{"id":3006,"date":"2019-08-17T05:50:44","date_gmt":"2019-08-17T04:50:44","guid":{"rendered":"https:\/\/kudzia.eu\/b\/?p=3006"},"modified":"2019-08-17T17:28:24","modified_gmt":"2019-08-17T16:28:24","slug":"openvpn-openssl-error1408518assl-routinesssl3_ctx_ctrldh-key-too-small-after-upgrade-to-debina-buster","status":"publish","type":"post","link":"https:\/\/kudzia.eu\/b\/2019\/08\/openvpn-openssl-error1408518assl-routinesssl3_ctx_ctrldh-key-too-small-after-upgrade-to-debina-buster\/","title":{"rendered":"openvpn &#8211; &#8220;OpenSSL: error:1408518A:SSL routines:ssl3_ctx_ctrl:dh key too small&#8221; after upgrade to Debina Buster"},"content":{"rendered":"<p>another thing to adjust after upgrade to Buster. on openvpn endpoint that in it&#8217;s config &#8211; \/etc\/openvpn\/whatever.conf &#8211; had: <i>dh dh1024.pem<\/i> the vpn service did not start.<\/p>\n<p>tail -f \/var\/log\/syslog showed:<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nAug 17 04:33:43 xyz ovpn-dialin-https&#x5B;1472]: library versions: OpenSSL 1.1.1c  28 May 2019, LZO 2.10\r\nAug 17 04:33:43 xyz ovpn-dialin-https&#x5B;1472]: OpenSSL: error:1408518A:SSL routines:ssl3_ctx_ctrl:dh key too small\r\nAug 17 04:33:43 xyz ovpn-dialin-https&#x5B;1472]: SSL_CTX_set_tmp_dh\r\nAug 17 04:33:43 xyz ovpn-dialin-https&#x5B;1472]: Exiting due to fatal error\r\n<\/pre>\n<p>apparently the new version of openssl no longer accepts 1024 Diffie Hellman group. solution:<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nopenssl dhparam -out \/etc\/openvpn\/dh2048.pem 2048\r\n<\/pre>\n<p>and change in \/etc\/openvpn\/whatever.conf &#8211; from <i>dh dh1024.pem<\/i> to <i>dh dh2048.pem<\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>another thing to adjust after upgrade to Buster. on openvpn endpoint that in it&#8217;s config &#8211; \/etc\/openvpn\/whatever.conf &#8211; had: dh dh1024.pem the vpn service did not start. tail -f \/var\/log\/syslog showed: Aug 17 04:33:43 xyz ovpn-dialin-https&#x5B;1472]: library versions: OpenSSL 1.1.1c 28 May 2019, LZO 2.10 Aug 17 04:33:43 xyz ovpn-dialin-https&#x5B;1472]: OpenSSL: error:1408518A:SSL routines:ssl3_ctx_ctrl:dh key too [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17,51],"tags":[105,104,89],"class_list":["post-3006","post","type-post","status-publish","format-standard","hentry","category-tech","category-unimportant","tag-debian-buster","tag-openssl","tag-openvpn"],"_links":{"self":[{"href":"https:\/\/kudzia.eu\/b\/wp-json\/wp\/v2\/posts\/3006","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kudzia.eu\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kudzia.eu\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kudzia.eu\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kudzia.eu\/b\/wp-json\/wp\/v2\/comments?post=3006"}],"version-history":[{"count":2,"href":"https:\/\/kudzia.eu\/b\/wp-json\/wp\/v2\/posts\/3006\/revisions"}],"predecessor-version":[{"id":3008,"href":"https:\/\/kudzia.eu\/b\/wp-json\/wp\/v2\/posts\/3006\/revisions\/3008"}],"wp:attachment":[{"href":"https:\/\/kudzia.eu\/b\/wp-json\/wp\/v2\/media?parent=3006"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kudzia.eu\/b\/wp-json\/wp\/v2\/categories?post=3006"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kudzia.eu\/b\/wp-json\/wp\/v2\/tags?post=3006"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}