what you should have seen is the certificate stack, starting with the CA, and then the client cert, e.g. Connection accept... ok = 1 cert DN: /C=US/O=Cookbook 2.4/CN=Cookbook 2.4 CA/emailAddress=openvpn@xxxxxxxxxxx ok = 1 cert DN: /C=US/O=Cookbook 2.4/CN=client1 so I suspect that your ca.crt on the server side is not specified correctly. You may also send me your ca.crt, server.{crt,key} and client.{crt,key} files privately, and I will run the same test using your set of certificates. HTH, JJK
|
-- openssl-users mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users