Openvpn 2.6.12-1 break vpn?

Hi today i updated my fedora using dnf update.
And after the update I noticed that I cannot connect to my office’s vpn.
This is the error i get from journalctl:

> Jul 27 23:51:51 mantop NetworkManager[1891]: <info>  [1722099111.8172] vpn[0x55a4c6d9df50,be55041a-dec8-4b3c-8398-45936f6d0a9f,"meruya"]: starting openvpn
Jul 27 23:51:51 mantop NetworkManager[1891]: <info>  [1722099111.8178] audit: op="connection-activate" uuid="be55041a-dec8-4b3c-8398-45936f6d0a9f" name="meruya" pid=3177 uid=1000 result="success"
Jul 27 23:51:51 mantop nm-openvpn[30969]: DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305). OpenVPN ignores --cipher for cipher negotiations.
Jul 27 23:51:51 mantop nm-openvpn[30969]: WARNING: file '/home/lam/.cert/meruya/meruya_client.key' is group or others accessible
Jul 27 23:51:51 mantop nm-openvpn[30969]: OpenVPN 2.6.12 x86_64-redhat-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Jul 27 23:51:51 mantop nm-openvpn[30969]: library versions: OpenSSL 3.2.1 30 Jan 2024, LZO 2.10
Jul 27 23:51:51 mantop nm-openvpn[30969]: DCO version: N/A
Jul 27 23:51:52 mantop nm-openvpn[30969]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jul 27 23:51:52 mantop nm-openvpn[30969]: TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:52 mantop nm-openvpn[30969]: Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:52 mantop nm-openvpn[30969]: TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:52 mantop nm-openvpn[30969]: TCPv4_CLIENT link local: (not bound)
Jul 27 23:51:52 mantop nm-openvpn[30969]: TCPv4_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:52 mantop nm-openvpn[30969]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Jul 27 23:51:52 mantop nm-openvpn[30969]: Connection reset, restarting [0]
Jul 27 23:51:52 mantop nm-openvpn[30969]: SIGUSR1[soft,connection-reset] received, process restarting
Jul 27 23:51:53 mantop nm-openvpn[30969]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jul 27 23:51:53 mantop nm-openvpn[30969]: TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:53 mantop nm-openvpn[30969]: Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:53 mantop nm-openvpn[30969]: TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:53 mantop nm-openvpn[30969]: TCPv4_CLIENT link local: (not bound)
Jul 27 23:51:53 mantop nm-openvpn[30969]: TCPv4_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:54 mantop nm-openvpn[30969]: Connection reset, restarting [0]
Jul 27 23:51:54 mantop nm-openvpn[30969]: SIGUSR1[soft,connection-reset] received, process restarting
Jul 27 23:51:55 mantop gnome-text-edit[28340]: Finalizing GtkSourceGutter 0x55f2c8ec4d00, but it still has children left:
                                                  - GtkSourceGutterRendererLines 0x55f2c8ec6810
Jul 27 23:51:55 mantop gnome-text-edit[28340]: Finalizing GtkSourceGutter 0x55f2c9fba4d0, but it still has children left:
                                                  - GtkSourceGutterRendererLines 0x55f2c9fbbfe0
Jul 27 23:51:55 mantop nm-openvpn[30969]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jul 27 23:51:55 mantop nm-openvpn[30969]: TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:55 mantop nm-openvpn[30969]: Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:55 mantop nm-openvpn[30969]: TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:55 mantop nm-openvpn[30969]: TCPv4_CLIENT link local: (not bound)
Jul 27 23:51:55 mantop nm-openvpn[30969]: TCPv4_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:56 mantop nm-openvpn[30969]: Connection reset, restarting [0]
Jul 27 23:51:56 mantop nm-openvpn[30969]: SIGUSR1[soft,connection-reset] received, process restarting
Jul 27 23:51:57 mantop nm-openvpn[30969]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jul 27 23:51:57 mantop nm-openvpn[30969]: TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:57 mantop nm-openvpn[30969]: Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:57 mantop nm-openvpn[30969]: TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:57 mantop nm-openvpn[30969]: TCPv4_CLIENT link local: (not bound)
Jul 27 23:51:57 mantop nm-openvpn[30969]: TCPv4_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:57 mantop systemd[2872]: app-gnome-org.gnome.Settings-23111.scope: Consumed 18.571s CPU time.
Jul 27 23:51:58 mantop nm-openvpn[30969]: Connection reset, restarting [0]
Jul 27 23:51:58 mantop nm-openvpn[30969]: SIGUSR1[soft,connection-reset] received, process restarting
Jul 27 23:51:59 mantop nm-openvpn[30969]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jul 27 23:51:59 mantop nm-openvpn[30969]: TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:59 mantop nm-openvpn[30969]: Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:59 mantop nm-openvpn[30969]: TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:51:59 mantop nm-openvpn[30969]: TCPv4_CLIENT link local: (not bound)
Jul 27 23:51:59 mantop nm-openvpn[30969]: TCPv4_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:00 mantop nm-openvpn[30969]: Connection reset, restarting [0]
Jul 27 23:52:00 mantop nm-openvpn[30969]: SIGUSR1[soft,connection-reset] received, process restarting
Jul 27 23:52:02 mantop nm-openvpn[30969]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jul 27 23:52:02 mantop nm-openvpn[30969]: TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:02 mantop nm-openvpn[30969]: Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:02 mantop nm-openvpn[30969]: TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:02 mantop nm-openvpn[30969]: TCPv4_CLIENT link local: (not bound)
Jul 27 23:52:02 mantop nm-openvpn[30969]: TCPv4_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:02 mantop nm-openvpn[30969]: Connection reset, restarting [0]
Jul 27 23:52:02 mantop nm-openvpn[30969]: SIGUSR1[soft,connection-reset] received, process restarting
Jul 27 23:52:06 mantop nm-openvpn[30969]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jul 27 23:52:06 mantop nm-openvpn[30969]: TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:06 mantop nm-openvpn[30969]: Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:07 mantop nm-openvpn[30969]: TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:07 mantop nm-openvpn[30969]: TCPv4_CLIENT link local: (not bound)
Jul 27 23:52:07 mantop nm-openvpn[30969]: TCPv4_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:07 mantop nm-openvpn[30969]: Connection reset, restarting [0]
Jul 27 23:52:07 mantop nm-openvpn[30969]: SIGUSR1[soft,connection-reset] received, process restarting
Jul 27 23:52:08 mantop gnome-shell[3177]: clutter_actor_set_allocation_internal: assertion '!isnan (box->x1) && !isnan (box->x2) && !isnan (box->y1) && !isnan (box->y2)' failed
Jul 27 23:52:08 mantop gnome-shell[3177]: clutter_actor_set_allocation_internal: assertion '!isnan (box->x1) && !isnan (box->x2) && !isnan (box->y1) && !isnan (box->y2)' failed
Jul 27 23:52:08 mantop gnome-shell[3177]: clutter_actor_set_allocation_internal: assertion '!isnan (box->x1) && !isnan (box->x2) && !isnan (box->y1) && !isnan (box->y2)' failed
Jul 27 23:52:08 mantop gnome-shell[3177]: clutter_actor_set_allocation_internal: assertion '!isnan (box->x1) && !isnan (box->x2) && !isnan (box->y1) && !isnan (box->y2)' failed
Jul 27 23:52:08 mantop gnome-shell[3177]: clutter_actor_set_allocation_internal: assertion '!isnan (box->x1) && !isnan (box->x2) && !isnan (box->y1) && !isnan (box->y2)' failed
Jul 27 23:52:08 mantop gnome-shell[3177]: Can't update stage views actor Shadow Actor (Overview) [Gjs_rounded-window-corners_fxgn_extension_] is on because it needs an allocation.
Jul 27 23:52:08 mantop gnome-shell[3177]: Can't update stage views actor Shadow Actor (Overview) [Gjs_rounded-window-corners_fxgn_extension_] is on because it needs an allocation.
Jul 27 23:52:08 mantop gnome-shell[3177]: Can't update stage views actor Shadow Actor (Overview) [Gjs_rounded-window-corners_fxgn_extension_] is on because it needs an allocation.
Jul 27 23:52:08 mantop gnome-shell[3177]: Can't update stage views actor Shadow Actor (Overview) [Gjs_rounded-window-corners_fxgn_extension_] is on because it needs an allocation.
Jul 27 23:52:08 mantop gnome-shell[3177]: Can't update stage views actor Shadow Actor (Overview) [Gjs_rounded-window-corners_fxgn_extension_] is on because it needs an allocation.
Jul 27 23:52:15 mantop nm-openvpn[30969]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jul 27 23:52:15 mantop nm-openvpn[30969]: TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:15 mantop nm-openvpn[30969]: Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:15 mantop nm-openvpn[30969]: TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:15 mantop nm-openvpn[30969]: TCPv4_CLIENT link local: (not bound)
Jul 27 23:52:15 mantop nm-openvpn[30969]: TCPv4_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:16 mantop nm-openvpn[30969]: Connection reset, restarting [0]
Jul 27 23:52:16 mantop nm-openvpn[30969]: SIGUSR1[soft,connection-reset] received, process restarting
Jul 27 23:52:24 mantop warp-svc[1708]: 2024-07-27T16:52:24.620Z DEBUG warp::warp_service::network_change: Routes changed:
Jul 27 23:52:24 mantop warp-svc[1708]: NewNeighbour; Destination: fe80::1;
Jul 27 23:52:32 mantop nm-openvpn[30969]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jul 27 23:52:32 mantop nm-openvpn[30969]: TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:32 mantop nm-openvpn[30969]: Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:32 mantop nm-openvpn[30969]: TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:32 mantop nm-openvpn[30969]: TCPv4_CLIENT link local: (not bound)
Jul 27 23:52:32 mantop nm-openvpn[30969]: TCPv4_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194
Jul 27 23:52:33 mantop nm-openvpn[30969]: Connection reset, restarting [0]
Jul 27 23:52:33 mantop nm-openvpn[30969]: SIGUSR1[soft,connection-reset] received, process restarting
Jul 27 23:52:47 mantop gnome-calendar[6697]: source_credentials_required_cb: Failed to authenticate': Failed to obtain an access token for ”: No credentials found in the keyring
Jul 27 23:52:47 mantop gnome-calendar[6697]: source_credentials_required_cb: Failed to authenticate 'WFH Schedule': Failed to obtain an access token for “WFH Schedule”: No credentials found in the keyring
Jul 27 23:52:47 mantop gnome-calendar[6697]: source_credentials_required_cb: Failed to authenticate 'Family': Failed to obtain an access token for “Family”: No credentials found in the keyring
Jul 27 23:52:47 mantop gnome-calendar[6697]: source_credentials_required_cb: Failed to authenticate 'Holidays in Indonesia': Failed to obtain an access token for “Holidays in Indonesia”: No credentials found in the keyring
Jul 27 23:52:47 mantop gnome-calendar[6697]: source_credentials_required_cb: Failed to authenticate 'Muslim Holidays': Failed to obtain an access token for “Muslim Holidays”: No credentials found in the keyring
Jul 27 23:52:47 mantop gnome-calendar[6697]: source_credentials_required_cb: Failed to authenticate 'Hari libur di Indonesia': Failed to obtain an access token for “Hari libur di Indonesia”: No credentials found in the keyring
Jul 27 23:52:52 mantop nm-openvpn-serv[30960]: Connect timer expired, disconnecting.
Jul 27 23:52:52 mantop NetworkManager[1891]: <warn>  [1722099172.6140] vpn[0x55a4c6d9df50,be55041a-dec8-4b3c-8398-45936f6d0a9f,"meruya"]: connect timeout exceeded
Jul 27 23:52:52 mantop nm-openvpn[30969]: SIGTERM[hard,init_instance] received, process exiting
Jul 27 23:52:52 mantop NetworkManager[1891]: <warn>  [1722099172.6144] vpn[0x55a4c6d9df50,be55041a-dec8-4b3c-8398-45936f6d0a9f,"meruya"]: dbus: failure: connect-failed (1)

Using dnf history i noticed that openvpn get upgraded from 2.6.11-1 to 2.6.12-1.
Is there anyone facing the same issue? Should i downgrade my openvpn package?

If you try to downgrade it, does it work?

2 Likes

yup! downgraded openvpn, NetworkManager-openvpn, and NetworkManager-openvpn-gnome makes my vpn works again

2 Likes

Maybe it worth to file a bug

1 Like

Or follow this recent issue on NetworkManager-openvpn

The same issue persists on KDE too; I’ve created a thread on Fedora discussion on this.

Hey. This actually is Fedora discussion, that is a forum, so you have simply created a new thread about the very same issue. :slight_smile:
A bug report is something reported to the attention of developers. So in case of Fedora it could be bugzilla, for the upstream software it could be some git forge like github.com, gitlab, or other issue trackers.

1 Like

Apologies for that; wrong choice of words. And I did not know that a thread has been created on this already. My bad.

1 Like