On Debian 13 GNOME, how to solve the error:

```bash
ls_secret CENSORED | sudo ./openconnect --verbose -s 'INTERNAL_IP4_DNS= /usr/share/vpnc-scripts/vpnc-script' --protocol=gp vpn-CENSORED-CENSORED.CENSORED.fr -u benjamin.loison
```
```
POST https://vpn-CENSORED-CENSORED.CENSORED.fr/global-protect/prelogin.esp?tmp=tmp&clientVer=4100&clientos=Linux
Attempting to connect to server XXX.XXX.XXX.XXX:443
Connected to XXX.XXX.XXX.XXX:443
SSL negotiation with vpn-CENSORED-CENSORED.CENSORED.fr
SSL connection failure
80F7232AEF7F0000:error:0A000152:SSL routines:final_renegotiate:unsafe legacy renegotiation disabled:../ssl/statem/extensions.c:893:
Failed to open HTTPS connection to vpn-CENSORED-CENSORED.CENSORED.fr
Failed to complete authentication
```

?
Sep 11, 11:45pm

The error you're encountering:

text
80F7232AEF7F0000:error:0A000152:SSL routines:final_renegotiate:unsafe legacy renegotiation disabled:../ssl/statem/extensions.c:893:

indicates that OpenConnect (or the underlying OpenSSL library) is rejecting the VPN server's attempt to use unsafe legacy SSL renegotiation. This is a security feature in modern OpenSSL versions to prevent vulnerabilities like the CRIME attack.


Why This Happens

  • The VPN server (vpn-CENSORED-CENSORED.CENSORED.fr) is using an outdated or insecure SSL/TLS configuration that relies on legacy renegotiation.
  • OpenSSL (used by openconnect) now disables unsafe legacy renegotiation by default for security reasons.

How to Fix It

Option 1: Allow Legacy Renegotiation (Temporary Workaround)

You can temporarily allow unsafe legacy renegotiation by setting the OPENSSL_ALLOW_UNSAFE_LEGACY_RENEGOTIATION environment variable before running openconnect:

bash
export OPENSSL_ALLOW_UNSAFE_LEGACY_RENEGOTIATION=1
echo "ls_secret CENSORED" | sudo ./openconnect --verbose -s 'INTERNAL_IP4_DNS= /usr/share/vpnc-scripts/vpnc-script' --protocol=gp vpn-CENSORED-CENSORED.CENSORED.fr -u benjamin.loison

⚠️ Warning: This weakens SSL security. Only use this if you fully trust the VPN server and understand the risks.


Option 2: Update OpenConnect or OpenSSL

If possible, update openconnect and OpenSSL to the latest versions, as newer versions may handle this more gracefully:

bash
sudo apt update
sudo apt upgrade openconnect openssl

Then retry the connection.


Option 3: Use --no-ssl-renegotiation (If Supported)

Some versions of openconnect support disabling renegotiation entirely. Try:

bash
echo "ls_secret CENSORED" | sudo ./openconnect --verbose --no-ssl-renegotiation -s 'INTERNAL_IP4_DNS= /usr/share/vpnc-scripts/vpnc-script' --protocol=gp vpn-CENSORED-CENSORED.CENSORED.fr -u benjamin.loison

Option 4: Check VPN Server Configuration

If you have control over the VPN server, update its SSL/TLS configuration to disable legacy renegotiation and use modern, secure protocols (e.g., TLS 1.2+).


Option 5: Use a Different VPN Client

If the issue persists, try using the official GlobalProtect VPN client (if available for Linux) or another OpenConnect-compatible client.


Recommended Next Steps

  1. Try Option 1 (temporary workaround) to confirm if the issue is indeed legacy renegotiation.
  2. If it works, contact your VPN administrator to update the server's SSL/TLS configuration.
  3. If you're uncomfortable with the security trade-off, ask the admin for a secure alternative.
Sep 11, 11:45pm

This is a shared conversation and may include unverified content that doesn't reflect Mistral AI's views. Login to resume chatting.

Vibe can make mistakes. Check answers. Learn more