Bad certificate

install pritunl just now

client side
2023-08-30 14:34:28 DEPRECATED OPTION: --cipher set to ‘AES-128-CBC’ but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add ‘AES-128-CBC’ to --data-ciphers or change --cipher ‘AES-128-CBC’ to --data-ciphers-fallback ‘AES-128-CBC’ to silence this warning

server side
● pritunl.service - Pritunl Daemon
Loaded: loaded (/etc/systemd/system/pritunl.service; enabled; vendor preset: enabled)
Active: active (running) since Wed 2023-08-30 12:19:48 PKT; 47min ago
Main PID: 11480 (pritunl)
Tasks: 122 (limit: 4556)
Memory: 128.1M
CPU: 4min 46.073s
CGroup: /system.slice/pritunl.service
├─11480 /usr/lib/pritunl/usr/bin/python3 /usr/lib/pritunl/usr/bin/pritunl start
├─12760 pritunl-web
└─14082 openvpn /tmp/pritunl_96f427ade9184b9c9ff8206cd51b6455/283e750bdaf04b43bd121edfb31627a7/openvpn.conf

Aug 30 12:19:48 dass-virtual-machine systemd[1]: Started Pritunl Daemon.
Aug 30 12:23:00 dass-virtual-machine pritunl[12760]: 2023/08/30 12:23:00 http: TLS handshake error from 192.168.0.116:56406: remote error: tls: bad certificate
Aug 30 12:45:46 dass-virtual-machine pritunl[12760]: 2023/08/30 12:45:46 http: TLS handshake error from 192.168.0.100:55416: remote error: tls: unknown certifi>
Aug 30 12:45:46 dass-virtual-machine pritunl[12760]: 2023/08/30 12:45:46 http: TLS handshake error from 192.168.0.100:55415: remote error: tls: unknown certifi>
Aug 30 12:45:51 dass-virtual-machine pritunl[12760]: 2023/08/30 12:45:51 http: TLS handshake error from 192.168.0.100:55417: remote error: tls: unknown certifi>

certificate error resolved by edit in cipher

cipher AES-256-CBC

data-ciphers-fallback AES-256-CBC

now i have error

023-08-31 14:22:07 OpenVPN 2.5.5 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Jul 14 2022
2023-08-31 14:22:07 library versions: OpenSSL 3.0.2 15 Mar 2022, LZO

This was fixed in an update, download the latest release from the pritunl/pritunl-client-electron repository. This occurred with older servers that do not support the newer GCM ciphers.

1 Like

how i move to new new updated sever

how i can add that repository

Problem Solved
public ip issue from my side