Bug 471397
| Summary: | nm-openvpn[15690]: Authenticate/Decrypt packet error: cipher final failed | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Robert Scheck <redhat-bugzilla> |
| Component: | NetworkManager-openvpn | Assignee: | Dan Williams <dcbw> |
| Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | urgent | Docs Contact: | |
| Priority: | medium | ||
| Version: | rawhide | CC: | choeger, dcbw, robert.scheck, steve, tim |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2008-11-13 14:50:30 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Robert Scheck
2008-11-13 14:27:28 UTC
Hi,
thanks for your bug report, the point is: NetworkManager-openvpn does not (and apparently will never) support _all_ openvpn options. If you need a special option you should consider making a request upstream (networkmanager-list).
I don not know the --keysize argument well, manpage tells that:
Use care in
changing a cipher’s default key size. Many ciphers have not
been extensively cryptanalyzed with non-standard key lengths,
and a larger key may offer no real guarantee of greater securi-
ty, or may even reduce security.
So I think it's pretty unlikely that this option will make its way in the gui.
The --up script will propably be used, as long as openvpn does not use dbus to talk with NetworkManager.
I'll close that bug with the advice to use plain openvpn if you have to use such special features.
Well, the main problem is, that the concept of NetworkManager-openvpn itself is broken and wrong. Even the Windows OpenVPN client uses the configuration file as it is and calls openvpn using the configuration file and doesn't create an own one or only appending the parameters to the openvpn call. Very worse to see that the Linux implementation of a thing is unusable while the Windows one works fine. Any firewall changes should be done from NetworkManager dispatcher scripts on the 'vpn-up' event. The VPN connection isn't the only connection, and policy gets applied to the machines *overall* IP configuration based on more than just the vpn connection. NetworkManager-openvpn-0.8.1-0.2.git20100609.el6 has been submitted as an update for Fedora EPEL 6. https://admin.fedoraproject.org/updates/NetworkManager-openvpn-0.8.1-0.2.git20100609.el6 NetworkManager-openvpn-0.8.1-0.2.git20100609.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report. |