indicates that OpenConnect (or the underlying OpenSSL library) is rejecting the VPN server's attempt to use unsafe legacy SSL renegotiation. This is a security feature in modern OpenSSL versions to prevent vulnerabilities like the CRIME attack.
Why This Happens
The VPN server (vpn-CENSORED-CENSORED.CENSORED.fr) is using an outdated or insecure SSL/TLS configuration that relies on legacy renegotiation.
OpenSSL (used by openconnect) now disables unsafe legacy renegotiation by default for security reasons.
You can temporarily allow unsafe legacy renegotiation by setting the OPENSSL_ALLOW_UNSAFE_LEGACY_RENEGOTIATION environment variable before running openconnect:
If you have control over the VPN server, update its SSL/TLS configuration to disable legacy renegotiation and use modern, secure protocols (e.g., TLS 1.2+).
Option 5: Use a Different VPN Client
If the issue persists, try using the official GlobalProtect VPN client (if available for Linux) or another OpenConnect-compatible client.
Recommended Next Steps
Try Option 1 (temporary workaround) to confirm if the issue is indeed legacy renegotiation.
If it works, contact your VPN administrator to update the server's SSL/TLS configuration.
If you're uncomfortable with the security trade-off, ask the admin for a secure alternative.
Sep 11, 11:45pm
This is a shared conversation and may include unverified content that doesn't reflect Mistral AI's views. Login to resume chatting.