OPNsense Forum

English Forums => Virtual private networks => Topic started by: DEC670airp414user on March 27, 2022, 01:27:29 PM

Title: trying to setup tls-crypt-v2
Post by: DEC670airp414user on March 27, 2022, 01:27:29 PM
Hi I am a new owner of a DEC670 took a little bit to covert from Pfsense to a new OS>.    but I have been successful in everyway but this new method now.   

current version  OPNsense 22.1.4_1-amd64
FreeBSD 13.0-STABLE


using a successful ed448 connection.   when I create a new TLS-crypt key per the instructions.  and I paste it into the "TLS Shared Key".   window.   no matter how many times I try I always get the error :

The following input errors were detected:
The field 'TLS Shared Key' does not appear to be valid

I have read the instructions word for word. and even posted their example and it gives this error
any suggestions?


Title: Re: trying to setup tls-crypt-v2
Post by: DEC670airp414user on July 17, 2022, 03:16:13 PM
so in setting this up.

for the TLS shared key.    is the tbs-cryptv2 key posted BELOW the TLS crypt key?

this is the only way I can get it to accept the new key

how can I see in the logs if pls-cryptv2 is being utilized ?

I am now running the latest version of Business;
OPNsense 22.4.2-amd64
FreeBSD 13.0-STABLE
OpenSSL 1.1.1q 5 Jul 2022 on a DEC670


Nope now all I get are these

AEAD Decrypt error: bad packet ID (may be a replay): [ #720196 ] -- see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warnings