VPN: killed expiring key for some clients, not all Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern) Come Celebrate our 10 Year Anniversary!Unable to logon to vpnProblems setting up a VPN: can connect but can't ping anyoneSamba over OpenVPN - horribly slowSome clients on a VPN network are not reachableFix 'TLS Error: TLS handshake failed' on OpenVPN clientopenvpn, option tls-cipher not working, no shared cipherServer 2012 - OpenVPN 2.3 64-bit - very slow (10mbps only to clients)tls error : tls handshake failedOpenVPN and multicast routingOpenVPN using TAP with a dummy interface

Is it common practice to audition new musicians one-on-one before rehearsing with the entire band?

Extracting terms with certain heads in a function

Is it ethical to give a final exam after the professor has quit before teaching the remaining chapters of the course?

Do jazz musicians improvise on the parent scale in addition to the chord-scales?

In what way is everyone not a utilitarian

How to compare two different files line by line in unix?

What is the meaning of the simile “quick as silk”?

How do I stop a creek from eroding my steep embankment?

How to Make a Beautiful Stacked 3D Plot

Fundamental Solution of the Pell Equation

Why wasn't DOSKEY integrated with COMMAND.COM?

Trademark violation for app?

How do pianists reach extremely loud dynamics?

Is there such thing as an Availability Group failover trigger?

What font is "z" in "z-score"?

Do square wave exist?

How to answer "Have you ever been terminated?"

What would be the ideal power source for a cybernetic eye?

How do I make this wiring inside cabinet safer? (Pic)

old style "caution" boxes

Most bit efficient text communication method?

What does "lightly crushed" mean for cardamon pods?

Is grep documentation wrong?

Can you use the Shield Master feat to shove someone before you make an attack by using a Readied action?



VPN: killed expiring key for some clients, not all



Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern)
Come Celebrate our 10 Year Anniversary!Unable to logon to vpnProblems setting up a VPN: can connect but can't ping anyoneSamba over OpenVPN - horribly slowSome clients on a VPN network are not reachableFix 'TLS Error: TLS handshake failed' on OpenVPN clientopenvpn, option tls-cipher not working, no shared cipherServer 2012 - OpenVPN 2.3 64-bit - very slow (10mbps only to clients)tls error : tls handshake failedOpenVPN and multicast routingOpenVPN using TAP with a dummy interface



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















I have a VPN server running with +-150 connected users at any given time. While investigating a connectivity issue, I noticed that the clients suffering from connectivity problems had the following error message:




TLS: tls_process: killed expiring key




I understand what this error means and how the process in general works:




In SSL/TLS mode, an SSL session is established with bidirectional
authentication (i.e. each side of the connection must present its own
certificate). If the SSL/TLS authentication succeeds,
encryption/decryption and HMAC key source material is then randomly
generated by OpenSSL's RAND_bytes function and exchanged over the
SSL/TLS connection.




I do however, see these in the logs:




Data Channel Encrypt: Cipher 'AES-256-GCM' initialized with 256 bit key



Data Channel Decrypt: Cipher 'AES-256-GCM' initialized with 256 bit key



Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 4096 bit RSA




But these are the only ones mentioning anything about this. I never see the USING message, which might be the cause of this, right?



I was wondering, why do some clients have this in the server logs, while others don't have this error message. Additional, why do the clients that have this error message, reconnect?










share|improve this question






























    0















    I have a VPN server running with +-150 connected users at any given time. While investigating a connectivity issue, I noticed that the clients suffering from connectivity problems had the following error message:




    TLS: tls_process: killed expiring key




    I understand what this error means and how the process in general works:




    In SSL/TLS mode, an SSL session is established with bidirectional
    authentication (i.e. each side of the connection must present its own
    certificate). If the SSL/TLS authentication succeeds,
    encryption/decryption and HMAC key source material is then randomly
    generated by OpenSSL's RAND_bytes function and exchanged over the
    SSL/TLS connection.




    I do however, see these in the logs:




    Data Channel Encrypt: Cipher 'AES-256-GCM' initialized with 256 bit key



    Data Channel Decrypt: Cipher 'AES-256-GCM' initialized with 256 bit key



    Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 4096 bit RSA




    But these are the only ones mentioning anything about this. I never see the USING message, which might be the cause of this, right?



    I was wondering, why do some clients have this in the server logs, while others don't have this error message. Additional, why do the clients that have this error message, reconnect?










    share|improve this question


























      0












      0








      0








      I have a VPN server running with +-150 connected users at any given time. While investigating a connectivity issue, I noticed that the clients suffering from connectivity problems had the following error message:




      TLS: tls_process: killed expiring key




      I understand what this error means and how the process in general works:




      In SSL/TLS mode, an SSL session is established with bidirectional
      authentication (i.e. each side of the connection must present its own
      certificate). If the SSL/TLS authentication succeeds,
      encryption/decryption and HMAC key source material is then randomly
      generated by OpenSSL's RAND_bytes function and exchanged over the
      SSL/TLS connection.




      I do however, see these in the logs:




      Data Channel Encrypt: Cipher 'AES-256-GCM' initialized with 256 bit key



      Data Channel Decrypt: Cipher 'AES-256-GCM' initialized with 256 bit key



      Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 4096 bit RSA




      But these are the only ones mentioning anything about this. I never see the USING message, which might be the cause of this, right?



      I was wondering, why do some clients have this in the server logs, while others don't have this error message. Additional, why do the clients that have this error message, reconnect?










      share|improve this question
















      I have a VPN server running with +-150 connected users at any given time. While investigating a connectivity issue, I noticed that the clients suffering from connectivity problems had the following error message:




      TLS: tls_process: killed expiring key




      I understand what this error means and how the process in general works:




      In SSL/TLS mode, an SSL session is established with bidirectional
      authentication (i.e. each side of the connection must present its own
      certificate). If the SSL/TLS authentication succeeds,
      encryption/decryption and HMAC key source material is then randomly
      generated by OpenSSL's RAND_bytes function and exchanged over the
      SSL/TLS connection.




      I do however, see these in the logs:




      Data Channel Encrypt: Cipher 'AES-256-GCM' initialized with 256 bit key



      Data Channel Decrypt: Cipher 'AES-256-GCM' initialized with 256 bit key



      Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 4096 bit RSA




      But these are the only ones mentioning anything about this. I never see the USING message, which might be the cause of this, right?



      I was wondering, why do some clients have this in the server logs, while others don't have this error message. Additional, why do the clients that have this error message, reconnect?







      vpn openvpn






      share|improve this question















      share|improve this question













      share|improve this question




      share|improve this question








      edited May 28 '18 at 10:49







      ThomasVdB

















      asked May 28 '18 at 9:58









      ThomasVdBThomasVdB

      135




      135




















          1 Answer
          1






          active

          oldest

          votes


















          0














          I had the same issue, I believe the setting for renegotiation time interval reneg-sec which is set to 3600 by default. Hence the vpn clients will renegotiate the key every hour and re-connect. The work around is to set the --reneg-sec config to 0. More information is available here:-



          https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage






          share|improve this answer








          New contributor




          Atul Ajmani is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
          Check out our Code of Conduct.




















            Your Answer








            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "2"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f914092%2fvpn-killed-expiring-key-for-some-clients-not-all%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            0














            I had the same issue, I believe the setting for renegotiation time interval reneg-sec which is set to 3600 by default. Hence the vpn clients will renegotiate the key every hour and re-connect. The work around is to set the --reneg-sec config to 0. More information is available here:-



            https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage






            share|improve this answer








            New contributor




            Atul Ajmani is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
            Check out our Code of Conduct.
























              0














              I had the same issue, I believe the setting for renegotiation time interval reneg-sec which is set to 3600 by default. Hence the vpn clients will renegotiate the key every hour and re-connect. The work around is to set the --reneg-sec config to 0. More information is available here:-



              https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage






              share|improve this answer








              New contributor




              Atul Ajmani is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
              Check out our Code of Conduct.






















                0












                0








                0







                I had the same issue, I believe the setting for renegotiation time interval reneg-sec which is set to 3600 by default. Hence the vpn clients will renegotiate the key every hour and re-connect. The work around is to set the --reneg-sec config to 0. More information is available here:-



                https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage






                share|improve this answer








                New contributor




                Atul Ajmani is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                Check out our Code of Conduct.










                I had the same issue, I believe the setting for renegotiation time interval reneg-sec which is set to 3600 by default. Hence the vpn clients will renegotiate the key every hour and re-connect. The work around is to set the --reneg-sec config to 0. More information is available here:-



                https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage







                share|improve this answer








                New contributor




                Atul Ajmani is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                Check out our Code of Conduct.









                share|improve this answer



                share|improve this answer






                New contributor




                Atul Ajmani is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                Check out our Code of Conduct.









                answered Apr 12 at 6:56









                Atul AjmaniAtul Ajmani

                11




                11




                New contributor




                Atul Ajmani is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                Check out our Code of Conduct.





                New contributor





                Atul Ajmani is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                Check out our Code of Conduct.






                Atul Ajmani is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
                Check out our Code of Conduct.



























                    draft saved

                    draft discarded
















































                    Thanks for contributing an answer to Server Fault!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f914092%2fvpn-killed-expiring-key-for-some-clients-not-all%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

                    Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

                    Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020