Score:0

Self hosted ocserv reject clients

bz flag
M.J

I deployed an ocserv on my VPS but my android client raise below error:

AnyConnect

Connection attempt has timed out. Please verify Internet connectivity.

I stop ocserv service on the VPS and run as debug mode, output messages of ocserv when this client try to connect is:

# /usr/sbin/ocserv --foreground --pid-file /tmp/ocserv.pid --config /etc/ocserv/ocserv.conf --debug=10
note: skipping 'pid-file' config option                                                                   
note: vhost:default: setting 'plain' as primary authentication method                        
note: setting 'file' as supplemental config option                                                        
listening (TCP) on 0.0.0.0:443...      
listening (TCP) on [::]:443...                                                                            
ocserv[2166087]: main: Starting 1 instances of ocserv-sm             
ocserv[2166087]: main: created sec-mod socket file (/tmp/ocserv.socket.8ebc1713.0)
ocserv[2166087]: main: initializing control unix socket: /var/run/occtl.socket        
ocserv[2166087]: main: initialized ocserv 1.1.3   
ocserv[2166088]: sec-mod: reading supplemental config from files
ocserv[2166088]: TLS[<3>]: ASSERT: ../../../lib/x509/attributes.c[_x509_parse_attribute]:103
ocserv[2166088]: TLS[<3>]: ASSERT: ../../../lib/x509/attributes.c[_x509_parse_attribute]:174
ocserv[2166088]: sec-mod: loaded 1 keys    
ocserv[2166088]: sec-mod: sec-mod initialized (socket: /tmp/ocserv.socket.8ebc1713.0)
                                                                                                          
                                                     
                                                                                                          
ocserv[2166087]: main: added 1 points (total 1) for IP 'xxx.xxx.xxx.xxx' to ban list
note: skipping 'pid-file' config option         
note: vhost:default: setting 'plain' as primary authentication method                 
ocserv[2166088]: sec-mod: received request from pid 2166314 and uid 0
ocserv[2166088]: sec-mod: cmd [size=57] sm: sign                                                          
ocserv[2166088]: TLS[<3>]: ASSERT: ../../../lib/nettle/mpi.c[wrap_nettle_mpi_print]:60
note: setting 'file' as supplemental config option
ocserv[2166314]: worker: xxx.xxx.xxx.xxx accepted connection             
ocserv[2166087]: main: added 1 points (total 2) for IP 'xxx.xxx.xxx.xxx' to ban list
note: skipping 'pid-file' config option         
note: vhost:default: setting 'plain' as primary authentication method                 
ocserv[2166088]: sec-mod: received request from pid 2166707 and uid 0
ocserv[2166088]: sec-mod: cmd [size=57] sm: sign                                                          
ocserv[2166088]: TLS[<3>]: ASSERT: ../../../lib/nettle/mpi.c[wrap_nettle_mpi_print]:60
note: setting 'file' as supplemental config option                                                        
ocserv[2166707]: worker: xxx.xxx.xxx.xxx accepted connection
ocserv[2166087]: main: added 1 points (total 3) for IP 'xxx.xxx.xxx.xxx' to ban list
note: skipping 'pid-file' config option
note: vhost:default: setting 'plain' as primary authentication method
ocserv[2166088]: sec-mod: received request from pid 2167044 and uid 0
ocserv[2166088]: sec-mod: cmd [size=57] sm: sign
ocserv[2166088]: TLS[<3>]: ASSERT: ../../../lib/nettle/mpi.c[wrap_nettle_mpi_print]:60
note: setting 'file' as supplemental config option
ocserv[2167044]: worker: xxx.xxx.xxx.xxx accepted connection
ocserv[2166087]: main: Latency: Median Total 0 RMS Total 0 Sample Count 0
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.