I'm trying to configure an IPSEC remote access VPN. When I download and extract the configuration archive, the .tgb file appear to be valid, but the .sck file only contains the following:
cannot open file /tmp/root_cert.txt at /scripts/vpn/ipsec/generateJSONVPNClientConf.pl line 331.
I am using the appliance certificate for the local cert and an uploaded certificate for the remote. The remote certificate uploaded successfully and looks fine when I select it in the IPSEC config in the firewall.
This is running on: SFVH (SFOS 19.0.0 GA-Build317))
Any suggestions would be welcome.
Hi Craig,
Thank you for your query, have you tried with the following command in the advance shell:
SFOS 19.0.0 GA-Build317# cat /scripts/vpn/ipsec/generateJSONVPNClientConf.pl
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
I have the same problem with v.19.0.
The .tbg File seems to be valid but there is an Error at the "Public-RootCA-Key"-Section:
unable to load certificate
4153952000:error:0909006C:PEM routines:get_name:no start line:crypto/pem/pem_lib.c:745:Expecting: TRUSTED CERTIFICATE
The Perl script can be open with: cat /scripts/vpn/ipsec/generateJSONVPNClientConf.pl
Hi Craig Glaser: Based on provided error it seems it is getting matched with a known issue NC-85383 and fixed for the same has been taken in V18.5 MR-4 and V19.0.1 MR-1. This is mostly getting observed when cert or cert chain is containing german umlaut characters and translation of same details fetching in SCX is creating a problem.
Regards,
Vishal Ranpariya
Technical Account Manager | Global Customer Experience
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question, use the 'Verify Answer' link.
Hi Michael Sugar III As per the info in my last comment fix for the above ID taken in version V18.5 MR-4 and V19.0.1 MR-1. So once this firmware is released, upgrading to those versions will fix the error.
Regards,
Vishal Ranpariya
Technical Account Manager | Global Customer Experience
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question, use the 'Verify Answer' link.
Hello,
i have the same problem. When i try to import the .scx or .tgb file into sophos connect there comes "Connection could not be parsed". When i open the .scx file in editor i see "cannot open file /tmp/root_cert.txt at /scripts/vpn/ipsec/generateJSONVPNClientConf.pl line 331."
I try everything to fix these issue. ApplianceCertificate (used for local cert in ipsec vpn config) and remote certificate (localy signied from xg) has no german umlaut characters or spaces.
Is there any workaround in the mean time? I am on 19.0.0 GA-Build317 and I've heard 19.0.1 won't be released until the end of July.
Hi,
I have the same problem.
Updating to SFOS 19.0.1 MR-1-Build350 did not help.
Trying to create a new local certificate and remote certificate didn't change anything either.
When exporting the VPN configuration, there is still an error in client_ipsec.tgb:
......
-----END CERTIFICATE-----
[client_ipsec-Public-RootCA-Key]
unable to load certificate
4154918656:error:0909006C:PEM routines:get_name:no start line:crypto/pem/pem_lib.c:745:Expecting: TRUSTED CERTIFICATE
[client_ipsec-secret-client-key]
-----BEGIN RSA PRIVATE KEY-----
...
and in the client_ipsec.scx:
cannot open file /tmp/root_cert.txt at /scripts/vpn/ipsec/generateJSONVPNClientConf.pl line 331.
Hi Holger Krieg1 In recent cases it has been observed that apart from german umlaut characters "Spaces in the cert" also creates a problem and results in the above error. The Fix will be included in the SFOS v19.0MR2 release and the ID is NC-95633.
Regards,
Vishal Ranpariya
Technical Account Manager | Global Customer Experience
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question, use the 'Verify Answer' link.
Hi,
I fixed the problem.
It is the space in the company name in the default certificate.