Bug 1334899 - Can't connect to VPN under Fedora 24 (Got error "Your environment does not meet the access criteria defined by your administrator.")
Summary: Can't connect to VPN under Fedora 24 (Got error "Your environment does not me...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: openconnect
Version: 24
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: David Woodhouse
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 1334890 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-05-10 18:36 UTC by Mikhail
Modified: 2016-12-14 12:18 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-12-14 12:00:00 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Mikhail 2016-05-10 18:36:04 UTC
Description of problem:
Can't connect to  VPN under Fedora 24, but on Windows 10 Cisco AnyConnect client connect fine.

Version-Release number of selected component (if applicable):
# rpm -q openconnect
openconnect-7.06-4.fc24.x86_64

How reproducible:
# openconnect -vvv 85.248.4.70
POST https://85.248.4.70/
Attempting to connect to server 85.248.4.70:443
SSL negotiation with 85.248.4.70
Server certificate verify failed: signer not found

Certificate from VPN server "85.248.4.70" failed verification.
Reason: signer not found
Enter 'yes' to accept, 'no' to abort; anything else to view: yes
Connected to HTTPS on 85.248.4.70
Got HTTP response: HTTP/1.0 302 Temporary moved
Set-Cookie: tg=0WlYtR2xvYmFs; path=/; secure
Content-Length: 0
Cache-Control: no-cache
Pragma: no-cache
Connection: Close
Date: Tue, 10 May 2016 18:32:55 GMT
X-Frame-Options: SAMEORIGIN
Location: /+webvpn+/index.html
HTTP body length:  (0)
GET https://85.248.4.70/
Attempting to connect to server 85.248.4.70:443
SSL negotiation with 85.248.4.70
Server certificate verify failed: signer not found
Connected to HTTPS on 85.248.4.70
Got HTTP response: HTTP/1.0 302 Temporary moved
Set-Cookie: tg=0WlYtR2xvYmFs; path=/; secure
Content-Length: 0
Cache-Control: no-cache
Pragma: no-cache
Connection: Close
Date: Tue, 10 May 2016 18:32:55 GMT
X-Frame-Options: SAMEORIGIN
Location: /+webvpn+/index.html
HTTP body length:  (0)
GET https://85.248.4.70/+webvpn+/index.html
SSL negotiation with 85.248.4.70
Server certificate verify failed: signer not found
Connected to HTTPS on 85.248.4.70
Got HTTP response: HTTP/1.1 200 OK
Transfer-Encoding: chunked
Content-Type: text/xml
Cache-Control: max-age=0
Set-Cookie: webvpn=; expires=Thu, 01 Jan 1970 22:00:00 GMT; path=/; secure
Set-Cookie: webvpnc=; expires=Thu, 01 Jan 1970 22:00:00 GMT; path=/; secure
Set-Cookie: webvpnlogin=1; secure
X-Frame-Options: SAMEORIGIN
X-Transcend-Version: 1
HTTP body chunked (-2)
Please enter your username and password.
Username:east-kronospan\nasibu1
Password:
POST https://85.248.4.70/+webvpn+/index.html
Got HTTP response: HTTP/1.1 200 OK
Transfer-Encoding: chunked
Content-Type: text/xml
Cache-Control: max-age=0
Set-Cookie: webvpn=; expires=Thu, 01 Jan 1970 22:00:00 GMT; path=/; secure
Set-Cookie: webvpnc=; expires=Thu, 01 Jan 1970 22:00:00 GMT; path=/; secure
Set-Cookie: webvpnlogin=1; secure
X-Frame-Options: SAMEORIGIN
X-Transcend-Version: 1
HTTP body chunked (-2)
Login denied.  Your environment does not meet the access criteria defined by your administrator.
Please enter your username and password.
Username:

Comment 1 David Woodhouse 2016-12-14 12:00:00 UTC
Apologies for the delay in responding to this. It's likely that your server is configured to refuse access to Linux clients. You can tweak the UserAgent that's presented, and even the OS that we claim to be, on the openconnect command line. But other than that, I'm not sure there's a lot we can do in a generic fashion to support this.

Please ask on the openconnect-devel.org mailing list (you can just post there; you don't need to subscribe) if you need some help trying to find working settings.

Comment 2 David Woodhouse 2016-12-14 12:01:39 UTC
*** Bug 1334890 has been marked as a duplicate of this bug. ***

Comment 3 Mikhail 2016-12-14 12:18:59 UTC
Is possible add change UserAgent option in NetworkManager-openconnect-gnome? I prefer use Network manager for configuring network.


Note You need to log in before you can comment on or make changes to this bug.