Discussion:
[Openvpn-users] Error reading PKCS#12 file
Ralf Hildebrandt
2008-02-05 10:07:21 UTC
Permalink
One (just one!) user has the following problem:

Thu Jan 31 16:13:26 2008 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct 1 2006
Thu Jan 31 16:13:32 2008 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Thu Jan 31 16:13:32 2008 Error reading PKCS#12 file charite.p12: error:0D07207B:asn1 encoding routines:ASN1_get_object:header too long
Thu Jan 31 16:13:32 2008 Exiting
--
Ralf Hildebrandt (i.A. des IT-Zentrums) ***@charite.de
Charite - Universitätsmedizin Berlin Tel. +49 (0)30-450 570-155
Gemeinsame Einrichtung von FU- und HU-Berlin Fax. +49 (0)30-450 570-962
IT-Zentrum Standort CBF send no mail to ***@charite.de
Jan Just Keijser
2008-02-05 10:16:55 UTC
Permalink
did you try an
openssl pkcs12 -in charite.p12 -noout
yet? sounds like a problem with the PKCS12 file itself.

HTH,

JJK
Post by Ralf Hildebrandt
Thu Jan 31 16:13:26 2008 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct 1 2006
Thu Jan 31 16:13:32 2008 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Thu Jan 31 16:13:32 2008 Error reading PKCS#12 file charite.p12: error:0D07207B:asn1 encoding routines:ASN1_get_object:header too long
Thu Jan 31 16:13:32 2008 Exiting
Ralf Hildebrandt
2008-02-05 10:19:04 UTC
Permalink
Post by Jan Just Keijser
did you try an
openssl pkcs12 -in charite.p12 -noout
yet? sounds like a problem with the PKCS12 file itself.
# openssl pkcs12 -in charite.p12 -noout
Enter Import Password:
MAC verified OK
--
Ralf Hildebrandt (i.A. des IT-Zentrums) ***@charite.de
Charite - Universitätsmedizin Berlin Tel. +49 (0)30-450 570-155
Gemeinsame Einrichtung von FU- und HU-Berlin Fax. +49 (0)30-450 570-962
IT-Zentrum Standort CBF send no mail to ***@charite.de
Jan Just Keijser
2008-02-05 10:28:46 UTC
Permalink
and
openssl pkcs12 -info -in charite.p12
?

BTW, are you using the same p12 file for multiple clients? or is it just
this particular p12 file?

cheers,

JJK
Post by Ralf Hildebrandt
Post by Jan Just Keijser
did you try an
openssl pkcs12 -in charite.p12 -noout
yet? sounds like a problem with the PKCS12 file itself.
# openssl pkcs12 -in charite.p12 -noout
MAC verified OK
Ralf Hildebrandt
2008-02-05 10:35:37 UTC
Permalink
Post by Jan Just Keijser
and
openssl pkcs12 -info -in charite.p12
?
Enter Import Password:
MAC Iteration 2048
MAC verified OK
PKCS7 Encrypted data: pbeWithSHA1And40BitRC2-CBC, Iteration 2048
Certificate bag
Bag Attributes
localKeyID: AF A1 50 79 71 FE 9A 32 29 4E 5E 43 4B 13 93 82 DF B1
78 55
subject=/C=DE/ST=Berlin/L=Berlin/O=Charite-VPN/CN=infoteam.vpn.charite.de/emailAddress=vpn-***@charite.de
issuer=/C=DE/ST=BERLIN/L=BERLIN/O=OpenVPN-Charite/CN=OpenVPN-Charite-CA/emailAddress=einwahl-***@charite.de
-----BEGIN CERTIFICATE-----
MIID3DCCA0WgAwIBAgICDkkwDQYJKoZIhvcNAQEFBQAwgY8xCzAJBgNVBAYTAkRF
MQ8wDQYDVQQIEwZCRVJMSU4xDzANBgNVBAcTBkJFUkxJTjEYMBYGA1UEChMPT3Bl
blZQTi1DaGFyaXRlMRswGQYDVQQDExJPcGVuVlBOLUNoYXJpdGUtQ0ExJzAlBgkq
hkiG9w0BCQEWGGVpbndhaGwtYWRtaW5AY2hhcml0ZS5kZTAeFw0wODAxMjkxMjMw
MzhaFw0xODAxMjYxMjMwMzhaMIGMMQswCQYDVQQGEwJERTEPMA0GA1UECBMGQmVy
bGluMQ8wDQYDVQQHEwZCZXJsaW4xFDASBgNVBAoTC0NoYXJpdGUtVlBOMSAwHgYD
VQQDExdpbmZvdGVhbS52cG4uY2hhcml0ZS5kZTEjMCEGCSqGSIb3DQEJARYUdnBu
LWFkbWluQGNoYXJpdGUuZGUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAPzu
IoH9gV9ETCXFYws++nJ/+NnaM8LZ3G6ZwoMVw/bU9CKEn50U5+aoQS69K+DPR0ML
oDNQuFRoCTrBc1c1vyerTUIFOqm4TVvOcwNbuYPfUwqqsPp0xkfOCEIrG2jrcv1m
A4M2Zue4Is+N3nv6SkGQcm/6zKgQx2qc2PkAxSdJAgMBAAGjggFGMIIBQjAJBgNV
HRMEAjAAMC0GCWCGSAGG+EIBDQQgFh5FYXN5LVJTQSBHZW5lcmF0ZWQgQ2VydGlm
aWNhdGUwHQYDVR0OBBYEFHF60dL5dc0Rs/tSTmrpHJHJv/4UMIHEBgNVHSMEgbww
gbmAFAsp3+AJPb5TbjJRCy9VD5Lk1f/foYGVpIGSMIGPMQswCQYDVQQGEwJERTEP
MA0GA1UECBMGQkVSTElOMQ8wDQYDVQQHEwZCRVJMSU4xGDAWBgNVBAoTD09wZW5W
UE4tQ2hhcml0ZTEbMBkGA1UEAxMST3BlblZQTi1DaGFyaXRlLUNBMScwJQYJKoZI
hvcNAQkBFhhlaW53YWhsLWFkbWluQGNoYXJpdGUuZGWCCQCwklYfsFdZ1jATBgNV
HSUEDDAKBggrBgEFBQcDAjALBgNVHQ8EBAMCB4AwDQYJKoZIhvcNAQEFBQADgYEA
OLo4xp4J84yar+JZtDO9tdcasuGhWM59v9cC5pgbq73cVpjMNpCzPVDUK2pa9Sop
bBDl2Y8uscH8n6reT4hCo07y0uZHnN1K30PmL6Gti/JU/rjNoeMeGu3MDSpu/lJ8
XkaRfvAh6TsyBylsg4AynGJ+OJTL0yoptU3rPMBsY30=
-----END CERTIFICATE-----
Certificate bag
Bag Attributes: <No Attributes>
subject=/C=DE/ST=BERLIN/L=BERLIN/O=OpenVPN-Charite/CN=OpenVPN-Charite-CA/emailAddress=einwahl-***@charite.de
issuer=/C=DE/ST=BERLIN/L=BERLIN/O=OpenVPN-Charite/CN=OpenVPN-Charite-CA/emailAddress=einwahl-***@charite.de
-----BEGIN CERTIFICATE-----
MIIDljCCAv+gAwIBAgIJALCSVh+wV1nWMA0GCSqGSIb3DQEBBAUAMIGPMQswCQYD
VQQGEwJERTEPMA0GA1UECBMGQkVSTElOMQ8wDQYDVQQHEwZCRVJMSU4xGDAWBgNV
BAoTD09wZW5WUE4tQ2hhcml0ZTEbMBkGA1UEAxMST3BlblZQTi1DaGFyaXRlLUNB
MScwJQYJKoZIhvcNAQkBFhhlaW53YWhsLWFkbWluQGNoYXJpdGUuZGUwHhcNMDUw
OTA3MTMzNTMzWhcNMTUwOTA1MTMzNTMzWjCBjzELMAkGA1UEBhMCREUxDzANBgNV
BAgTBkJFUkxJTjEPMA0GA1UEBxMGQkVSTElOMRgwFgYDVQQKEw9PcGVuVlBOLUNo
YXJpdGUxGzAZBgNVBAMTEk9wZW5WUE4tQ2hhcml0ZS1DQTEnMCUGCSqGSIb3DQEJ
ARYYZWlud2FobC1hZG1pbkBjaGFyaXRlLmRlMIGfMA0GCSqGSIb3DQEBAQUAA4GN
ADCBiQKBgQCT79xke89wD7KCbxy0oUsDjwyNAGbTyhnCB+0u+oY3XxdWpaY6RWyb
YVNOktZy34OE/Vp4SCprV6iYxyloMqd1iCq2bGTA5NOD6uEXieRWJ35PFujcgf1n
doAXim+FheZCHsYNR5rJ+nECdZBfUUu2TLBFh7E9ibpPK3Sb9GAjqwIDAQABo4H3
MIH0MB0GA1UdDgQWBBQLKd/gCT2+U24yUQsvVQ+S5NX/3zCBxAYDVR0jBIG8MIG5
gBQLKd/gCT2+U24yUQsvVQ+S5NX/36GBlaSBkjCBjzELMAkGA1UEBhMCREUxDzAN
BgNVBAgTBkJFUkxJTjEPMA0GA1UEBxMGQkVSTElOMRgwFgYDVQQKEw9PcGVuVlBO
LUNoYXJpdGUxGzAZBgNVBAMTEk9wZW5WUE4tQ2hhcml0ZS1DQTEnMCUGCSqGSIb3
DQEJARYYZWlud2FobC1hZG1pbkBjaGFyaXRlLmRlggkAsJJWH7BXWdYwDAYDVR0T
BAUwAwEB/zANBgkqhkiG9w0BAQQFAAOBgQBH6BNhI8+7GCTHZhKQmywB1ZHSYDJo
1pPcHn20gNi70bhX9ZIzziDDMkZayb1nrTOKhDhRToLuWfGI8sdeFRLSaf0mCw6J
rtWoIKWFUsRVgEyJ6K+wIUId1suyoEosI0I7RobCOSxAH6pS2O+U8Dy0PaU6DvD/
5xwtICd8YLwOFQ==
-----END CERTIFICATE-----
PKCS7 Data
Shrouded Keybag: pbeWithSHA1And3-KeyTripleDES-CBC, Iteration 2048
Bag Attributes
localKeyID: AF A1 50 79 71 FE 9A 32 29 4E 5E 43 4B 13 93 82 DF B1
78 55
Key Attributes: <No Attributes>
Post by Jan Just Keijser
BTW, are you using the same p12 file for multiple clients?
No.
Post by Jan Just Keijser
or is it just this particular p12 file?
It's just that user on XP SP2
--
Ralf Hildebrandt (i.A. des IT-Zentrums) ***@charite.de
Charite - Universitätsmedizin Berlin Tel. +49 (0)30-450 570-155
Gemeinsame Einrichtung von FU- und HU-Berlin Fax. +49 (0)30-450 570-962
IT-Zentrum Standort CBF send no mail to ***@charite.de
Jan Just Keijser
2008-02-05 10:47:18 UTC
Permalink
is this the *entire* pkcs12 output? if so, then there's no private key
in the p12 file and that would explain the error. If you did remove it
for security reasons I completely agree and understand, but I must want
to make sure...
A last thing that could be wrong with this p12 file is that the public
cert and private key do not match. It is possible to verify this, but
only if you also have the private key included (section '-----BEGIN RSA
PRIVATE KEY-----').
Try
openssl pkcs12 -in charite.p12 -out blah
openssl x509 -noout -text -in blah
look for the section 'Modulus:' in the output. then compare this to
openssl rsa -noout -text -in blah
and verify that the 'modulus' sections are identical. If so, then this
public cert and private key belong together. Otherwise, your p12 is corrupt.

HTH,

JJK
Post by Ralf Hildebrandt
Post by Jan Just Keijser
and
openssl pkcs12 -info -in charite.p12
?
MAC Iteration 2048
MAC verified OK
PKCS7 Encrypted data: pbeWithSHA1And40BitRC2-CBC, Iteration 2048
Certificate bag
Bag Attributes
localKeyID: AF A1 50 79 71 FE 9A 32 29 4E 5E 43 4B 13 93 82 DF B1
78 55
-----BEGIN CERTIFICATE-----
MIID3DCCA0WgAwIBAgICDkkwDQYJKoZIhvcNAQEFBQAwgY8xCzAJBgNVBAYTAkRF
MQ8wDQYDVQQIEwZCRVJMSU4xDzANBgNVBAcTBkJFUkxJTjEYMBYGA1UEChMPT3Bl
blZQTi1DaGFyaXRlMRswGQYDVQQDExJPcGVuVlBOLUNoYXJpdGUtQ0ExJzAlBgkq
hkiG9w0BCQEWGGVpbndhaGwtYWRtaW5AY2hhcml0ZS5kZTAeFw0wODAxMjkxMjMw
MzhaFw0xODAxMjYxMjMwMzhaMIGMMQswCQYDVQQGEwJERTEPMA0GA1UECBMGQmVy
bGluMQ8wDQYDVQQHEwZCZXJsaW4xFDASBgNVBAoTC0NoYXJpdGUtVlBOMSAwHgYD
VQQDExdpbmZvdGVhbS52cG4uY2hhcml0ZS5kZTEjMCEGCSqGSIb3DQEJARYUdnBu
LWFkbWluQGNoYXJpdGUuZGUwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAPzu
IoH9gV9ETCXFYws++nJ/+NnaM8LZ3G6ZwoMVw/bU9CKEn50U5+aoQS69K+DPR0ML
oDNQuFRoCTrBc1c1vyerTUIFOqm4TVvOcwNbuYPfUwqqsPp0xkfOCEIrG2jrcv1m
A4M2Zue4Is+N3nv6SkGQcm/6zKgQx2qc2PkAxSdJAgMBAAGjggFGMIIBQjAJBgNV
HRMEAjAAMC0GCWCGSAGG+EIBDQQgFh5FYXN5LVJTQSBHZW5lcmF0ZWQgQ2VydGlm
aWNhdGUwHQYDVR0OBBYEFHF60dL5dc0Rs/tSTmrpHJHJv/4UMIHEBgNVHSMEgbww
gbmAFAsp3+AJPb5TbjJRCy9VD5Lk1f/foYGVpIGSMIGPMQswCQYDVQQGEwJERTEP
MA0GA1UECBMGQkVSTElOMQ8wDQYDVQQHEwZCRVJMSU4xGDAWBgNVBAoTD09wZW5W
UE4tQ2hhcml0ZTEbMBkGA1UEAxMST3BlblZQTi1DaGFyaXRlLUNBMScwJQYJKoZI
hvcNAQkBFhhlaW53YWhsLWFkbWluQGNoYXJpdGUuZGWCCQCwklYfsFdZ1jATBgNV
HSUEDDAKBggrBgEFBQcDAjALBgNVHQ8EBAMCB4AwDQYJKoZIhvcNAQEFBQADgYEA
OLo4xp4J84yar+JZtDO9tdcasuGhWM59v9cC5pgbq73cVpjMNpCzPVDUK2pa9Sop
bBDl2Y8uscH8n6reT4hCo07y0uZHnN1K30PmL6Gti/JU/rjNoeMeGu3MDSpu/lJ8
XkaRfvAh6TsyBylsg4AynGJ+OJTL0yoptU3rPMBsY30=
-----END CERTIFICATE-----
Certificate bag
Bag Attributes: <No Attributes>
-----BEGIN CERTIFICATE-----
MIIDljCCAv+gAwIBAgIJALCSVh+wV1nWMA0GCSqGSIb3DQEBBAUAMIGPMQswCQYD
VQQGEwJERTEPMA0GA1UECBMGQkVSTElOMQ8wDQYDVQQHEwZCRVJMSU4xGDAWBgNV
BAoTD09wZW5WUE4tQ2hhcml0ZTEbMBkGA1UEAxMST3BlblZQTi1DaGFyaXRlLUNB
MScwJQYJKoZIhvcNAQkBFhhlaW53YWhsLWFkbWluQGNoYXJpdGUuZGUwHhcNMDUw
OTA3MTMzNTMzWhcNMTUwOTA1MTMzNTMzWjCBjzELMAkGA1UEBhMCREUxDzANBgNV
BAgTBkJFUkxJTjEPMA0GA1UEBxMGQkVSTElOMRgwFgYDVQQKEw9PcGVuVlBOLUNo
YXJpdGUxGzAZBgNVBAMTEk9wZW5WUE4tQ2hhcml0ZS1DQTEnMCUGCSqGSIb3DQEJ
ARYYZWlud2FobC1hZG1pbkBjaGFyaXRlLmRlMIGfMA0GCSqGSIb3DQEBAQUAA4GN
ADCBiQKBgQCT79xke89wD7KCbxy0oUsDjwyNAGbTyhnCB+0u+oY3XxdWpaY6RWyb
YVNOktZy34OE/Vp4SCprV6iYxyloMqd1iCq2bGTA5NOD6uEXieRWJ35PFujcgf1n
doAXim+FheZCHsYNR5rJ+nECdZBfUUu2TLBFh7E9ibpPK3Sb9GAjqwIDAQABo4H3
MIH0MB0GA1UdDgQWBBQLKd/gCT2+U24yUQsvVQ+S5NX/3zCBxAYDVR0jBIG8MIG5
gBQLKd/gCT2+U24yUQsvVQ+S5NX/36GBlaSBkjCBjzELMAkGA1UEBhMCREUxDzAN
BgNVBAgTBkJFUkxJTjEPMA0GA1UEBxMGQkVSTElOMRgwFgYDVQQKEw9PcGVuVlBO
LUNoYXJpdGUxGzAZBgNVBAMTEk9wZW5WUE4tQ2hhcml0ZS1DQTEnMCUGCSqGSIb3
DQEJARYYZWlud2FobC1hZG1pbkBjaGFyaXRlLmRlggkAsJJWH7BXWdYwDAYDVR0T
BAUwAwEB/zANBgkqhkiG9w0BAQQFAAOBgQBH6BNhI8+7GCTHZhKQmywB1ZHSYDJo
1pPcHn20gNi70bhX9ZIzziDDMkZayb1nrTOKhDhRToLuWfGI8sdeFRLSaf0mCw6J
rtWoIKWFUsRVgEyJ6K+wIUId1suyoEosI0I7RobCOSxAH6pS2O+U8Dy0PaU6DvD/
5xwtICd8YLwOFQ==
-----END CERTIFICATE-----
PKCS7 Data
Shrouded Keybag: pbeWithSHA1And3-KeyTripleDES-CBC, Iteration 2048
Bag Attributes
localKeyID: AF A1 50 79 71 FE 9A 32 29 4E 5E 43 4B 13 93 82 DF B1
78 55
Key Attributes: <No Attributes>
Post by Jan Just Keijser
BTW, are you using the same p12 file for multiple clients?
No.
Post by Jan Just Keijser
or is it just this particular p12 file?
It's just that user on XP SP2
Ralf Hildebrandt
2008-02-05 11:50:24 UTC
Permalink
is this the *entire* pkcs12 output? if so, then there's no private key in
the p12 file and that would explain the error. If you did remove it for
security reasons I completely agree and understand, but I must want to
make sure...
It is in there :)
A last thing that could be wrong with this p12 file is that the public
cert and private key do not match. It is possible to verify this, but
only if you also have the private key included (section '-----BEGIN RSA
PRIVATE KEY-----').
Try
openssl pkcs12 -in charite.p12 -out blah
openssl x509 -noout -text -in blah
look for the section 'Modulus:' in the output. then compare this to
Modulus (1024 bit):
00:fc:ee:22:81:fd:81:5f:44:4c:25:c5:63:0b:3e:
fa:72:7f:f8:d9:da:33:c2:d9:dc:6e:99:c2:83:15:
c3:f6:d4:f4:22:84:9f:9d:14:e7:e6:a8:41:2e:bd:
2b:e0:cf:47:43:0b:a0:33:50:b8:54:68:09:3a:c1:
73:57:35:bf:27:ab:4d:42:05:3a:a9:b8:4d:5b:ce:
73:03:5b:b9:83:df:53:0a:aa:b0:fa:74:c6:47:ce:
08:42:2b:1b:68:eb:72:fd:66:03:83:36:66:e7:b8:
22:cf:8d:de:7b:fa:4a:41:90:72:6f:fa:cc:a8:10:
c7:6a:9c:d8:f9:00:c5:27:49
Exponent: 65537 (0x10001)
openssl rsa -noout -text -in blah
modulus:
00:fc:ee:22:81:fd:81:5f:44:4c:25:c5:63:0b:3e:
fa:72:7f:f8:d9:da:33:c2:d9:dc:6e:99:c2:83:15:
c3:f6:d4:f4:22:84:9f:9d:14:e7:e6:a8:41:2e:bd:
2b:e0:cf:47:43:0b:a0:33:50:b8:54:68:09:3a:c1:
73:57:35:bf:27:ab:4d:42:05:3a:a9:b8:4d:5b:ce:
73:03:5b:b9:83:df:53:0a:aa:b0:fa:74:c6:47:ce:
08:42:2b:1b:68:eb:72:fd:66:03:83:36:66:e7:b8:
22:cf:8d:de:7b:fa:4a:41:90:72:6f:fa:cc:a8:10:
c7:6a:9c:d8:f9:00:c5:27:49
publicExponent: 65537 (0x10001)
and verify that the 'modulus' sections are identical. If so, then this
public cert and private key belong together. Otherwise, your p12 is corrupt.
So, am I seeing a Windows-Bug?
--
Ralf Hildebrandt (i.A. des IT-Zentrums) ***@charite.de
Charite - Universitätsmedizin Berlin Tel. +49 (0)30-450 570-155
Gemeinsame Einrichtung von FU- und HU-Berlin Fax. +49 (0)30-450 570-962
IT-Zentrum Standort CBF send no mail to ***@charite.de
Jan Just Keijser
2008-02-05 12:26:38 UTC
Permalink
Hi Ralf,

OK, so your pkcs12 file contains a cert and a priv key that belong
together; the p12 file seems to contain 2 certs, is that correct? can
you try creating a new pkcs12 with only the correct cert+priv key pair
in it? It should not matter, as far as I understand the PKCS12 format
but I just want to make sure that Windows is not choking on the 2 certs
in a single pkcs12 file.

Also, sad but true: have you tried re-installing openvpn on this box?

cheers,

JJK
Post by Ralf Hildebrandt
is this the *entire* pkcs12 output? if so, then there's no private key in
the p12 file and that would explain the error. If you did remove it for
security reasons I completely agree and understand, but I must want to
make sure...
It is in there :)
A last thing that could be wrong with this p12 file is that the public
cert and private key do not match. It is possible to verify this, but
only if you also have the private key included (section '-----BEGIN RSA
PRIVATE KEY-----').
Try
openssl pkcs12 -in charite.p12 -out blah
openssl x509 -noout -text -in blah
look for the section 'Modulus:' in the output. then compare this to
c7:6a:9c:d8:f9:00:c5:27:49
Exponent: 65537 (0x10001)
openssl rsa -noout -text -in blah
c7:6a:9c:d8:f9:00:c5:27:49
publicExponent: 65537 (0x10001)
and verify that the 'modulus' sections are identical. If so, then this
public cert and private key belong together. Otherwise, your p12 is corrupt.
So, am I seeing a Windows-Bug?
Ralf Hildebrandt
2008-02-05 12:43:43 UTC
Permalink
Post by Jan Just Keijser
Hi Ralf,
OK, so your pkcs12 file contains a cert and a priv key that belong
together; the p12 file seems to contain 2 certs, is that correct? can
you try creating a new pkcs12 with only the correct cert+priv key pair
in it?
Sorry, this p12 works just fine on my own installation
Post by Jan Just Keijser
It should not matter, as far as I understand the PKCS12 format but I
just want to make sure that Windows is not choking on the 2 certs in a
single pkcs12 file.
Also, sad but true: have you tried re-installing openvpn on this box?
It's not my box.
--
Ralf Hildebrandt (i.A. des IT-Zentrums) ***@charite.de
Charite - Universitätsmedizin Berlin Tel. +49 (0)30-450 570-155
Gemeinsame Einrichtung von FU- und HU-Berlin Fax. +49 (0)30-450 570-962
IT-Zentrum Standort CBF send no mail to ***@charite.de
Jan Just Keijser
2008-02-05 13:03:48 UTC
Permalink
Hi Ralf,

I've run out of options here... there seems to be nothing wrong with the
p12 file. All I can think of is a openssl library conflict on the client
machine, e.g. there's another version of ssleay32.dll installed on the
client box. A re-install of openvpn might alleviate that problem but as
you stated, you don't own the box. I am curious what the 'openssl
pkcs12' commands would show on the client's machine instead of on your
(correctly functioning) PC.

cheers,

JJK
Post by Ralf Hildebrandt
Post by Jan Just Keijser
Hi Ralf,
OK, so your pkcs12 file contains a cert and a priv key that belong
together; the p12 file seems to contain 2 certs, is that correct? can
you try creating a new pkcs12 with only the correct cert+priv key pair
in it?
Sorry, this p12 works just fine on my own installation
Post by Jan Just Keijser
It should not matter, as far as I understand the PKCS12 format but I
just want to make sure that Windows is not choking on the 2 certs in a
single pkcs12 file.
Also, sad but true: have you tried re-installing openvpn on this box?
It's not my box.
Ralf Hildebrandt
2008-02-05 13:05:38 UTC
Permalink
Post by Jan Just Keijser
Hi Ralf,
I've run out of options here... there seems to be nothing wrong with the
p12 file. All I can think of is a openssl library conflict on the client
machine, e.g. there's another version of ssleay32.dll installed on the
client box.
Yes, with Windows, who knows :)
Post by Jan Just Keijser
A re-install of openvpn might alleviate that problem but as you stated,
you don't own the box. I am curious what the 'openssl pkcs12' commands
would show on the client's machine instead of on your (correctly
functioning) PC.
--
Ralf Hildebrandt (i.A. des IT-Zentrums) ***@charite.de
Charite - Universitätsmedizin Berlin Tel. +49 (0)30-450 570-155
Gemeinsame Einrichtung von FU- und HU-Berlin Fax. +49 (0)30-450 570-962
IT-Zentrum Standort CBF send no mail to ***@charite.de
Loading...