NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
catch222
Jul 02, 2023Aspirant
Orbi AX6000 vpn from linux: OpenSSL: error:0A00018F:SSL routines::ee key too small
I'm encountered an issue connecting to the orbi from linux, specifically fedora 38.
Running `sudo openvpn --config ./smart_phone.ovpn`,
I get the an error `OpenSSL: error:0A00018F:SSL routines::ee key too small`
The system thinks the keys are too small and insecure for use and stops.
This works OK with other linux versions but Fedora 38 is being more pedantic.
I don't think it likes the 1024 bit RSA root certificate ( Asymmetric_algorithm_key_lengths )
I'm far from a security expert, but can anyone advise if this is secure or had any luck connecting to the orbi's vpn from Fedora.
~Adam
2 Replies
- catch222Aspirant
In fedora i need to explicitly allow this legacy cipher
```
sudo openvpn --config ./smart_phone.ovpn --tls-cipher TLS-DHE-RSA-WITH-AES-128-CBC-SHA
```
Other links
https://ciphersuite.info/cs/TLS_DHE_RSA_WITH_AES_128_CBC_SHA/
https://csrc.nist.gov/csrc/media/projects/key-management/documents/transitions/transitioning_cryptoalgos_070209.pdf- catch222Aspirant
I've contacted support about this issue. In the hope they might bump up the keys to 2048 bits as has been the NIST recommendation since 2015.
I'm surprised to learn the SRK80 is EOL, and won't be receiving further updates.
Having just purchased this device in the last week AND not finding any mention of this on the netgear website, I'm a fairly unhappy customer.
https://www.netgear.com/support/product/sxk80
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!