7.33
****** LOG ********
2022-02-03 15:39:13 official build 0.7.33 running on samsung SM-G981U1 (kona), Android 11 (RP1A.200720.012) API 30, ABI arm64-v8a, (samsung/x1quex/x1q:11/RP1A.200720.012/G981U1UES2DUL2:user/release-keys)
2022-02-03 15:39:13 Building configuration…
2022-02-03 15:39:14 started Socket Thread
2022-02-03 15:39:14 Network Status: CONNECTED to WIFI
2022-02-03 15:39:14 Debug state info: CONNECTED to WIFI , pause: userPause, shouldbeconnected: true, network: SHOULDBECONNECTED
2022-02-03 15:39:14 Debug state info: CONNECTED to WIFI , pause: userPause, shouldbeconnected: true, network: SHOULDBECONNECTED
2022-02-03 15:39:14 P:WARNING: linker: Warning: "/data/app/~~N9oTBqREF1ZM3BIpYe_AUg==/de.blinkt.openvpn-DG-OZbtieJspYxNCJ-VNwg==/lib/arm64/libovpnexec.so" is not a directory (ignoring)
2022-02-03 15:39:14 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2022-02-03 15:39:14 Current Parameter Settings:
2022-02-03 15:39:14 config = '/data/user/0/de.blinkt.openvpn/cache/android.conf'
2022-02-03 15:39:14 mode = 0
2022-02-03 15:39:14 show_ciphers = DISABLED
2022-02-03 15:39:14 show_digests = DISABLED
2022-02-03 15:39:14 show_engines = DISABLED
2022-02-03 15:39:14 genkey = DISABLED
2022-02-03 15:39:14 genkey_filename = '[UNDEF]'
2022-02-03 15:39:14 key_pass_file = '[UNDEF]'
2022-02-03 15:39:14 show_tls_ciphers = DISABLED
2022-02-03 15:39:14 connect_retry_max = 0
2022-02-03 15:39:14 Connection profiles [0]:
2022-02-03 15:39:14 proto = udp
2022-02-03 15:39:14 local = '[UNDEF]'
2022-02-03 15:39:14 local_port = '[UNDEF]'
2022-02-03 15:39:14 remote = '******.duckdns.org'
2022-02-03 15:39:14 remote_port = '1194'
2022-02-03 15:39:14 remote_float = DISABLED
2022-02-03 15:39:14 bind_defined = DISABLED
2022-02-03 15:39:14 bind_local = DISABLED
2022-02-03 15:39:14 bind_ipv6_only = DISABLED
2022-02-03 15:39:14 connect_retry_seconds = 2
2022-02-03 15:39:14 connect_timeout = 120
2022-02-03 15:39:14 socks_proxy_server = '[UNDEF]'
2022-02-03 15:39:14 socks_proxy_port = '[UNDEF]'
2022-02-03 15:39:14 tun_mtu = 1500
2022-02-03 15:39:14 tun_mtu_defined = ENABLED
2022-02-03 15:39:14 link_mtu = 1500
2022-02-03 15:39:14 link_mtu_defined = DISABLED
2022-02-03 15:39:14 tun_mtu_extra = 0
2022-02-03 15:39:14 tun_mtu_extra_defined = DISABLED
2022-02-03 15:39:14 mtu_discover_type = -1
2022-02-03 15:39:14 fragment = 0
2022-02-03 15:39:14 mssfix = 1492
2022-02-03 15:39:14 mssfix_encap = ENABLED
2022-02-03 15:39:14 explicit_exit_notification = 1
2022-02-03 15:39:14 tls_auth_file = '[INLINE]'
2022-02-03 15:39:14 key_direction = 1
2022-02-03 15:39:14 tls_crypt_file = '[UNDEF]'
2022-02-03 15:39:14 tls_crypt_v2_file = '[UNDEF]'
2022-02-03 15:39:14 Connection profiles END
2022-02-03 15:39:14 remote_random = DISABLED
2022-02-03 15:39:14 ipchange = '[UNDEF]'
2022-02-03 15:39:14 dev = 'tun'
2022-02-03 15:39:14 dev_type = '[UNDEF]'
2022-02-03 15:39:14 dev_node = '[UNDEF]'
2022-02-03 15:39:14 lladdr = '[UNDEF]'
2022-02-03 15:39:14 topology = 1
2022-02-03 15:39:14 ifconfig_local = '[UNDEF]'
2022-02-03 15:39:14 ifconfig_remote_netmask = '[UNDEF]'
2022-02-03 15:39:14 ifconfig_noexec = DISABLED
2022-02-03 15:39:14 ifconfig_nowarn = ENABLED
2022-02-03 15:39:14 ifconfig_ipv6_local = '[UNDEF]'
2022-02-03 15:39:14 ifconfig_ipv6_netbits = 0
2022-02-03 15:39:14 ifconfig_ipv6_remote = '[UNDEF]'
2022-02-03 15:39:14 shaper = 0
2022-02-03 15:39:14 mtu_test = 0
2022-02-03 15:39:14 mlock = DISABLED
2022-02-03 15:39:14 keepalive_ping = 0
2022-02-03 15:39:14 keepalive_timeout = 0
2022-02-03 15:39:14 inactivity_timeout = 0
2022-02-03 15:39:14 ping_send_timeout = 0
2022-02-03 15:39:14 ping_rec_timeout = 0
2022-02-03 15:39:14 ping_rec_timeout_action = 0
2022-02-03 15:39:14 ping_timer_remote = DISABLED
2022-02-03 15:39:14 remap_sigusr1 = 0
2022-02-03 15:39:14 persist_tun = ENABLED
2022-02-03 15:39:14 persist_local_ip = DISABLED
2022-02-03 15:39:14 persist_remote_ip = DISABLED
2022-02-03 15:39:14 persist_key = DISABLED
2022-02-03 15:39:14 passtos = DISABLED
2022-02-03 15:39:14 resolve_retry_seconds = 60
2022-02-03 15:39:14 resolve_in_advance = ENABLED
2022-02-03 15:39:14 username = '[UNDEF]'
2022-02-03 15:39:14 groupname = '[UNDEF]'
2022-02-03 15:39:14 chroot_dir = '[UNDEF]'
2022-02-03 15:39:14 cd_dir = '[UNDEF]'
2022-02-03 15:39:14 writepid = '[UNDEF]'
2022-02-03 15:39:14 up_script = '[UNDEF]'
2022-02-03 15:39:14 down_script = '[UNDEF]'
2022-02-03 15:39:14 down_pre = DISABLED
2022-02-03 15:39:14 up_restart = DISABLED
2022-02-03 15:39:14 up_delay = DISABLED
2022-02-03 15:39:14 daemon = DISABLED
2022-02-03 15:39:14 log = DISABLED
2022-02-03 15:39:14 suppress_timestamps = DISABLED
2022-02-03 15:39:14 machine_readable_output = ENABLED
2022-02-03 15:39:14 nice = 0
2022-02-03 15:39:14 verbosity = 4
2022-02-03 15:39:14 mute = 0
2022-02-03 15:39:14 gremlin = 0
2022-02-03 15:39:14 status_file = '[UNDEF]'
2022-02-03 15:39:14 status_file_version = 1
2022-02-03 15:39:14 status_file_update_freq = 60
2022-02-03 15:39:14 occ = ENABLED
2022-02-03 15:39:14 rcvbuf = 0
2022-02-03 15:39:14 sndbuf = 0
2022-02-03 15:39:14 sockflags = 0
2022-02-03 15:39:14 fast_io = DISABLED
2022-02-03 15:39:14 comp.alg = 2
2022-02-03 15:39:14 comp.flags = 1
2022-02-03 15:39:14 route_script = '[UNDEF]'
2022-02-03 15:39:14 route_default_gateway = '[UNDEF]'
2022-02-03 15:39:14 route_default_metric = 0
2022-02-03 15:39:14 route_noexec = DISABLED
2022-02-03 15:39:14 route_delay = 0
2022-02-03 15:39:14 route_delay_window = 30
2022-02-03 15:39:14 route_delay_defined = DISABLED
2022-02-03 15:39:14 route_nopull = DISABLED
2022-02-03 15:39:14 route_gateway_via_dhcp = DISABLED
2022-02-03 15:39:14 allow_pull_fqdn = DISABLED
2022-02-03 15:39:14 management_addr = '/data/user/0/de.blinkt.openvpn/cache/mgmtsocket'
2022-02-03 15:39:14 management_port = 'unix'
2022-02-03 15:39:14 management_user_pass = '[UNDEF]'
2022-02-03 15:39:14 management_log_history_cache = 250
2022-02-03 15:39:14 management_echo_buffer_size = 100
2022-02-03 15:39:14 management_write_peer_info_file = '[UNDEF]'
2022-02-03 15:39:14 management_client_user = '[UNDEF]'
2022-02-03 15:39:14 management_client_group = '[UNDEF]'
2022-02-03 15:39:14 management_flags = 16678
2022-02-03 15:39:14 shared_secret_file = '[UNDEF]'
2022-02-03 15:39:14 key_direction = 1
2022-02-03 15:39:14 ciphername = 'AES-128-CBC'
2022-02-03 15:39:14 ncp_ciphers = 'AES-128-GCM:AES-128-CBC'
2022-02-03 15:39:14 authname = 'SHA256'
2022-02-03 15:39:14 engine = DISABLED
2022-02-03 15:39:14 Waiting 0s seconds between connection attempt
2022-02-03 15:39:14 replay = ENABLED
2022-02-03 15:39:14 mute_replay_warnings = DISABLED
2022-02-03 15:39:14 replay_window = 64
2022-02-03 15:39:14 replay_time = 15
2022-02-03 15:39:14 packet_id_file = '[UNDEF]'
2022-02-03 15:39:14 test_crypto = DISABLED
2022-02-03 15:39:14 tls_server = DISABLED
2022-02-03 15:39:14 tls_client = ENABLED
2022-02-03 15:39:14 ca_file = '[INLINE]'
2022-02-03 15:39:14 ca_path = '[UNDEF]'
2022-02-03 15:39:14 dh_file = '[UNDEF]'
2022-02-03 15:39:14 cert_file = '[INLINE]'
2022-02-03 15:39:14 extra_certs_file = '[UNDEF]'
2022-02-03 15:39:14 priv_key_file = '[INLINE]'
2022-02-03 15:39:14 pkcs12_file = '[UNDEF]'
2022-02-03 15:39:14 cipher_list = '[UNDEF]'
2022-02-03 15:39:14 cipher_list_tls13 = '[UNDEF]'
2022-02-03 15:39:14 tls_cert_profile = '[UNDEF]'
2022-02-03 15:39:14 tls_verify = '[UNDEF]'
2022-02-03 15:39:14 tls_export_cert = '[UNDEF]'
2022-02-03 15:39:14 verify_x509_type = 2
2022-02-03 15:39:14 verify_x509_name = 'ScurvyOpenVPN-CA'
2022-02-03 15:39:14 crl_file = '[UNDEF]'
2022-02-03 15:39:14 ns_cert_type = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 65535
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_ku[i] = 0
2022-02-03 15:39:14 remote_cert_eku = 'TLS Web Server Authentication'
2022-02-03 15:39:14 ssl_flags = 192
2022-02-03 15:39:14 tls_timeout = 2
2022-02-03 15:39:14 renegotiate_bytes = -1
2022-02-03 15:39:14 renegotiate_packets = 0
2022-02-03 15:39:14 renegotiate_seconds = 3600
2022-02-03 15:39:14 handshake_window = 60
2022-02-03 15:39:14 transition_window = 3600
2022-02-03 15:39:14 single_session = DISABLED
2022-02-03 15:39:14 push_peer_info = DISABLED
2022-02-03 15:39:14 tls_exit = DISABLED
2022-02-03 15:39:14 tls_crypt_v2_metadata = '[UNDEF]'
2022-02-03 15:39:14 server_network = 0.0.0.0
2022-02-03 15:39:14 server_netmask = 0.0.0.0
2022-02-03 15:39:14 server_network_ipv6 = ::
2022-02-03 15:39:14 server_netbits_ipv6 = 0
2022-02-03 15:39:14 server_bridge_ip = 0.0.0.0
2022-02-03 15:39:14 server_bridge_netmask = 0.0.0.0
2022-02-03 15:39:14 server_bridge_pool_start = 0.0.0.0
2022-02-03 15:39:14 server_bridge_pool_end = 0.0.0.0
2022-02-03 15:39:14 ifconfig_pool_defined = DISABLED
2022-02-03 15:39:14 ifconfig_pool_start = 0.0.0.0
2022-02-03 15:39:14 ifconfig_pool_end = 0.0.0.0
2022-02-03 15:39:14 ifconfig_pool_netmask = 0.0.0.0
2022-02-03 15:39:14 ifconfig_pool_persist_filename = '[UNDEF]'
2022-02-03 15:39:14 ifconfig_pool_persist_refresh_freq = 600
2022-02-03 15:39:14 ifconfig_ipv6_pool_defined = DISABLED
2022-02-03 15:39:14 ifconfig_ipv6_pool_base = ::
2022-02-03 15:39:14 ifconfig_ipv6_pool_netbits = 0
2022-02-03 15:39:14 n_bcast_buf = 256
2022-02-03 15:39:14 tcp_queue_limit = 64
2022-02-03 15:39:14 real_hash_size = 256
2022-02-03 15:39:14 virtual_hash_size = 256
2022-02-03 15:39:14 client_connect_script = '[UNDEF]'
2022-02-03 15:39:14 learn_address_script = '[UNDEF]'
2022-02-03 15:39:14 client_disconnect_script = '[UNDEF]'
2022-02-03 15:39:14 client_config_dir = '[UNDEF]'
2022-02-03 15:39:14 ccd_exclusive = DISABLED
2022-02-03 15:39:14 tmp_dir = '/data/data/de.blinkt.openvpn/cache'
2022-02-03 15:39:14 push_ifconfig_defined = DISABLED
2022-02-03 15:39:14 push_ifconfig_local = 0.0.0.0
2022-02-03 15:39:14 push_ifconfig_remote_netmask = 0.0.0.0
2022-02-03 15:39:14 push_ifconfig_ipv6_defined = DISABLED
2022-02-03 15:39:14 push_ifconfig_ipv6_local = ::/0
2022-02-03 15:39:14 push_ifconfig_ipv6_remote = ::
2022-02-03 15:39:14 enable_c2c = DISABLED
2022-02-03 15:39:14 duplicate_cn = DISABLED
2022-02-03 15:39:14 cf_max = 0
2022-02-03 15:39:14 cf_per = 0
2022-02-03 15:39:14 max_clients = 1024
2022-02-03 15:39:14 max_routes_per_client = 256
2022-02-03 15:39:14 auth_user_pass_verify_script = '[UNDEF]'
2022-02-03 15:39:14 auth_user_pass_verify_script_via_file = DISABLED
2022-02-03 15:39:14 auth_token_generate = DISABLED
2022-02-03 15:39:14 auth_token_lifetime = 0
2022-02-03 15:39:14 auth_token_secret_file = '[UNDEF]'
2022-02-03 15:39:14 port_share_host = '[UNDEF]'
2022-02-03 15:39:14 port_share_port = '[UNDEF]'
2022-02-03 15:39:14 vlan_tagging = DISABLED
2022-02-03 15:39:14 vlan_accept = all
2022-02-03 15:39:14 vlan_pvid = 1
2022-02-03 15:39:14 client = ENABLED
2022-02-03 15:39:14 pull = ENABLED
2022-02-03 15:39:14 auth_user_pass_file = 'stdin'
2022-02-03 15:39:14 OpenVPN 2.6-icsopenvpn [git:icsopenvpn/v0.7.33-0-g8bc2287a] arm64-v8a [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] built on Jan 13 2022
2022-02-03 15:39:14 library versions: OpenSSL 3.0.1 14 Dec 2021, LZO 2.10
2022-02-03 15:39:14 MANAGEMENT: Connected to management server at /data/user/0/de.blinkt.openvpn/cache/mgmtsocket
2022-02-03 15:39:14 MANAGEMENT: CMD 'version 3'
2022-02-03 15:39:14 MANAGEMENT: CMD 'hold release'
2022-02-03 15:39:14 MANAGEMENT: CMD 'bytecount 2'
2022-02-03 15:39:14 MANAGEMENT: CMD 'state on'
2022-02-03 15:39:14 MANAGEMENT: CMD 'username 'Auth' ******'
2022-02-03 15:39:14 MANAGEMENT: CMD 'password [...]'
2022-02-03 15:39:14 MANAGEMENT: >STATE:1643902754,RESOLVE,,,,,,
2022-02-03 15:39:14 MANAGEMENT: CMD 'proxy NONE'
2022-02-03 15:39:15 OpenSSL: error:0A00018E:SSL routines::ca md too weak
2022-02-03 15:39:15 OpenSSL reported a certificate with a weak hash, please see the in app FAQ about weak hashes.
2022-02-03 15:39:15 MGMT: Got unrecognized command>FATAL:Cannot load inline certificate file
2022-02-03 15:39:15 MANAGEMENT: Client disconnected
2022-02-03 15:39:15 Cannot load inline certificate file
2022-02-03 15:39:15 Exiting due to fatal error
2022-02-03 15:39:15 Process exited with exit value 1
Beta Was this translation helpful? Give feedback.
All reactions