Пытаюсь настроить канал с офисами. вот конф сервера:
port 1194
proto udp
dev tun
ca /etc/ssl/ca-cert.pem
cert /etc/ssl/sys-0-cert.pem
key /etc/ssl/private/sys-0-key.pem
dh /etc/ssl/dh1024.pem
server 192.168.6.0 255.255.255.0
keepalive 10 120
comp-lzo
user nobody
group nobody
persist-key
persist-tun
ifconfig-pool-persist /var/lib/openvpn/ipp.txt
status /var/lib/openvpn/openvpn-status.log
verb 3
route 192.168.4.0 255.255.255.0
route 192.168.5.0 255.255.255.0
plugin /usr/share/openvpn/plugin/lib/openvpn-auth-ldap.so /etc/openvpn/auth-ldap
push "dhcp-option DNS 192.168.3.105"
push "dhcp-option WINS 192.168.3.105"
push "dhcp-option DOMAIN myapteka.com"
push "route 192.168.3.0 255.255.255.0"Вот конфиг клиента
client
remote (ip адрес сервера белый) 1194
dev tun
proto udp
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca-cert.pem
cert client-rob-cert.pem
key client-rob-key.pem
ns-cert-type server
comp-lzo
verb 3
auth-user-pass
Соединяется но пишет ошибку:
Mon Apr 06 11:53:50 2015 VERIFY ERROR: depth=1, error=certificate has expired: O=org, OU=Krasnodar, emailAddress=security@mail.com, L=Krasnodar, ST=Krasnodar, C=RU, CN=ca.mail.com
Mon Apr 06 11:53:50 2015 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
Mon Apr 06 11:53:50 2015 TLS Error: TLS object -> incoming plaintext read error
Mon Apr 06 11:53:50 2015 TLS Error: TLS handshake failed
Mon Apr 06 11:53:50 2015 SIGUSR1[soft,tls-error] received, process restarting
Mon Apr 06 11:53:50 2015 MANAGEMENT: >STATE:1428306830,RECONNECTING,tls-error,,
Mon Apr 06 11:53:50 2015 Restart pause, 2 second(s)
Mon Apr 06 11:53:52 2015 SIGTERM[hard,init_instance] received, process exiting
Mon Apr 06 11:53:52 2015 MANAGEMENT: >STATE:1428306832,EXITING,init_instance,,
Где проблема?