Re: [Openvpn-devel] openvpn-2.1.0-r1: easy-rsa tools creates broken client CERTs unusable for TLS

2010-06-09 Thread David Sommerseth
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 09/06/10 23:56, Martin MOKREJŠ wrote: > The patches in Gentoo I for example here: > http://mirror.averse.net/gentoo-portage/net-misc/openvpn/files/ > >>> On the client: >>> I use net-misc/openvpn-2.1.0-r1, I see there are two patches applying to

Re: [Openvpn-devel] openvpn-2.1.0-r1: easy-rsa tools creates broken client CERTs unusable for TLS

2010-06-09 Thread Jan Just Keijser
Hi, Martin Mokrejs wrote: Hi, David Sommerseth wrote: On 08/06/10 18:24, Martin Mokrejs wrote: Hi, I had a look into the original bug report I sent and the summary is this: at some version openvpn implemented a more strict check for certificate values and if teh cjeck fails one

Re: [Openvpn-devel] openvpn-2.1.0-r1: easy-rsa tools creates broken client CERTs unusable for TLS

2010-06-09 Thread Martin Mokrejs
Hi, David Sommerseth wrote: > On 08/06/10 18:24, Martin Mokrejs wrote: >> Hi, >> I had a look into the original bug report I sent and the summary is this: >> at some version openvpn implemented a more strict check for certificate >> values and if teh cjeck fails one yields "unsupported