openVPN with TSL 1.3 on LibreSSL. When?

Started by chemlud, October 23, 2019, 12:06:41 PM

Previous topic - Next topic
Hi!

I tried to force one of my openVPN tunnels to require TSL 1.3, but I got in the VPN logs

Options error: unknown tls-version-min parameter: 1.3

so apparently LibreSSL/openVPN is not ready for TLS 1.3. I found a rather old discussion in the developers tickest system. Are there any infos when this feature will be available?

Did anybody try to force TLS 1.3 on openVPN with openSSL? Maybe I would switch if it works there...
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

only with 20.1 (FBSD 12.1) which offers OpenSSL 1.1.1 .. libressl, no idea ..

...even with latest OPNsense und LibreSSL I get:

openvpn[14673]: Options error: unknown tls-version-min parameter: 1.3

when I set tls_min_version to 1.3 in the server config. Is this really not possible?
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....


Yeah, TLS 1.3 is pure luxury, nothing to really care for...
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

TLS 1.3 is important as it has many good features like ESNI and 0RTT. ESNI is going to break transparent proxies and hardens TLS against passive espionage because the hostname is not in plaintext anymore. This feature of course needs DoT or DoH to avoid being bypassed by reading the DNS traffic.

...sorry if you missed the mild irony in my voice ;-)

DoT light I use, would be VERY nice to switch my openVPN tunnels to TLS 1.3. But I don't really want to go back to openSSL.... sigh...
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

I don't want to switch 2 senses fro LibreSSL to openSSL just to learn that TLS 1.3 doesn't work for openVPN there either, so:

Is anybody successfully (!) using TLS_minversion 1.3 on openVPN with latest opnsense and openSSL? :O)
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....