OpenVPN 2.3.0 x86_64-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [eurephia] [MH] [IPv6] built on Feb 9 2013 Originally developed by James Yonan Copyright (C) 2002-2010 OpenVPN Technologies, Inc. Compile time defines: enable_crypto=yes enable_debug=yes enable_def_auth=yes enable_dlopen=unknown enable_dlopen_self=unknown enable_dlopen_self_static=unknown enable_eurephia=yes enable_fast_install=yes enable_fragment=yes enable_http_proxy=yes enable_iproute2=yes enable_libtool_lock=yes enable_lzo=yes enable_lzo_stub=no enable_management=yes enable_multi=yes enable_multihome=yes enable_pam_dlopen=no enable_password_save=yes enable_pedantic=no enable_pf=yes enable_pkcs11=no enable_plugin_auth_pam=yes enable_plugin_down_root=yes enable_plugins=yes enable_port_share=yes enable_selinux=no enable_server=yes enable_shared=yes enable_shared_with_static_runtimes=no enable_small=no enable_socks=yes enable_ssl=yes enable_static=yes enable_strict=no enable_strict_options=no enable_systemd=yes enable_win32_dll=yes enable_x509_alt_username=no with_crypto_library=openssl with_gnu_ld=yes with_mem_check=no with_plugindir='$(libdir)/openvpn/plugins' Sat Feb 23 16:33:39 2013 WARNING: Make sure you understand the semantics of --tls-remote before using it (see the man page). Sat Feb 23 16:33:39 2013 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables Sat Feb 23 16:33:39 2013 Socket Buffers: R=[87380->131072] S=[16384->131072] Sat Feb 23 16:33:39 2013 Attempting to establish TCP connection with [AF_INET]XXX.XXX.XXX.XXX:443 [nonblock] Sat Feb 23 16:33:40 2013 TCP connection established with [AF_INET]XXX.XXX.XXX.XXX:443 Sat Feb 23 16:33:40 2013 TCPv4_CLIENT link local: [undef] Sat Feb 23 16:33:40 2013 TCPv4_CLIENT link remote: [AF_INET]XXX.XXX.XXX.XXX:443 Sat Feb 23 16:33:40 2013 TLS: Initial packet from [AF_INET]XXX.XXX.XXX.XXX:443, sid=f6aba14d b36efcf0 Sat Feb 23 16:33:40 2013 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this Sat Feb 23 16:33:41 2013 VERIFY OK: depth=1, C=de, L=Frankfurt, O=T-Com Testcenter, CN=T-Com Testcenter VPN CA, emailAddress=fw-admin@ffm.tc.iot.dtag.de Sat Feb 23 16:33:41 2013 VERIFY X509NAME ERROR: C=de, L=Frankfurt, O=T-Com Testcenter, CN=someotheromain.com, emailAddress=fw-admin@ffm.tc.iot.dtag.de, must be /C=de/L=Frankfurt/O=T-Com_Testcenter/CN=someotheromain.com/emailAddress=fw-admin@somedomain.com Sat Feb 23 16:33:41 2013 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed Sat Feb 23 16:33:41 2013 TLS Error: TLS object -> incoming plaintext read error Sat Feb 23 16:33:41 2013 TLS Error: TLS handshake failed Sat Feb 23 16:33:41 2013 Fatal TLS error (check_tls_errors_co), restarting Sat Feb 23 16:33:41 2013 SIGUSR1[soft,tls-error] received, process restarting Sat Feb 23 16:33:41 2013 Restart pause, 5 second(s) Sat Feb 23 16:33:46 2013 WARNING: Make sure you understand the semantics of --tls-remote before using it (see the man page). Sat Feb 23 16:33:46 2013 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables Sat Feb 23 16:33:46 2013 Socket Buffers: R=[87380->131072] S=[16384->131072] Sat Feb 23 16:33:46 2013 Attempting to establish TCP connection with [AF_INET]XXX.XXX.XXX.XXX:443 [nonblock] Sat Feb 23 16:33:47 2013 TCP connection established with [AF_INET]XXX.XXX.XXX.XXX:443 Sat Feb 23 16:33:47 2013 TCPv4_CLIENT link local: [undef] Sat Feb 23 16:33:47 2013 TCPv4_CLIENT link remote: [AF_INET]XXX.XXX.XXX.XXX:443 Sat Feb 23 16:33:47 2013 TLS: Initial packet from [AF_INET]XXX.XXX.XXX.XXX:443, sid=f910e926 38d86ae5 Sat Feb 23 16:33:47 2013 VERIFY OK: depth=1, C=de, L=Frankfurt, O=T-Com Testcenter, CN=T-Com Testcenter VPN CA, emailAddress=fw-admin@somedomain.com Sat Feb 23 16:33:47 2013 VERIFY X509NAME ERROR: C=de, L=Frankfurt, O=T-Com Testcenter, CN=someotheromain.com, emailAddress=fw-admin@somedomain.com, must be /C=de/L=Frankfurt/O=T-Com_Testcenter/CN=someotheromain.com/emailAddress=fw-admin@somedomain.com Sat Feb 23 16:33:47 2013 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed Sat Feb 23 16:33:47 2013 TLS Error: TLS object -> incoming plaintext read error Sat Feb 23 16:33:47 2013 TLS Error: TLS handshake failed Sat Feb 23 16:33:47 2013 Fatal TLS error (check_tls_errors_co), restarting Sat Feb 23 16:33:47 2013 SIGUSR1[soft,tls-error] received, process restarting Sat Feb 23 16:33:47 2013 Restart pause, 5 second(s) Sat Feb 23 16:33:51 2013 SIGINT[hard,init_instance] received, process exiting