Re: OpenVPN + rutoken + неэкспортируемая пара ГОСТ = возможно? (решено!)
Ура!!! пошла:
Mon Aug 17 16:34:34 2020 WARNING: Ignoring option 'dh' in tls-client mode, please only include this in your server configuration
Mon Aug 17 16:34:34 2020 OpenVPN 2.4.9 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Aug 17 2020
Mon Aug 17 16:34:34 2020 Windows version 6.1 (Windows 7) 64bit
Mon Aug 17 16:34:34 2020 library versions: OpenSSL 1.1.0l 10 Sep 2019, LZO 2.10
Mon Aug 17 16:34:34 2020 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25341
Mon Aug 17 16:34:34 2020 Need hold release from management interface, waiting...
Mon Aug 17 16:34:34 2020 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25341
Mon Aug 17 16:34:34 2020 MANAGEMENT: CMD 'state on'
Mon Aug 17 16:34:34 2020 MANAGEMENT: CMD 'log all on'
Mon Aug 17 16:34:34 2020 MANAGEMENT: CMD 'echo all on'
Mon Aug 17 16:34:34 2020 MANAGEMENT: CMD 'bytecount 5'
Mon Aug 17 16:34:34 2020 MANAGEMENT: CMD 'hold off'
Mon Aug 17 16:34:34 2020 MANAGEMENT: CMD 'hold release'
Mon Aug 17 16:34:34 2020 PKCS#11: Adding PKCS#11 provider 'rtPKCS11ECP.dll'
Mon Aug 17 16:34:34 2020 Initializing OpenSSL support for engine 'gost'
Mon Aug 17 16:34:35 2020 Outgoing Control Channel Authentication: Using 512 bit message hash 'md_gost12_512' for HMAC authentication
Mon Aug 17 16:34:35 2020 Incoming Control Channel Authentication: Using 512 bit message hash 'md_gost12_512' for HMAC authentication
Mon Aug 17 16:34:35 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]10.x.x.190:1194
Mon Aug 17 16:34:35 2020 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Aug 17 16:34:35 2020 Attempting to establish TCP connection with [AF_INET]10.x.x.190:1194 [nonblock]
Mon Aug 17 16:34:35 2020 MANAGEMENT: >STATE:1597649675,TCP_CONNECT,,,,,,
Mon Aug 17 16:34:36 2020 TCP connection established with [AF_INET]10.x.x.190:1194
Mon Aug 17 16:34:36 2020 TCP_CLIENT link local: (not bound)
Mon Aug 17 16:34:36 2020 TCP_CLIENT link remote: [AF_INET]10.x.x.190:1194
Mon Aug 17 16:34:36 2020 MANAGEMENT: >STATE:1597649676,WAIT,,,,,,
Mon Aug 17 16:34:36 2020 MANAGEMENT: >STATE:1597649676,AUTH,,,,,,
Mon Aug 17 16:34:36 2020 TLS: Initial packet from [AF_INET]10.x.x.190:1194, sid=00b8a630 aa030866
Mon Aug 17 16:34:36 2020 VERIFY OK: depth=1, C=RU, ST=28 ....
Mon Aug 17 16:34:36 2020 VERIFY KU OK
Mon Aug 17 16:34:36 2020 Validating certificate extended key usage
Mon Aug 17 16:34:36 2020 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Mon Aug 17 16:34:36 2020 VERIFY EKU OK
Mon Aug 17 16:34:36 2020 VERIFY OK: depth=0, C=RU, ST=28 ...
Mon Aug 17 16:34:39 2020 MANAGEMENT: CMD 'password [...]'
Mon Aug 17 16:34:40 2020 Control Channel: TLSv1.2, cipher TLSv1.0 GOST2012-GOST8912-GOST8912
Mon Aug 17 16:34:40 2020 [З...] Peer Connection Initiated with [AF_INET]10.x.x.190:1194
Mon Aug 17 16:34:41 2020 MANAGEMENT: >STATE:1597649681,GET_CONFIG,,,,,,
Mon Aug 17 16:34:41 2020 SENT CONTROL [З...]: 'PUSH_REQUEST' (status=1)
Mon Aug 17 16:34:41 2020 PUSH: Received control message: 'PUSH_REPLY,route 10.х.х.0 255.255.248.0,route-gateway 10.x.x.1,ping 10,ping-restart 120,ifconfig 10.x.x.2 255.255.255.0,peer-id 0'
Mon Aug 17 16:34:41 2020 OPTIONS IMPORT: timers and/or timeouts modified
Mon Aug 17 16:34:41 2020 OPTIONS IMPORT: --ifconfig/up options modified
Mon Aug 17 16:34:41 2020 OPTIONS IMPORT: route options modified
Mon Aug 17 16:34:41 2020 OPTIONS IMPORT: route-related options modified
Mon Aug 17 16:34:41 2020 OPTIONS IMPORT: peer-id set
Mon Aug 17 16:34:41 2020 OPTIONS IMPORT: adjusting link_mtu to 1658
Mon Aug 17 16:34:41 2020 Outgoing Data Channel: Cipher 'grasshopper-cbc' initialized with 256 bit key
Mon Aug 17 16:34:41 2020 Outgoing Data Channel: Using 512 bit message hash 'md_gost12_512' for HMAC authentication
Mon Aug 17 16:34:41 2020 Incoming Data Channel: Cipher 'grasshopper-cbc' initialized with 256 bit key
Mon Aug 17 16:34:41 2020 Incoming Data Channel: Using 512 bit message hash 'md_gost12_512' for HMAC authentication
Mon Aug 17 16:34:41 2020 interactive service msg_channel=0
Mon Aug 17 16:34:41 2020 ROUTE_GATEWAY 10.x.x.129/255.255.255.192 I=11 HWADDR=00:1d:0f:be:fa:bb
Mon Aug 17 16:34:41 2020 open_tun
Mon Aug 17 16:34:41 2020 TAP-WIN32 device [Подключение по локальной сети 2] opened: \\.\Global\{B2D272BC-FB6A-4E7F-AEF5-3C0369CD9AB3}.tap
Mon Aug 17 16:34:41 2020 TAP-Windows Driver Version 9.21
Mon Aug 17 16:34:41 2020 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.x.x.2/255.255.255.0 on interface {B2D272BC-FB6A-4E7F-AEF5-3C0369CD9AB3} [DHCP-serv: 10.x.x.0, lease-time: 31536000]
Mon Aug 17 16:34:41 2020 Successful ARP Flush on interface [17] {B2D272BC-FB6A-4E7F-AEF5-3C0369CD9AB3}
Mon Aug 17 16:34:41 2020 MANAGEMENT: >STATE:1597649681,ASSIGN_IP,,10.x.x.2,,,,
Mon Aug 17 16:34:46 2020 TEST ROUTES: 1/1 succeeded len=1 ret=1 a=0 u/d=up
Mon Aug 17 16:34:46 2020 MANAGEMENT: >STATE:1597649686,ADD_ROUTES,,,,,,
Mon Aug 17 16:34:46 2020 C:\Windows\system32\route.exe ADD 10.x.x.0 MASK 255.255.248.0 10.x.x.1
Mon Aug 17 16:34:46 2020 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=20 and dwForwardType=4
Mon Aug 17 16:34:46 2020 Route addition via IPAPI succeeded [adaptive]
Mon Aug 17 16:34:46 2020 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Mon Aug 17 16:34:46 2020 Initialization Sequence Completed
Mon Aug 17 16:34:46 2020 MANAGEMENT: >STATE:1597649686,CONNECTED,SUCCESS,10.x.x.2,10.x.x.190,1194,127.0.0.1,49281