Bug 2337572

Summary: Non-functional parameter data-ciphers in client configuration
Product: [Fedora] Fedora Reporter: Elep331 <elep331>
Component: NetworkManager-openvpnAssignee: Lubomir Rintel <lkundrak>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 41CC: bgalvani, dcbw, ihuguet, kukabu, lkundrak, opensource, steve, tdawson, thaller
Target Milestone: ---Keywords: Desktop
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: NetworkManager-openvpn-1.12.3-1.fc42 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2025-09-26 01:10:06 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Elep331 2025-01-14 09:53:55 UTC
Since OpenVPN 2.5, the recommendation is to use parameter "data-ciphers" instead of "cipher". nm-openvpn has a problem with this new parameter and requires the use of the original "cipher".

It is possible that the bug is in the GUI configuration importer (parser). To set up the OpenVPN client I use Settings -> Network -> Add VPN -> Import form file... in Gnome.

Standard Fedora Workstation 41 with Gnome

Reproducible: Always

Steps to Reproduce:
Parameter "data-ciphers AES-256-GCM" in a client config file 
Actual Results:  
led 14 10:08:37 xxx.local nm-openvpn[19797]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.

led 14 10:08:37 xxx.local nm-openvpn[19797]: OpenVPN 2.6.12 x86_64-redhat-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]

Expected Results:  
Connecting

Comment 1 Michael Tatarinov 2025-09-24 07:47:30 UTC
Hello
Please, update the version in repo. This bug fixed in 1.12.2

Comment 2 Fedora Update System 2025-09-24 13:50:50 UTC
FEDORA-2025-7bd7950adb (NetworkManager-openvpn-1.12.3-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-7bd7950adb

Comment 3 Íñigo Huguet 2025-09-24 13:56:12 UTC
I have submitted an update to 1.12.3, but only for Fedora 42 and EPEL 10 (F43 and Rawhide already had this version). Fedora 41 is near its end of life, so better to leave it out.

F42: https://bodhi.fedoraproject.org/updates/FEDORA-2025-7bd7950adb
EPEL 10: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-2b7a5f3344

Comment 4 Michael Tatarinov 2025-09-24 17:48:03 UTC
Thanks!

Comment 5 Fedora Update System 2025-09-25 01:32:28 UTC
FEDORA-2025-7bd7950adb has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-7bd7950adb`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-7bd7950adb

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2025-09-26 01:10:06 UTC
FEDORA-2025-7bd7950adb (NetworkManager-openvpn-1.12.3-1.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.