OpenVPN only supports TLS v1.0
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| | openvpn (Ubuntu) |
Medium
|
Unassigned | ||
| | Trusty |
Medium
|
Unassigned | ||
| | Utopic |
Medium
|
Unassigned | ||
| | Vivid |
Medium
|
Unassigned | ||
Bug Description
Hi Guys,
Seems the version of OpenVPN we're carrying only supports and/or is able to negotiate TLS v1.0. The patch below has landed in upstream OpenVPN 2.3.3 and replaces TLSv1_server_
https:/
For example, when OpenVPN tls-ciphers is configured with TLS v1.2 ciphers:
| tls-cipher TLS-ECDHE-
Logs shows negotiating at TLS v1.0:
| Oct 26 21:58:47 ragnar ovpn-canonical[
When TLS v1.1 and/or v1.2 ciphers are only specified, sessions fail:
| Oct 26 21:58:29 ragnar ovpn-canonical[
| Oct 26 21:58:29 ragnar ovpn-canonical[
| Oct 26 21:58:29 ragnar ovpn-canonical[
| Oct 26 21:58:31 ragnar ovpn-canonical[
Could we please consider either packaging >= 2.3.3 or backporting this patch?
Thanks,
Haw
| description: | updated |
| no longer affects: | openvpn (Ubuntu Vivid) |
| description: | updated |
| Launchpad Janitor (janitor) wrote : | #1 |
| Changed in openvpn (Ubuntu Trusty): | |
| status: | New → Confirmed |
| Changed in openvpn (Ubuntu Utopic): | |
| status: | New → Confirmed |
| Changed in openvpn (Ubuntu): | |
| status: | New → Confirmed |
| Simon Déziel (sdeziel) wrote : | #4 |
The version that supports negociating TLS 1.1+ (2.3.4) landed in Debian Sid few days ago so it should be picked up by Ubuntu Vivid eventually.
| tags: | added: patch-accepted-upstream |
| Changed in openvpn (Ubuntu): | |
| importance: | Undecided → Medium |
| Changed in openvpn (Ubuntu Trusty): | |
| importance: | Undecided → Medium |
| Changed in openvpn (Ubuntu Utopic): | |
| importance: | Undecided → Medium |
| Simon Déziel (sdeziel) wrote : | #6 |
OpenVPN 2.3.7 made it into Wily
| Changed in openvpn (Ubuntu): | |
| status: | Confirmed → Fix Released |
| Haw Loeung (hloeung) wrote : | #7 |
Any chance we could backport support for TLS v1.1+ to Trusty LTS?
| description: | updated |
| Rolf Leggewie (r0lf) wrote : | #8 |
utopic has seen the end of its life and is no longer receiving any updates. Marking the utopic task for this ticket as "Won't Fix".
| Changed in openvpn (Ubuntu Utopic): | |
| status: | Confirmed → Won't Fix |
| Andreas Hasenack (ahasenack) wrote : | #9 |
Vivid is end-of-life too.
| Changed in openvpn (Ubuntu Vivid): | |
| status: | Confirmed → Won't Fix |


Status changed to 'Confirmed' because the bug affects multiple users.