Summary: | [Openconnect] Will not connect to openconnect vpn if CN in untrusted certificate does not match the host name | ||
---|---|---|---|
Product: | [Plasma] plasmashell | Reporter: | Robert Demski <drdemsey> |
Component: | Networks widget | Assignee: | Jan Grulich <jgrulich> |
Status: | RESOLVED INTENTIONAL | ||
Severity: | major | CC: | jgrulich, lukas, mpapet |
Priority: | NOR | ||
Version First Reported In: | master | ||
Target Milestone: | 1.0 | ||
Platform: | Other | ||
OS: | Linux | ||
Latest Commit: | Version Fixed In: | ||
Sentry Crash Report: |
Description
Robert Demski
2015-11-08 19:16:04 UTC
I believe that this bug got fixed in Plasma 5.5.1, can you confirm that? As of 4/22/16, Debian Testing distro, this is an issue. Background: Debian Testing, KDE desktop install from the "tasksel" menu. There is nothing fancy going on with the install. Cisco VPN host isn't going to get their cert signed. 1. Add Openconnect network via the NetworkManager KDE applet. 2. Launch the openconnect network via the KDE applet. 3. VPN Secrets GUI opens with the appropriate IP address. 4. Click the "connect" button. 5. GUI opens with "Check failed for certificate from VPN server "xx.yy.zz.aa" Reason: signer not found. Accetpt it anyway?" Select "okay" 6. "Accept anyway" goes away and VPN secrets GUI is refreshed with error "Failed to open HTTPS connection to xx.yy.zz.aa. Expected behavior: Enter user password Actual behavior: No opportunity to enter a password, no opportunity to ignore cert check. Workaround, as root "openconnect --no-cert-check xx.yy.zz.aa" FYI, Debian's package information. plasma-nm 4:5.4.3-1 amd64 Plasma5 networkmanager library. Is this still reproducible with Plasma 5.5.1 or newer? Closing. Please reopen if this issue is still reproducible with latest Plasma release. Bulk transfer as requested in T17796 |