Cookie auth rejected by ocserv on reconnect

Niels Peen niels at peen.ch
Fri Jan 30 07:37:25 PST 2015


> On 25 Jan 2015, at 14:52, David Frank <bitinn at gmail.com> wrote:
> 
> Is auth cookie somehow affected by my client certificate?

I’m seeing a similar issue with users who authenticate using certificates. Those using username/password (radius) are not affected.

Jan 30 23:23:47 server ocserv[18528]: main[oid]: 1.1.1.1:64633 assigned IPv4: 10.255.230.57
Jan 30 23:23:47 server ocserv[18528]: main[oid]: 1.1.1.1:64633 assigning tun device tun_oc2
Jan 30 23:23:47 server ocserv[18528]: main[oid]: 1.1.1.1:64633 user ‘oid' of group '[unknown]' authenticated (using cookie)
Jan 30 23:23:48 server ocserv[18528]: main: 1.1.1.1:64630 main-misc.c:501: command socket closed
Jan 30 23:24:14 server ocserv[18528]: main[oid]: 1.1.1.1:64633 main-misc.c:501: command socket closed
Jan 30 23:24:17 server ocserv[18528]: common.c:385: recvmsg returned zero
Jan 30 23:24:17 server ocserv[18528]: main[oid]: 1.1.1.1:64634 main-misc.c:226: error receiving auth reply message
Jan 30 23:24:17 server ocserv[18528]: main[oid]: 1.1.1.1:64634 could not open session
Jan 30 23:24:17 server ocserv[18528]: main[oid]: 1.1.1.1:64634 failed authentication attempt for user ‘oid'
Jan 30 23:24:17 server ocserv[18528]: main[oid]: 1.1.1.1:64634 main-misc.c:501: command socket closed

Niels


More information about the openconnect-devel mailing list