Authentication failed - Repeatedly

Got a problem with Viscosity or need help? Ask here!

bill74

Posts: 2
Joined: Fri Oct 29, 2021 6:02 pm

Post by bill74 » Fri Oct 29, 2021 6:26 pm
Hi

I've just installed Viscosity on a new laptop, and I can't authenticate to my VPN as I could on my old laptop. I keep getting a popup saying that "The username and/or password in your password store was incorrect. Please reconnect to try again."

I've tried:
1) Hitting the "Clear All Saved Credentials" button
2) Deleting the LoginInfo.xml file in my profile
3) Reimporting the connection from a file
4) Manually creating a new connection from scratch
5) Importing the connection from the VPN server
6) Importing the connection from the OpenVPN client

but nothing works. Viewing the logs I always get the "AUTH: Received control message: AUTH_FAILED" message and then the popup appears.

If I make the same connection in the OpenVPN client it works, so there's nothing wrong with my credentials. The reason I'm using Viscosity (and paid for a license) is that I need to be connected to more than one VPN at the same time which I can't do with the OpenVPN client. The other two connections I have in Viscosity connect with no problem.

This is very frustrating, and it's more frustrating that this used to work fine on my old laptop. Can someone please help me?

Thanks very much.

Eric

User avatar
Posts: 1146
Joined: Sun Jan 03, 2010 3:27 am

Post by Eric » Fri Oct 29, 2021 6:30 pm
Hi bill74,

If you go to Preferences -> Advanced, change the OpenVPN Version to 2.4, then try to connect again, are you able to connect?

Regards,
Eric
Eric Thorpe
Viscosity Developer

Web: http://www.sparklabs.com
Support: http://www.sparklabs.com/support
Twitter: http://twitter.com/sparklabs

bill74

Posts: 2
Joined: Fri Oct 29, 2021 6:02 pm

Post by bill74 » Sat Oct 30, 2021 1:11 am
Perfect, thanks, Eric, That worked!

Cheers

Eric

User avatar
Posts: 1146
Joined: Sun Jan 03, 2010 3:27 am

Post by Eric » Mon Nov 01, 2021 12:03 pm
Hi bill74,

We'd highly appreciate some more information about your server setup so we can try and see if there is an issue with OpenVPN 2.5 we can solve, or provide future advice to how to fix the issue. Are you able to let us know anything about your server setup? For example, the OpenVPN version, any scripts/plugins it is using and what type of authentication you are using? That would be highly appreciated.

OpenVPN 2.4 will be out of support soon and will cease to receive updates, so whatever is causing this issue will need to be fixed.

Regards,
Eric
Eric Thorpe
Viscosity Developer

Web: http://www.sparklabs.com
Support: http://www.sparklabs.com/support
Twitter: http://twitter.com/sparklabs

VIClarke

Posts: 1
Joined: Mon Nov 08, 2021 3:13 am

Post by VIClarke » Mon Nov 08, 2021 3:35 am
Afternoon.

I am experiencing a similar problem and have tried all the suggestions including selecting 2.4 with no luck.

I have a surface proX running windows 11. I get the exact same error.

I have removed my work microsoft account as I thought there might be permission issues but the authenication fails on every attempt. I am trying to connect to ExpressVPN, which works correctly when I access via a web browser, but fails when I use the app

The log is below. Please advise what I should do next.

Nov 07 7:50:32 PM: State changed to Connecting
Nov 07 7:50:32 PM: Viscosity Windows 1.10 (1745)
Nov 07 7:50:32 PM: Running on Microsoft Windows 11 Pro ARM64
Nov 07 7:50:32 PM: Running on .NET Framework Version 4.8.04161.528449
Nov 07 7:50:32 PM: Checking reachability status of connection...
Nov 07 7:50:32 PM: Connection is reachable. Starting connection attempt.
Nov 07 7:50:32 PM: Interface Type: ViscTunTap
Nov 07 7:50:32 PM: Bringing up interface...
Nov 07 7:50:32 PM: DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning.
Nov 07 7:50:32 PM: WARNING: --keysize is DEPRECATED and will be removed in OpenVPN 2.6
Nov 07 7:50:32 PM: OpenVPN 2.5.4 Windows-MSVC [SSL (OpenSSL)] [LZO] [LZ4] [AEAD] built on Oct 18 2021
Nov 07 7:50:32 PM: library versions: OpenSSL 1.1.1l 24 Aug 2021, LZO 2.10
Nov 07 7:50:33 PM: Resolving address: "southafrica-ca-version-2.expressnetw.com"
Nov 07 7:50:33 PM: Valid endpoint found: southafrica-ca-version-2.expressnetw.com:1195:udp
Nov 07 7:50:33 PM: WARNING: --ns-cert-type is DEPRECATED. Use --remote-cert-tls instead.
Nov 07 7:50:33 PM: NOTE: --fast-io is disabled since we are running on Windows
Nov 07 7:50:34 PM: Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Nov 07 7:50:34 PM: Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Nov 07 7:50:34 PM: TCP/UDP: Preserving recently used remote address: [AF_INET]154.70.152.148:1195
Nov 07 7:50:34 PM: Socket Buffers: R=[65536->524288] S=[65536->524288]
Nov 07 7:50:34 PM: UDP link local: (not bound)
Nov 07 7:50:34 PM: UDP link remote: [AF_INET]154.70.152.148:1195
Nov 07 7:50:34 PM: State changed to Authenticating
Nov 07 7:50:34 PM: TLS: Initial packet from [AF_INET]154.70.152.148:1195, sid=7bad2fff a7caf395
Nov 07 7:50:34 PM: VERIFY OK: depth=1, C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=ExpressVPN CA, emailAddress=[email protected]
Nov 07 7:50:34 PM: VERIFY OK: nsCertType=SERVER
Nov 07 7:50:34 PM: VERIFY X509NAME OK: C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=Server-6815-0a, emailAddress=[email protected]
Nov 07 7:50:34 PM: VERIFY OK: depth=0, C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=Server-6815-0a, emailAddress=[email protected]
Nov 07 7:50:35 PM: Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256
Nov 07 7:50:35 PM: [Server-6815-0a] Peer Connection Initiated with [AF_INET]154.70.152.148:1195
Nov 07 7:50:35 PM: State changed to Connecting
Nov 07 7:50:35 PM: SENT CONTROL [Server-6815-0a]: 'PUSH_REQUEST' (status=1)
Nov 07 7:50:35 PM: AUTH: Received control message: AUTH_FAILED
Nov 07 7:50:38 PM: SIGUSR1[soft,auth-failure] received, process restarting
Nov 07 7:50:38 PM: Valid existing endpoint found... 154.70.152.148:1195:udp
Nov 07 7:50:54 PM: WARNING: --ns-cert-type is DEPRECATED. Use --remote-cert-tls instead.
Nov 07 7:50:54 PM: NOTE: --fast-io is disabled since we are running on Windows
Nov 07 7:50:54 PM: Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Nov 07 7:50:54 PM: Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Nov 07 7:50:54 PM: TCP/UDP: Preserving recently used remote address: [AF_INET]154.70.152.148:1195
Nov 07 7:50:54 PM: Socket Buffers: R=[65536->524288] S=[65536->524288]
Nov 07 7:50:54 PM: UDP link local: (not bound)
Nov 07 7:50:54 PM: UDP link remote: [AF_INET]154.70.152.148:1195
Nov 07 7:50:55 PM: State changed to Authenticating
Nov 07 7:50:55 PM: TLS: Initial packet from [AF_INET]154.70.152.148:1195, sid=7585a8f7 85805a3f
Nov 07 7:50:55 PM: VERIFY OK: depth=1, C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=ExpressVPN CA, emailAddress=[email protected]
Nov 07 7:50:55 PM: VERIFY OK: nsCertType=SERVER
Nov 07 7:50:55 PM: VERIFY X509NAME OK: C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=Server-6815-0a, emailAddress=[email protected]
Nov 07 7:50:55 PM: VERIFY OK: depth=0, C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=Server-6815-0a, emailAddress=[email protected]
Nov 07 7:50:55 PM: Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256
Nov 07 7:50:55 PM: [Server-6815-0a] Peer Connection Initiated with [AF_INET]154.70.152.148:1195
Nov 07 7:50:55 PM: State changed to Connecting
Nov 07 7:50:55 PM: SENT CONTROL [Server-6815-0a]: 'PUSH_REQUEST' (status=1)
Nov 07 7:50:56 PM: AUTH: Received control message: AUTH_FAILED
Nov 07 7:51:13 PM: SIGUSR1[soft,auth-failure] received, process restarting
Nov 07 7:51:13 PM: Valid existing endpoint found... 154.70.152.148:1195:udp
Nov 07 7:51:32 PM: State changed to Disconnecting (Username/Password Cancelled)
Nov 07 7:51:32 PM: ERROR: could not read Auth username/password/ok/string from management interface
Nov 07 7:51:32 PM: OpenVPN has exited. Exitcode = 1
Nov 07 7:51:32 PM: State changed to Disconnected
Nov 07 8:12:16 PM: State changed to Connecting
Nov 07 8:12:16 PM: Viscosity Windows 1.10 (1745)
Nov 07 8:12:16 PM: Running on Microsoft Windows 11 Pro ARM64
Nov 07 8:12:16 PM: Running on .NET Framework Version 4.8.04161.528449
Nov 07 8:12:16 PM: Checking reachability status of connection...
Nov 07 8:12:16 PM: Connection is reachable. Starting connection attempt.
Nov 07 8:12:16 PM: Interface Type: ViscTunTap
Nov 07 8:12:16 PM: Bringing up interface...
Nov 07 8:12:16 PM: WARNING: --keysize is DEPRECATED and will be removed in OpenVPN 2.6
Nov 07 8:12:16 PM: OpenVPN 2.4.11 Windows-MSVC [SSL (OpenSSL)] [LZO] [LZ4] [AEAD] built on Oct 18 2021
Nov 07 8:12:16 PM: library versions: OpenSSL 1.1.1l 24 Aug 2021, LZO 2.10
Nov 07 8:12:17 PM: Resolving address: "southafrica-ca-version-2.expressnetw.com"
Nov 07 8:12:17 PM: Valid endpoint found: southafrica-ca-version-2.expressnetw.com:1195:udp
Nov 07 8:12:17 PM: WARNING: --ns-cert-type is DEPRECATED. Use --remote-cert-tls instead.
Nov 07 8:12:17 PM: NOTE: --fast-io is disabled since we are running on Windows
Nov 07 8:12:17 PM: Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Nov 07 8:12:17 PM: Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Nov 07 8:12:17 PM: TCP/UDP: Preserving recently used remote address: [AF_INET]154.70.152.164:1195
Nov 07 8:12:17 PM: Socket Buffers: R=[65536->524288] S=[65536->524288]
Nov 07 8:12:17 PM: UDP link local: (not bound)
Nov 07 8:12:17 PM: UDP link remote: [AF_INET]154.70.152.164:1195
Nov 07 8:12:18 PM: State changed to Authenticating
Nov 07 8:12:18 PM: TLS: Initial packet from [AF_INET]154.70.152.164:1195, sid=1a42b494 31a9902f
Nov 07 8:12:18 PM: VERIFY OK: depth=1, C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=ExpressVPN CA, emailAddress=[email protected]
Nov 07 8:12:18 PM: VERIFY OK: nsCertType=SERVER
Nov 07 8:12:18 PM: VERIFY X509NAME OK: C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=Server-6816-0a, emailAddress=[email protected]
Nov 07 8:12:18 PM: VERIFY OK: depth=0, C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=Server-6816-0a, emailAddress=[email protected]
Nov 07 8:12:19 PM: Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, 2048 bit RSA
Nov 07 8:12:19 PM: [Server-6816-0a] Peer Connection Initiated with [AF_INET]154.70.152.164:1195
Nov 07 8:12:19 PM: State changed to Connecting
Nov 07 8:12:19 PM: SENT CONTROL [Server-6816-0a]: 'PUSH_REQUEST' (status=1)
Nov 07 8:12:19 PM: AUTH: Received control message: AUTH_FAILED
Nov 07 8:12:23 PM: SIGUSR1[soft,auth-failure] received, process restarting
Nov 07 8:12:23 PM: Valid existing endpoint found... 154.70.152.164:1195:udp
Nov 07 8:12:25 PM: State changed to Disconnecting (Username/Password Cancelled)
Nov 07 8:12:25 PM: ERROR: could not read Auth username/password/ok/string from management interface
Nov 07 8:12:25 PM: OpenVPN has exited. Exitcode = 1
Nov 07 8:12:25 PM: State changed to Disconnected

Eric

User avatar
Posts: 1146
Joined: Sun Jan 03, 2010 3:27 am

Post by Eric » Mon Nov 08, 2021 9:47 am
Hi VIClarke,

You will need to contact your VPN Provider for assistance, they will be able to see on their server why your authentication is being rejected - https://sparklabs.com/support/kb/articl ... ovider-is/

Regards,
Eric
Eric Thorpe
Viscosity Developer

Web: http://www.sparklabs.com
Support: http://www.sparklabs.com/support
Twitter: http://twitter.com/sparklabs
6 posts Page 1 of 1