Superb quality and spec AB-Com PULSe 4K SE. Crazy offer! Only £99! FREE UK DELIVERY! 4K UHD, Enigma 2, Multiboot 4 images & more!...
Superb quality and spec AB-Com PULSe 4K Rev II Twin Satellite tuner only £149! FREE UK DELIVERY! 4K UHD, Enigma 2, SATA HDD facility, Multiboot 4 images & more!...

[VU+ Duo4K SE] OpenVix 6.6 and PIA vpn

CK*

New member
Joined
Sep 3, 2018
Messages
3
Reaction score
0
Points
1
Hi,

I've always used OpenVix for the last few years and all the way up to v6.5 I could use PIA with OpenVPN with no issues but when v6.6 was released OpenVPN connects but on checking the ip it shows it's not connected through a vpn therefore I stayed with 6.5 but I'm feeling left out because I cannot update to 6.6 otherwise I won't have a vpn connection.

Can anyone give me a pointer on what might be the issue and how I maybe able to resolve it ?

Wireguard seems a bit to much for me to get my head round setting up with PIA.


Cheers.
 
Comparing the latest Openvix 6.5 and 6.6 log is showing me why 6.6 is failing but I'm not technical enough to understand how to fix it.

Vix 6.5
OpenVPN 2.6.7 arm-oe-linux-gnueabi
OpenSSL 3.2.1 30 Jan 2024

Vix 6.6
OpenVPN 2.6.10 arm-oe-linux-gnueabi
OpenSSL 3.3.0 9 Apr 2024

Errors on 6.6
2024-12-13 18:11:44 OpenSSL: error:068000E9:asn1 encoding routines::utctime is too short:
2024-12-13 18:11:44 OpenSSL: error:0688010A:asn1 encoding routines::nested asn1 error:Field=revocationDate, Type=X509_REVOKED
2024-12-13 18:11:44 OpenSSL: error:0688010A:asn1 encoding routines::nested asn1 error:Field=revoked, Type=X509_CRL_INFO
2024-12-13 18:11:44 OpenSSL: error:0688010A:asn1 encoding routines::nested asn1 error:Field=crl, Type=X509_CRL
2024-12-13 18:11:44 OpenSSL: error:0488000D:PEM routines::ASN1 lib:


I found some alternative SSL files on here that I tried but it made no difference, any idea's how I can resolve this please?
 
The CRL that is being loaded is malformed. It contains malformed revocation dates for certificates.
The difference between 3.3.0 and 3.2.x is that 3.3.0 rejects the invalid dates when loading the CRL where 3.2.x just ignores the malformed entries.
Some say they have worked around this by manually editing the .ovpn file to change the verification of the date.

see the discussion about openssl 3.3.0 and PIA issue here:
Code:
https://github.com/openssl/openssl/discussions/24301
 
Thank you LraiZer !!!!

It worked, feels like a great weight lifted :)

Anyone else with the same issue, in the client.conf' change the line that says compress to comp-lzo no

Then delete <crl-verify> section.

such as below REMOVE IT.

​

<crl-verify>-----BEGIN X509 CRL-----MIICWDCCAUAwDQYJKoZIhvcNAQENBQAwgegxCzAJBgNVBAYTAlVTMQswCQYDVQQI

EwJDQTETMBEGA1UEBxMKTG9zQW5nZWxlczEgMB4GA1UEChMXUHJpdmF0ZSBJbnRl

m5ldCBBY2Nlc3MxIDAeBgNVBAsTF1ByaXZhdGUgSW50ZXJuZXQgQWNjZXNzMSAw

HgYDVQQDExdQcml2YXRlIEludGVybmV0IEFjY2VzczEgMB4GA1UEKRMXUHJpdmF0

ZSBJbnRlcm5ldCBBY2Nlc3MxLzAtBgkqhkiG9w0BCQEWIHNlY3VyZUBwcml2YXRl

aW50ZXJuZXRhY2Nlc3MuY29tFw0xNjA3MDgxOTAwNDZaFw0zNjA3MDMxOTAwNDZa

MCYwEQIBARcMMTYwNzA4MTkwMDQ2MBECAQYXDDE2MDcwODE5MDA0NjANBgkqhkiG

9w0BAQ0FAAOCAQEAQZo9X97ci8EcPYu/uK2HB152OZbeZCINmYyluLDOdcSvg6B5

jI+ffKN3laDvczsG6CxmY3jNyc79XVpEYUnq4rT3FfveW1+Ralf+Vf38HdpwB8EW

B4hZlQ205+21CALLvZvR8HcPxC9KEnev1mU46wkTiov0EKc+EdRxkj5yMgv0V2Re

ze7AP+NQ9ykvDScH4eYCsmufNpIjBLhpLE2cuZZXBLcPhuRzVoU3l7A9lvzG9mjA

5YijHJGHNjlWFqyrn1CfYS6koa4TGEPngBoAziWRbDGdhEgJABHrpoaFYaL61zqy

MR6jC0K2ps9qyZAN74LEBedEfK7tBOzWMwr58A==

-----END X509 CRL-----

</crl-verify>
 

OpenViX Feeds Status

Back
Top