Topics-2010-04-22: script_security_warning.txt

File script_security_warning.txt, 2.9 KB (added by Samuli Seppänen, 14 years ago)
Line 
100:56 < demonTormentor> hi!
200:57 < demonTormentor> how can I remedy this message from openvpn, OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
300:58 < demonTormentor> can i ignore that or i need to install that "--script-security 2'"? Where can i get that?
401:03 < demonTormentor> anyone here?
501:29 < krzee> demonTormentor, thats not an error, it is a warning
601:29 < krzee> if you are not calling external scripts ignore it
701:29 < krzee> if you are, see --script-security in the manual
801:29 < krzee> !man
901:29 < vpnHelper> krzee: "man" is (#1) http://openvpn.net/man for 2.0 manual, or (#2) http://openvpn.net/man-beta.html for 2.1 manual, or (#3) the man pages are your friend!
1001:30 < demonTormentor> krzee: tnx for the response. I guess not, I just need to connect to my vpn server
1101:30 < krzee> !goal
1201:30 < vpnHelper> krzee: "goal" is Please clearly state your goal for your vpn: example, I would like to access the lan behind the server , I would like to access the internet over my vpn , I just want a secure connection between 2 computers , etc
1301:32 < demonTormentor> krzee: can i test accessing my openvpn server from within the same domain?
1401:33 < Bushmills> indeed does that warning not make a lot of sense without --up/down/client-connect/disconnect etc  in the config
1501:34 < Bushmills> why warn about a requirement which doesn't apply?
1601:36 < demonTormentor> that's right
1701:41 < demonTormentor> what can these logs mean? I still can't connect
1801:42 < Bushmills> may eveb be counterproductive: i could imagine that users exist, who set script-security for no other reason than to get rid of the warning - thereby unnecessarily reducing system security
1901:42 < demonTormentor> http://pastebin.com/xR6fq94m
2001:54 < krzee> Bushmills, agreed
21
22---
23
24http://pastebin.com/xR6fq94m
25
26
27   1. Mon Apr 19 14:02:44 2010 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
28   2. Mon Apr 19 14:02:44 2010 TLS Error: TLS handshake failed
29   3. Mon Apr 19 14:02:44 2010 TCP/UDP: Closing socket
30   4. Mon Apr 19 14:02:44 2010 SIGUSR1[soft,tls-error] received, process restarting
31   5. Mon Apr 19 14:02:44 2010 Restart pause, 2 second(s)
32   6. Mon Apr 19 14:02:46 2010 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
33   7. Mon Apr 19 14:02:46 2010 Re-using SSL/TLS context
34   8. Mon Apr 19 14:02:46 2010 LZO compression initialized
35   9. Mon Apr 19 14:02:46 2010 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
36  10. Mon Apr 19 14:02:47 2010 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
37  11. Mon Apr 19 14:02:47 2010 Local Options hash (VER=V4): '41690919'
38  12. Mon Apr 19 14:02:47 2010 Expected Remote Options hash (VER=V4): '530fdded'
39  13. Mon Apr 19 14:02:47 2010 Socket Buffers: R=[8192->8192] S=[8192->8192]
40  14. Mon Apr 19 14:02:47 2010 UDPv4 link local: [undef]
41