# Switch to tls-crypt instead from tls-auth

**URL:** https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962
**Category:** Pritunl VPN
**Created:** [April 14, 2023, 2:21pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962 "2023-04-14T14:21:34Z")
**Posts on this page:** 17
**Page:** 1

<div class="post-metadata">

### Author: ![pznamensky](https://forum.pritunl.com/user_avatar/forum.pritunl.com/pznamensky/32/398_2.png) [@pznamensky](https://forum.pritunl.com/u/pznamensky)
#### Post date: [April 14, 2023, 2:21pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/1 "2023-04-14T14:21:34Z")

</div>

Hey there,

We are happy users of the Pritunl VPN Server.  
However, lately, some of our employees have reported that their VPN access has been blocked more often than in previous years in different countries.  
We are trying to find a way to continue providing VPN access and avoid situations when an employee is unable to connect to our server.

Our first idea was to:

1. Use the 443/tcp port
2. Use tls-crypt (or tls-crypt2) to mimic HTTPS traffic

This should make VPN traffic look like HTTPS traffic and help bypass most restrictions.  
However, it’s not possible to configure the Pritunl VPN Server to use tls-crypt. Instead, Pritunl VPN Server enables tls-auth by default, which is similar, but it looks like it’s not enough to eliminate the issue (because tls-auth does not encrypt the TLS control channel).

More about the differences [here](https://openvpn.net/vpn-server-resources/tls-control-channel-security-in-openvpn-access-server/).

We think it would be useful to introduce a new VPN server option called “tls security” with the following choices:

- None
- tls-auth
- tls-crypt
- tls-crypt2

In fact, it seems that we can switch to tls-crypt without any changes in the code, except for renaming corresponding variables and strings.  
Therefore, it might be a good idea to make tls-crypt the new default choice for new installations.

What do you think about this?

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [April 17, 2023, 2:45pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/2 "2023-04-17T14:45:14Z")

</div>

This will be available in the next release with the command `sudo pritunl set vpn.tls_mode '"tls-auth"'`, it may in the future be added as a server option which would replace this global option.

---

<div class="post-metadata">

### Author: ![pznamensky](https://forum.pritunl.com/user_avatar/forum.pritunl.com/pznamensky/32/398_2.png) [@pznamensky](https://forum.pritunl.com/u/pznamensky)
#### Post date: [April 17, 2023, 2:55pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/3 "2023-04-17T14:55:58Z")

</div>

Great news! Thank you!

---

<div class="post-metadata">

### Author: ![Dmitriy](https://forum.pritunl.com/user_avatar/forum.pritunl.com/dmitriy/32/461_2.png) [@Dmitriy](https://forum.pritunl.com/u/Dmitriy)
#### Post date: [July 13, 2023, 1:50pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/4 "2023-07-13T13:50:37Z")

</div>

Hi @zach ,  
is this feature with tls-crypt not added yet?

---

<div class="post-metadata">

### Author: ![Dmitriy](https://forum.pritunl.com/user_avatar/forum.pritunl.com/dmitriy/32/461_2.png) [@Dmitriy](https://forum.pritunl.com/u/Dmitriy)
#### Post date: [July 13, 2023, 2:23pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/5 "2023-07-13T14:23:32Z")

</div>

Hi @pznamensky ,  
how did you obfuscate the TLS connection?

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [July 13, 2023, 11:49pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/6 "2023-07-13T23:49:27Z")

</div>

This option may only be available in the [**unstable releases**](https://docs.pritunl.com/docs/repo).

---

<div class="post-metadata">

### Author: ![mangogroup-user](https://forum.pritunl.com/user_avatar/forum.pritunl.com/mangogroup-user/32/699_2.png) [@mangogroup-user](https://forum.pritunl.com/u/mangogroup-user)
#### Post date: [January 18, 2024, 5:38am UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/7 "2024-01-18T05:38:36Z")

</div>

I typed “sudo pritunl set vpn.tls\_mode ‘“tls-crypt”’” But when connecting I get the error “TLS Error: tls-crypt unwrapping failed from [AF\_INET6]::ffff:xxxxxx”  
How to configure this correctly?

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [January 18, 2024, 9:44am UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/8 "2024-01-18T09:44:51Z")

</div>

I never checked the usage of tls-crypt in that option. It will require additional changes to generate a different key. It’s possible this will be done in the future but there is currently no support for setting that option to `tls-crypt`.

---

<div class="post-metadata">

### Author: ![stavropolsky](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/s/87869e/32.png) [@stavropolsky](https://forum.pritunl.com/u/stavropolsky)
#### Post date: [March 11, 2024, 1:30pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/9 "2024-03-11T13:30:29Z")

</div>

> [@zach](#):
>
> sudo pritunl set vpn.tls\_mode ‘“tls-auth”’

I have the latest version of pritunl v1.32.3805.95 installed. I entered the command in the console sudo pritunl set vpn.tls\_mode ‘“tls-crypt”’. Then I restarted pritunl and mongo - sudo systemctl restart mongod pritunl. Then I created a new profile in the web interface and my VPN works. But I would like tls-crypt-v2 to work. Maybe I need to write my own plugin for this?  
upd: tls-crypt only works with the openvpn client, with the pritunl client it produces errors, example:

```auto
TLS Error: tls-crypt unwrapping failed from [AF_INET6]::ffff:178.34.160.199:7740

```

@zach any ideas on how to make tls-crypt-v2 work with pritunl and make tls-crypt work with the pritunl client?

---

<div class="post-metadata">

### Author: ![esaday](https://forum.pritunl.com/user_avatar/forum.pritunl.com/esaday/32/779_2.png) [@esaday](https://forum.pritunl.com/u/esaday)
#### Post date: [March 22, 2024, 11:00am UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/10 "2024-03-22T11:00:15Z")

</div>

We are having the exact same issue. Is it atleast on the roadmap by any chance?

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [March 22, 2024, 3:28pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/11 "2024-03-22T15:28:35Z")

</div>

It will be added in the future but there is no support for it currently.

---

<div class="post-metadata">

### Author: ![esaday](https://forum.pritunl.com/user_avatar/forum.pritunl.com/esaday/32/779_2.png) [@esaday](https://forum.pritunl.com/u/esaday)
#### Post date: [March 25, 2024, 1:51pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/12 "2024-03-25T13:51:57Z")

</div>

I beileve PR mentioned in [this thread](https://forum.pritunl.com/t/tls-crypt-in-pritunl-official-client/1932) resolves the `tls-crypt` issue. Can we make it reviewed/merged/released soon? 🤔

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [March 27, 2024, 7:18pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/13 "2024-03-27T19:18:41Z")

</div>

That will only add support to the client, the server will still need changes.

---

<div class="post-metadata">

### Author: ![esaday](https://forum.pritunl.com/user_avatar/forum.pritunl.com/esaday/32/779_2.png) [@esaday](https://forum.pritunl.com/u/esaday)
#### Post date: [March 27, 2024, 7:40pm UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/14 "2024-03-27T19:40:04Z")

</div>

We already tested it with server version `pritunl v1.32.3805.95` by setting `sudo pritunl set vpn.tls_mode ‘tls-crypt’` with the local build of [electron client PR](https://github.com/pritunl/pritunl-client-electron/pull/87) and I can confirm it works. The server side apparently can handle the `tls-crypt` key generation and include it in the OVPN Profile.

But I believe `tls-crypt-v2` still requires implementation on both server and client 👍

---

<div class="post-metadata">

### Author: ![stavropolsky](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/s/87869e/32.png) [@stavropolsky](https://forum.pritunl.com/u/stavropolsky)
#### Post date: [March 28, 2024, 7:54am UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/15 "2024-03-28T07:54:33Z")

</div>

> [@esaday](#):
>
> But I believe `tls-crypt-v2` still requires implementation on both server and client

I completely agree!

---

<div class="post-metadata">

### Author: ![oonant](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/o/848f3c/32.png) [@oonant](https://forum.pritunl.com/u/oonant)
#### Post date: [March 29, 2024, 10:52am UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/16 "2024-03-29T10:52:26Z")

</div>

Checked tls-crypt and tls-crypt-v2 option, and found, that some of ISP(MTS RUS in some regios) learned to block connection even if this option enabled - connection established, but after several control packets, all traffci blocks. So, when this rules applyed widely it wont be a silver bullet

---

<div class="post-metadata">

### Author: ![timansky](https://forum.pritunl.com/user_avatar/forum.pritunl.com/timansky/32/843_2.png) [@timansky](https://forum.pritunl.com/u/timansky)
#### Post date: [May 29, 2024, 11:50am UTC](https://forum.pritunl.com/t/switch-to-tls-crypt-instead-from-tls-auth/962/17 "2024-05-29T11:50:16Z")

</div>

We configured a [obfs4proxy](https://gitlab.com/yawning/obfs4.git) for obfuscate trafic. Simple tor proxy in front of server. Tested in different countries where ISP blocks traffic.  
THe only problem is pritunl client does not support it, So we switched to viscosity.  
It will be great feature for client to have an option to configure obfs connection.
