Jump to content

VPN : Mullvad (WireGuard VPN)


JOSHR3ll

Recommended Posts

client
dev tun
proto udp
remote us-ca.mullvad.net 1195
cipher AES-256-CBC
resolv-retry infinite
nobind
persist-key
persist-tun
verb 3
remote-cert-tls server
ping 10
ping-restart 60
sndbuf 524288
rcvbuf 524288
fast-io
auth-user-pass
reneg-sec 0
tun-ipv6
<ca>
-----BEGIN CERTIFICATE-----
MIIGIzCCBAugAwIBAgIJAK6BqXN9GHI0MA0GCSqGSIb3DQEBCwUAMIGfMQswCQYD
VQQGEwJTRTERMA8GA1UECAwIR290YWxhbmQxEzARBgNVBAcMCkdvdGhlbmJ1cmcx
FDASBgNVBAoMC0FtYWdpY29tIEFCMRAwDgYDVQQLDAdNdWxsdmFkMRswGQYDVQQD
DBJNdWxsdmFkIFJvb3QgQ0EgdjIxIzAhBgkqhkiG9w0BCQEWFHNlY3VyaXR5QG11
bGx2YWQubmV0MB4XDTE4MTEwMjExMTYxMVoXDTI4MTAzMDExMTYxMVowgZ8xCzAJ
BgNVBAYTAlNFMREwDwYDVQQIDAhHb3RhbGFuZDETMBEGA1UEBwwKR290aGVuYnVy
ZzEUMBIGA1UECgwLQW1hZ2ljb20gQUIxEDAOBgNVBAsMB011bGx2YWQxGzAZBgNV
BAMMEk11bGx2YWQgUm9vdCBDQSB2MjEjMCEGCSqGSIb3DQEJARYUc2VjdXJpdHlA
bXVsbHZhZC5uZXQwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCifDn7
5E/Zdx1qsy31rMEzuvbTXqZVZp4bjWbmcyyXqvnayRUHHoovG+lzc+HDL3HJV+kj
xKpCMkEVWwjY159lJbQbm8kkYntBBREdzRRjjJpTb6haf/NXeOtQJ9aVlCc4dM66
bEmyAoXkzXVZTQJ8h2FE55KVxHi5Sdy4XC5zm0wPa4DPDokNp1qm3A9Xicq3Hsfl
LbMZRCAGuI+Jek6caHqiKjTHtujn6Gfxv2WsZ7SjerUAk+mvBo2sfKmB7octxG7y
AOFFg7YsWL0AxddBWqgq5R/1WDJ9d1Cwun9WGRRQ1TLvzF1yABUerjjKrk89RCzY
ISwsKcgJPscaDqZgO6RIruY/xjuTtrnZSv+FXs+Woxf87P+QgQd76LC0MstTnys+
AfTMuMPOLy9fMfEzs3LP0Nz6v5yjhX8ff7+3UUI3IcMxCvyxdTPClY5IvFdW7CCm
mLNzakmx5GCItBWg/EIg1K1SG0jU9F8vlNZUqLKz42hWy/xB5C4QYQQ9ILdu4ara
PnrXnmd1D1QKVwKQ1DpWhNbpBDfE776/4xXD/tGM5O0TImp1NXul8wYsDi8g+e0p
xNgY3Pahnj1yfG75Yw82spZanUH0QSNoMVMWnmV2hXGsWqypRq0pH8mPeLzeKa82
gzsAZsouRD1k8wFlYA4z9HQFxqfcntTqXuwQcQIDAQABo2AwXjAdBgNVHQ4EFgQU
faEyaBpGNzsqttiSMETq+X/GJ0YwHwYDVR0jBBgwFoAUfaEyaBpGNzsqttiSMETq
+X/GJ0YwCwYDVR0PBAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQEL
BQADggIBADH5izxu4V8Javal8EA4DxZxIHUsWCg5cuopB28PsyJYpyKipsBoI8+R
XqbtrLLue4WQfNPZHLXlKi+A3GTrLdlnenYzXVipPd+n3vRZyofaB3Jtb03nirVW
Ga8FG21Xy/f4rPqwcW54lxrnnh0SA0hwuZ+b2yAWESBXPxrzVQdTWCqoFI6/aRnN
8RyZn0LqRYoW7WDtKpLmfyvshBmmu4PCYSh/SYiFHgR9fsWzVcxdySDsmX8wXowu
Ffp8V9sFhD4TsebAaplaICOuLUgj+Yin5QzgB0F9Ci3Zh6oWwl64SL/OxxQLpzMW
zr0lrWsQrS3PgC4+6JC4IpTXX5eUqfSvHPtbRKK0yLnd9hYgvZUBvvZvUFR/3/fW
+mpBHbZJBu9+/1uux46M4rJ2FeaJUf9PhYCPuUj63yu0Grn0DreVKK1SkD5V6qXN
0TmoxYyguhfsIPCpI1VsdaSWuNjJ+a/HIlKIU8vKp5iN/+6ZTPAg9Q7s3Ji+vfx/
AhFtQyTpIYNszVzNZyobvkiMUlK+eUKGlHVQp73y6MmGIlbBbyzpEoedNU4uFu57
mw4fYGHqYZmYqFaiNQv4tVrGkg6p+Ypyu1zOfIHF7eqlAOu/SyRTvZkt9VtSVEOV
H7nDIGdrCC9U/g1Lqk8Td00Oj8xesyKzsG214Xd8m7/7GmJ7nXe5
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIGHDCCBASgAwIBAgIEEAAAADANBgkqhkiG9w0BAQsFADCBnzELMAkGA1UEBhMC
U0UxETAPBgNVBAgMCEdvdGFsYW5kMRMwEQYDVQQHDApHb3RoZW5idXJnMRQwEgYD
VQQKDAtBbWFnaWNvbSBBQjEQMA4GA1UECwwHTXVsbHZhZDEbMBkGA1UEAwwSTXVs
bHZhZCBSb290IENBIHYyMSMwIQYJKoZIhvcNAQkBFhRzZWN1cml0eUBtdWxsdmFk
Lm5ldDAeFw0xODExMDIxMTI2MDNaFw0xOTExMDIxMTI2MDNaMIGdMQswCQYDVQQG
EwJTRTERMA8GA1UECAwIR290YWxhbmQxFDASBgNVBAoMC0FtYWdpY29tIEFCMRAw
DgYDVQQLDAdNdWxsdmFkMS4wLAYDVQQDDCVNdWxsdmFkIFRyYW5zaXRpb24tSW50
ZXJtZWRpYXRlIENBIHYxMSMwIQYJKoZIhvcNAQkBFhRzZWN1cml0eUBtdWxsdmFk
Lm5ldDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAOAvizkx9wPHo9qH
TKdSe1ckgoe20PsN++pAnIZ1ZrrUAW/Y/7HjeZvPH1nJHWtQaoY72mQKbl3WVafZ
THm+t0qtnAGcI+1dZjAERmPBZyVtbsOegITqWiAyw5QGfq/+pmC752a8NxHy73Pt
cvt81vML87dx0vzOm2IPCr2mdsdxMsoETuBCED/gY6N4BEnK/NS5JjNnpynq4bZb
obzKuLKTmFabU5CVttg7eBcI4O6KhOYbP4T6Xpo+ALRN7+fyAjir2YKIifccftf5
eiB23Ov1kt9k4nIc3lt6tDHaz6INPHjigHJ2AuJDb7V3GH0czdu2Elr5tZC+5sDX
NcMSOPNA9L4o9svA553c21tg/1cwKUD3GJoCzIN9k9+ba9VWnpOiebNakdTUlegy
5LlzO+aVpZbMoAHoP/1PHqPe9Nz62vrt2wtTfuP5cTCHkTIFy6X6LWitWmox3lLo
aaruQ2x6WF64bGuFHKLDlMNRWd63GE/ZE3AXTmmYIE+CgZ6aPyFuUluAA9C6r7bU
052ddBIuQLBZ2Pj4yZ0UK2aymjS4OBYddzLkPM4B5Mttcj3nbk8FKHDHTXLlyIvE
9BQAejH2p+sOboWudHyw7B7kDqWt9aHHYrQbSimnaY6QoJ8VisyFZVrrIQMQxwLw
AvBScVkmBDTP1iG0B4tGzCRTIilPAgMBAAGjYDBeMB0GA1UdDgQWBBQVxpaQ55d1
yngyg7YEXMuTDc9hPzAfBgNVHSMEGDAWgBR9oTJoGkY3Oyq22JIwROr5f8YnRjAL
BgNVHQ8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAgEA
STee9JP7tegxul90VTRyG53l37fuZGjrp70tYQfl8676lTyFyZVBF7tAFrJwc1K9
2d1JnMbyHzyR7LzZr/7tB3w7eIR8Q7TiBAe9eHleMlmK975ivcAhrY0fJ+BO8xgw
6KE7dOI1jeeff5wF/2KmXybeq2M1phA3KGy+sxc8KrLCVHfXfOnv+b9HRKDqE4/c
3ALMVHXir9sXDyY5bH7jcOGyVQTPI5ZLxvjndunCkXG595pJqDqUWXS8BYcFExIf
IQuJ5omt+tyM9U17yOPvwTyadbRW2m7LIcTwPEwC3IUHCUQzqLZkmF2pCQa8hV2b
q3eK/hV1mHvFbfZcQ+TPl8vl4cRT92vLQGGy51D9t8bVs4bBET0DSPivVcnMqkSO
vAz7xdXqya36iri27iI3aUdBI/XihT1LkxAJhas9YBt+T2xz7xN+WU/ImB+Cq+sH
nJNIcB+wE50/rBb+gTaOpEx80Onq277N3TUByVLjCztl1J6cWIy1XObhRVgXLUcT
B6/Z/zRblHt7f/f5TTUmAwMc+VwvnjpweSV98DpP0MLV6ZEpmh/ij0Dwpc6IoD8u
Lwvyq9jhkSAki5LHO2t1mw0jIjtncxEq/9RmrVP1e3/weYvyhy1T4Mq4NCcPGFR0
+TUxbjSUGVUuHIPxiR+XptxDWguRhwSYEKSy3EwfOMc=
-----END CERTIFICATE-----
</ca>
tls-cipher TLS-DHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA

Link to comment
Share on other sites

  • Administrators

There are not usually two certificates stacked like that. Where is says end certificate the first time that should be it. Could you provide a link to the original OpenVPN files/folder provided by Mullvad so we can take a look please?

Link to comment
Share on other sites

10 hours ago, Netduma Fraser said:

There are not usually two certificates stacked like that. Where is says end certificate the first time that should be it. Could you provide a link to the original OpenVPN files/folder provided by Mullvad so we can take a look please?

https://mullvad.net/en/download/config/

>> i select Android to get a single .ovpn file.

 

2018-12-15_1338.png

Link to comment
Share on other sites

3 hours ago, Netduma Fraser said:

I can't get the config because I don't have an account with them. Also you want to chose Linux instead not Android

If i chose linux i dont have a single ovpn but a zip with many single file .crt / .txt / .conf 

2018-12-15_1656.png

mullvad_ca.crt

mullvad_us-ca.conf

update-resolv-conf

Link to comment
Share on other sites

  • Administrators

Okay so there could be a few variations trying to get this to work, please try the following:

client
dev tun
proto udp
remote us-ca.mullvad.net 1302
cipher AES-256-CBC
resolv-retry infinite
nobind
persist-key
persist-tun
verb 3
remote-cert-tls server
ping 10
ping-restart 60
sndbuf 524288
rcvbuf 524288
fast-io
auth-user-pass
ca mullvad_ca.crt
tun-ipv6
tls-cipher TLS-DHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA

<ca>
-----BEGIN CERTIFICATE-----
MIIEQjCCAyqgAwIBAgIJAIRoLqBRKrvUMA0GCSqGSIb3DQEBBQUAMHMxCzAJBgNV
BAYTAk5BMQ0wCwYDVQQIEwROb25lMQ0wCwYDVQQHEwROb25lMRAwDgYDVQQKEwdN
dWxsdmFkMRMwEQYDVQQDEwpNdWxsdmFkIENBMR8wHQYJKoZIhvcNAQkBFhBpbmZv
QG11bGx2YWQubmV0MB4XDTA5MDMyNDA2NDcyNVoXDTE5MDMyMjA2NDcyNVowczEL
MAkGA1UEBhMCTkExDTALBgNVBAgTBE5vbmUxDTALBgNVBAcTBE5vbmUxEDAOBgNV
BAoTB011bGx2YWQxEzARBgNVBAMTCk11bGx2YWQgQ0ExHzAdBgkqhkiG9w0BCQEW
EGluZm9AbXVsbHZhZC5uZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB
AQDNNzZOrq+gMaA6wfyWdNFmxlM2OB1czwFgtPiDd9f6F8m6CGYBQog3Q2Wx3yAv
hxt/uchFBCKtYz6Yh59BCxXKfNAQT2uaMC6KAvKFgz0wppi4S8YbWg2KDelNO/Zv
Rb1QT4CBWMbtYzCQZvlJpHr2ZwuXG2OiT477oMyX5Hmf+iT0drmqi+wylRr7CRBs
LBu+fxLZ2LFD5g6MATuL3ql5JLIoVjlSqIgbld74pD4WUnM61HRwFsKoCEjq409Y
QNP1xO7BeaJu3uQvg/HJhXnGZxTatXhqvdCuAPQRppQ4UnkUzxdSTrfgM3hqMony
vX1vy0dX1S8iTQCIeyzAYNObAgMBAAGjgdgwgdUwHQYDVR0OBBYEFOFjtD5Vo9I3
X946kUhRSyAa8pvFMIGlBgNVHSMEgZ0wgZqAFOFjtD5Vo9I3X946kUhRSyAa8pvF
oXekdTBzMQswCQYDVQQGEwJOQTENMAsGA1UECBMETm9uZTENMAsGA1UEBxMETm9u
ZTEQMA4GA1UEChMHTXVsbHZhZDETMBEGA1UEAxMKTXVsbHZhZCBDQTEfMB0GCSqG
SIb3DQEJARYQaW5mb0BtdWxsdmFkLm5ldIIJAIRoLqBRKrvUMAwGA1UdEwQFMAMB
Af8wDQYJKoZIhvcNAQEFBQADggEBAMjMAFPDeFOrQsvMXD/x+CuARwegS2PDZuB5
f1Svw3YDF6cB1jlc0F12nh9SZxaYRwKIlpYoolLCOLoUCLwQJ0gsokxLV7G4gVb8
dzETnNq4HG/QOPwPisjoOCaEmcd0tx1EkyNY0KLqFZTS0VdmDHCn89dDFA/6yuYI
5u04uJs7c/K4qaW7X6ajOOdneqjbtPeVOvx9DWXHxA0xz4Y+/w4laX/OTRD7jySq
K9fLfRliE5zsxzpUr5EWxAnqiABoWL71SiItk5fG8k3MJJ9SVr+YnTHmE7S4KNqu
4wTksvkb0Tmjae1lRSlMd6u2AulAxVcVKAod2QVffhj+hdkYM94=
-----END CERTIFICATE-----
</ca>

 

Link to comment
Share on other sites

4 hours ago, Netduma Fraser said:

Okay so there could be a few variations trying to get this to work, please try the following:

Satus Connecting and Failled

Sun Dec 16 17:22:40 2018 OpenVPN 2.3.4 mips-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  4 2018
Sun Dec 16 17:22:40 2018 library versions: OpenSSL 1.0.1h 5 Jun 2014, LZO 2.06
Sun Dec 16 17:22:40 2018 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Dec 16 17:22:40 2018 Socket Buffers: R=[163840->327680] S=[163840->327680]
Sun Dec 16 17:22:40 2018 UDPv4 link local: [undef]
Sun Dec 16 17:22:40 2018 UDPv4 link remote: [AF_INET]185.236.200.66:1302
Sun Dec 16 17:22:41 2018 TLS: Initial packet from [AF_INET]185.236.200.66:1302, sid=54be1aea e84559d7
Sun Dec 16 17:22:41 2018 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Sun Dec 16 17:22:41 2018 VERIFY OK: depth=3, C=NA, ST=None, L=None, O=Mullvad, CN=Mullvad CA, [email protected]
Sun Dec 16 17:22:41 2018 VERIFY OK: depth=2, C=NA, ST=None, L=None, O=Mullvad, CN=master.mullvad.net, [email protected]
Sun Dec 16 17:22:41 2018 VERIFY OK: depth=1, C=SE, ST=Gotaland, O=Amagicom AB, OU=Mullvad, CN=Mullvad Transition-Intermediate CA v1, [email protected]
Sun Dec 16 17:22:41 2018 Validating certificate key usage
Sun Dec 16 17:22:41 2018 ++ Certificate has key usage  00a0, expects 00a0
Sun Dec 16 17:22:41 2018 VERIFY KU OK
Sun Dec 16 17:22:41 2018 Validating certificate extended key usage
Sun Dec 16 17:22:41 2018 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Sun Dec 16 17:22:41 2018 VERIFY EKU OK
Sun Dec 16 17:22:41 2018 VERIFY OK: depth=0, C=SE, ST=Gotaland, O=Amagicom AB, OU=Mullvad, CN=us-lax-005.mullvad.net, [email protected]
Sun Dec 16 17:22:47 2018 Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Sun Dec 16 17:22:47 2018 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Sun Dec 16 17:22:47 2018 Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Sun Dec 16 17:22:47 2018 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Sun Dec 16 17:22:47 2018 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 4096 bit RSA
Sun Dec 16 17:22:47 2018 [us-lax-005.mullvad.net] Peer Connection Initiated with [AF_INET]185.236.200.66:1302
Sun Dec 16 17:22:49 2018 SENT CONTROL [us-lax-005.mullvad.net]: 'PUSH_REQUEST' (status=1)
Sun Dec 16 17:22:50 2018 PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 10.16.0.1,redirect-gateway def1 bypass-dhcp,route-ipv6 0000::/2,route-ipv6 4000::/2,route-ipv6 8000::/2,route-ipv6 C000::/2,comp-lzo no,route-gateway 10.16.0.1,topology subnet,socket-flags TCP_NODELAY,ifconfig-ipv6 fdda:d0d0:cafe:1302::1006/64 fdda:d0d0:cafe:1302::,ifconfig 10.16.0.8 255.255.0.0'
Sun Dec 16 17:22:50 2018 OPTIONS IMPORT: --socket-flags option modified
Sun Dec 16 17:22:50 2018 NOTE: setsockopt TCP_NODELAY=1 failed
Sun Dec 16 17:22:50 2018 OPTIONS IMPORT: --ifconfig/up options modified
Sun Dec 16 17:22:50 2018 OPTIONS IMPORT: route options modified
Sun Dec 16 17:22:50 2018 OPTIONS IMPORT: route-related options modified
Sun Dec 16 17:22:50 2018 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Sun Dec 16 17:22:50 2018 TUN/TAP device tun0 opened
Sun Dec 16 17:22:50 2018 TUN/TAP TX queue length set to 100
Sun Dec 16 17:22:50 2018 do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1
Sun Dec 16 17:22:50 2018 /sbin/ifconfig tun0 10.16.0.8 netmask 255.255.0.0 mtu 1500 broadcast 10.16.255.255
Sun Dec 16 17:22:50 2018 /sbin/ifconfig tun0 add fdda:d0d0:cafe:1302::1006/64
ifconfig: SIOCSIFADDR: Permission denied
Sun Dec 16 17:22:50 2018 Linux ifconfig inet6 failed: external program exited with error status: 1
Sun Dec 16 17:22:50 2018 Exiting due to fatal error

Link to comment
Share on other sites

  • Administrators

Try this: 

client
dev tun
proto udp
remote us-ca.mullvad.net 1195
cipher AES-256-CBC
resolv-retry infinite
nobind
persist-key
persist-tun
verb 3
remote-cert-tls server
ping 10
ping-restart 60
sndbuf 524288
rcvbuf 524288
fast-io
auth-user-pass
reneg-sec 0
tun-ipv6
<ca>
-----BEGIN CERTIFICATE-----
MIIGIzCCBAugAwIBAgIJAK6BqXN9GHI0MA0GCSqGSIb3DQEBCwUAMIGfMQswCQYD
VQQGEwJTRTERMA8GA1UECAwIR290YWxhbmQxEzARBgNVBAcMCkdvdGhlbmJ1cmcx
FDASBgNVBAoMC0FtYWdpY29tIEFCMRAwDgYDVQQLDAdNdWxsdmFkMRswGQYDVQQD
DBJNdWxsdmFkIFJvb3QgQ0EgdjIxIzAhBgkqhkiG9w0BCQEWFHNlY3VyaXR5QG11
bGx2YWQubmV0MB4XDTE4MTEwMjExMTYxMVoXDTI4MTAzMDExMTYxMVowgZ8xCzAJ
BgNVBAYTAlNFMREwDwYDVQQIDAhHb3RhbGFuZDETMBEGA1UEBwwKR290aGVuYnVy
ZzEUMBIGA1UECgwLQW1hZ2ljb20gQUIxEDAOBgNVBAsMB011bGx2YWQxGzAZBgNV
BAMMEk11bGx2YWQgUm9vdCBDQSB2MjEjMCEGCSqGSIb3DQEJARYUc2VjdXJpdHlA
bXVsbHZhZC5uZXQwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCifDn7
5E/Zdx1qsy31rMEzuvbTXqZVZp4bjWbmcyyXqvnayRUHHoovG+lzc+HDL3HJV+kj
xKpCMkEVWwjY159lJbQbm8kkYntBBREdzRRjjJpTb6haf/NXeOtQJ9aVlCc4dM66
bEmyAoXkzXVZTQJ8h2FE55KVxHi5Sdy4XC5zm0wPa4DPDokNp1qm3A9Xicq3Hsfl
LbMZRCAGuI+Jek6caHqiKjTHtujn6Gfxv2WsZ7SjerUAk+mvBo2sfKmB7octxG7y
AOFFg7YsWL0AxddBWqgq5R/1WDJ9d1Cwun9WGRRQ1TLvzF1yABUerjjKrk89RCzY
ISwsKcgJPscaDqZgO6RIruY/xjuTtrnZSv+FXs+Woxf87P+QgQd76LC0MstTnys+
AfTMuMPOLy9fMfEzs3LP0Nz6v5yjhX8ff7+3UUI3IcMxCvyxdTPClY5IvFdW7CCm
mLNzakmx5GCItBWg/EIg1K1SG0jU9F8vlNZUqLKz42hWy/xB5C4QYQQ9ILdu4ara
PnrXnmd1D1QKVwKQ1DpWhNbpBDfE776/4xXD/tGM5O0TImp1NXul8wYsDi8g+e0p
xNgY3Pahnj1yfG75Yw82spZanUH0QSNoMVMWnmV2hXGsWqypRq0pH8mPeLzeKa82
gzsAZsouRD1k8wFlYA4z9HQFxqfcntTqXuwQcQIDAQABo2AwXjAdBgNVHQ4EFgQU
faEyaBpGNzsqttiSMETq+X/GJ0YwHwYDVR0jBBgwFoAUfaEyaBpGNzsqttiSMETq
+X/GJ0YwCwYDVR0PBAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQEL
BQADggIBADH5izxu4V8Javal8EA4DxZxIHUsWCg5cuopB28PsyJYpyKipsBoI8+R
XqbtrLLue4WQfNPZHLXlKi+A3GTrLdlnenYzXVipPd+n3vRZyofaB3Jtb03nirVW
Ga8FG21Xy/f4rPqwcW54lxrnnh0SA0hwuZ+b2yAWESBXPxrzVQdTWCqoFI6/aRnN
8RyZn0LqRYoW7WDtKpLmfyvshBmmu4PCYSh/SYiFHgR9fsWzVcxdySDsmX8wXowu
Ffp8V9sFhD4TsebAaplaICOuLUgj+Yin5QzgB0F9Ci3Zh6oWwl64SL/OxxQLpzMW
zr0lrWsQrS3PgC4+6JC4IpTXX5eUqfSvHPtbRKK0yLnd9hYgvZUBvvZvUFR/3/fW
+mpBHbZJBu9+/1uux46M4rJ2FeaJUf9PhYCPuUj63yu0Grn0DreVKK1SkD5V6qXN
0TmoxYyguhfsIPCpI1VsdaSWuNjJ+a/HIlKIU8vKp5iN/+6ZTPAg9Q7s3Ji+vfx/
AhFtQyTpIYNszVzNZyobvkiMUlK+eUKGlHVQp73y6MmGIlbBbyzpEoedNU4uFu57
mw4fYGHqYZmYqFaiNQv4tVrGkg6p+Ypyu1zOfIHF7eqlAOu/SyRTvZkt9VtSVEOV
H7nDIGdrCC9U/g1Lqk8Td00Oj8xesyKzsG214Xd8m7/7GmJ7nXe5
-----END CERTIFICATE-----
</ca>
<crt>
-----BEGIN CERTIFICATE-----
MIIGHDCCBASgAwIBAgIEEAAAADANBgkqhkiG9w0BAQsFADCBnzELMAkGA1UEBhMC
U0UxETAPBgNVBAgMCEdvdGFsYW5kMRMwEQYDVQQHDApHb3RoZW5idXJnMRQwEgYD
VQQKDAtBbWFnaWNvbSBBQjEQMA4GA1UECwwHTXVsbHZhZDEbMBkGA1UEAwwSTXVs
bHZhZCBSb290IENBIHYyMSMwIQYJKoZIhvcNAQkBFhRzZWN1cml0eUBtdWxsdmFk
Lm5ldDAeFw0xODExMDIxMTI2MDNaFw0xOTExMDIxMTI2MDNaMIGdMQswCQYDVQQG
EwJTRTERMA8GA1UECAwIR290YWxhbmQxFDASBgNVBAoMC0FtYWdpY29tIEFCMRAw
DgYDVQQLDAdNdWxsdmFkMS4wLAYDVQQDDCVNdWxsdmFkIFRyYW5zaXRpb24tSW50
ZXJtZWRpYXRlIENBIHYxMSMwIQYJKoZIhvcNAQkBFhRzZWN1cml0eUBtdWxsdmFk
Lm5ldDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAOAvizkx9wPHo9qH
TKdSe1ckgoe20PsN++pAnIZ1ZrrUAW/Y/7HjeZvPH1nJHWtQaoY72mQKbl3WVafZ
THm+t0qtnAGcI+1dZjAERmPBZyVtbsOegITqWiAyw5QGfq/+pmC752a8NxHy73Pt
cvt81vML87dx0vzOm2IPCr2mdsdxMsoETuBCED/gY6N4BEnK/NS5JjNnpynq4bZb
obzKuLKTmFabU5CVttg7eBcI4O6KhOYbP4T6Xpo+ALRN7+fyAjir2YKIifccftf5
eiB23Ov1kt9k4nIc3lt6tDHaz6INPHjigHJ2AuJDb7V3GH0czdu2Elr5tZC+5sDX
NcMSOPNA9L4o9svA553c21tg/1cwKUD3GJoCzIN9k9+ba9VWnpOiebNakdTUlegy
5LlzO+aVpZbMoAHoP/1PHqPe9Nz62vrt2wtTfuP5cTCHkTIFy6X6LWitWmox3lLo
aaruQ2x6WF64bGuFHKLDlMNRWd63GE/ZE3AXTmmYIE+CgZ6aPyFuUluAA9C6r7bU
052ddBIuQLBZ2Pj4yZ0UK2aymjS4OBYddzLkPM4B5Mttcj3nbk8FKHDHTXLlyIvE
9BQAejH2p+sOboWudHyw7B7kDqWt9aHHYrQbSimnaY6QoJ8VisyFZVrrIQMQxwLw
AvBScVkmBDTP1iG0B4tGzCRTIilPAgMBAAGjYDBeMB0GA1UdDgQWBBQVxpaQ55d1
yngyg7YEXMuTDc9hPzAfBgNVHSMEGDAWgBR9oTJoGkY3Oyq22JIwROr5f8YnRjAL
BgNVHQ8EBAMCAQYwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAgEA
STee9JP7tegxul90VTRyG53l37fuZGjrp70tYQfl8676lTyFyZVBF7tAFrJwc1K9
2d1JnMbyHzyR7LzZr/7tB3w7eIR8Q7TiBAe9eHleMlmK975ivcAhrY0fJ+BO8xgw
6KE7dOI1jeeff5wF/2KmXybeq2M1phA3KGy+sxc8KrLCVHfXfOnv+b9HRKDqE4/c
3ALMVHXir9sXDyY5bH7jcOGyVQTPI5ZLxvjndunCkXG595pJqDqUWXS8BYcFExIf
IQuJ5omt+tyM9U17yOPvwTyadbRW2m7LIcTwPEwC3IUHCUQzqLZkmF2pCQa8hV2b
q3eK/hV1mHvFbfZcQ+TPl8vl4cRT92vLQGGy51D9t8bVs4bBET0DSPivVcnMqkSO
vAz7xdXqya36iri27iI3aUdBI/XihT1LkxAJhas9YBt+T2xz7xN+WU/ImB+Cq+sH
nJNIcB+wE50/rBb+gTaOpEx80Onq277N3TUByVLjCztl1J6cWIy1XObhRVgXLUcT
B6/Z/zRblHt7f/f5TTUmAwMc+VwvnjpweSV98DpP0MLV6ZEpmh/ij0Dwpc6IoD8u
Lwvyq9jhkSAki5LHO2t1mw0jIjtncxEq/9RmrVP1e3/weYvyhy1T4Mq4NCcPGFR0
+TUxbjSUGVUuHIPxiR+XptxDWguRhwSYEKSy3EwfOMc=
-----END CERTIFICATE-----
</crt>
tls-cipher TLS-DHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA

 

Link to comment
Share on other sites

57 minutes ago, Netduma Fraser said:

Yeah that has a key on the end which I think we need but your provider don't seem to have it. 

Could you make a ticket with them to obtain the client, ca, cert and key parts of the config?

I did it, as soon as I have new information I come back to you, thank you

Link to comment
Share on other sites

13 hours ago, Netduma Fraser said:

Yeah that has a key on the end which I think we need but your provider don't seem to have it. 

Could you make a ticket with them to obtain the client, ca, cert and key parts of the config?

the answer of the support :

2018-12-16_2201.png

Link to comment
Share on other sites

  • Administrators

Thanks - have been using your account as the username and 'm' as the password?

It's worth letting them know you're using a DumaOS powered router as you will not be the last to have this issue with them. VPN providers are usually good at putting instructions online once they've helped someone to get it working.

Link to comment
Share on other sites

Mullvad VPN make a fix and that is the script, all is good now ; thanks you 

client
dev tun
proto udp
remote-random
remote us-lax-001.mullvad.net 1402
cipher AES-256-CBC
resolv-retry infinite
nobind
persist-key
persist-tun
verb 3
remote-cert-tls server
ping 10
ping-restart 60
sndbuf 524288
rcvbuf 524288
fast-io
auth-user-pass
reneg-sec 0
<ca>
-----BEGIN CERTIFICATE-----
MIIGIzCCBAugAwIBAgIJAK6BqXN9GHI0MA0GCSqGSIb3DQEBCwUAMIGfMQswCQYD
VQQGEwJTRTERMA8GA1UECAwIR290YWxhbmQxEzARBgNVBAcMCkdvdGhlbmJ1cmcx
FDASBgNVBAoMC0FtYWdpY29tIEFCMRAwDgYDVQQLDAdNdWxsdmFkMRswGQYDVQQD
DBJNdWxsdmFkIFJvb3QgQ0EgdjIxIzAhBgkqhkiG9w0BCQEWFHNlY3VyaXR5QG11
bGx2YWQubmV0MB4XDTE4MTEwMjExMTYxMVoXDTI4MTAzMDExMTYxMVowgZ8xCzAJ
BgNVBAYTAlNFMREwDwYDVQQIDAhHb3RhbGFuZDETMBEGA1UEBwwKR290aGVuYnVy
ZzEUMBIGA1UECgwLQW1hZ2ljb20gQUIxEDAOBgNVBAsMB011bGx2YWQxGzAZBgNV
BAMMEk11bGx2YWQgUm9vdCBDQSB2MjEjMCEGCSqGSIb3DQEJARYUc2VjdXJpdHlA
bXVsbHZhZC5uZXQwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCifDn7
5E/Zdx1qsy31rMEzuvbTXqZVZp4bjWbmcyyXqvnayRUHHoovG+lzc+HDL3HJV+kj
xKpCMkEVWwjY159lJbQbm8kkYntBBREdzRRjjJpTb6haf/NXeOtQJ9aVlCc4dM66
bEmyAoXkzXVZTQJ8h2FE55KVxHi5Sdy4XC5zm0wPa4DPDokNp1qm3A9Xicq3Hsfl
LbMZRCAGuI+Jek6caHqiKjTHtujn6Gfxv2WsZ7SjerUAk+mvBo2sfKmB7octxG7y
AOFFg7YsWL0AxddBWqgq5R/1WDJ9d1Cwun9WGRRQ1TLvzF1yABUerjjKrk89RCzY
ISwsKcgJPscaDqZgO6RIruY/xjuTtrnZSv+FXs+Woxf87P+QgQd76LC0MstTnys+
AfTMuMPOLy9fMfEzs3LP0Nz6v5yjhX8ff7+3UUI3IcMxCvyxdTPClY5IvFdW7CCm
mLNzakmx5GCItBWg/EIg1K1SG0jU9F8vlNZUqLKz42hWy/xB5C4QYQQ9ILdu4ara
PnrXnmd1D1QKVwKQ1DpWhNbpBDfE776/4xXD/tGM5O0TImp1NXul8wYsDi8g+e0p
xNgY3Pahnj1yfG75Yw82spZanUH0QSNoMVMWnmV2hXGsWqypRq0pH8mPeLzeKa82
gzsAZsouRD1k8wFlYA4z9HQFxqfcntTqXuwQcQIDAQABo2AwXjAdBgNVHQ4EFgQU
faEyaBpGNzsqttiSMETq+X/GJ0YwHwYDVR0jBBgwFoAUfaEyaBpGNzsqttiSMETq
+X/GJ0YwCwYDVR0PBAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQEL
BQADggIBADH5izxu4V8Javal8EA4DxZxIHUsWCg5cuopB28PsyJYpyKipsBoI8+R
XqbtrLLue4WQfNPZHLXlKi+A3GTrLdlnenYzXVipPd+n3vRZyofaB3Jtb03nirVW
Ga8FG21Xy/f4rPqwcW54lxrnnh0SA0hwuZ+b2yAWESBXPxrzVQdTWCqoFI6/aRnN
8RyZn0LqRYoW7WDtKpLmfyvshBmmu4PCYSh/SYiFHgR9fsWzVcxdySDsmX8wXowu
Ffp8V9sFhD4TsebAaplaICOuLUgj+Yin5QzgB0F9Ci3Zh6oWwl64SL/OxxQLpzMW
zr0lrWsQrS3PgC4+6JC4IpTXX5eUqfSvHPtbRKK0yLnd9hYgvZUBvvZvUFR/3/fW
+mpBHbZJBu9+/1uux46M4rJ2FeaJUf9PhYCPuUj63yu0Grn0DreVKK1SkD5V6qXN
0TmoxYyguhfsIPCpI1VsdaSWuNjJ+a/HIlKIU8vKp5iN/+6ZTPAg9Q7s3Ji+vfx/
AhFtQyTpIYNszVzNZyobvkiMUlK+eUKGlHVQp73y6MmGIlbBbyzpEoedNU4uFu57
mw4fYGHqYZmYqFaiNQv4tVrGkg6p+Ypyu1zOfIHF7eqlAOu/SyRTvZkt9VtSVEOV
H7nDIGdrCC9U/g1Lqk8Td00Oj8xesyKzsG214Xd8m7/7GmJ7nXe5
-----END CERTIFICATE-----
</ca>
tls-cipher TLS-DHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA

 

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...