[Bug 1203842] New: KDE Network Manager and openconnect
http://bugzilla.opensuse.org/show_bug.cgi?id=1203842 Bug ID: 1203842 Summary: KDE Network Manager and openconnect Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: KDE Workspace (Plasma) Assignee: opensuse-kde-bugs@opensuse.org Reporter: cosmin.tanczel@gmail.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- Can not connect using the PAN Global Protect (openconnect) with KDE Network Manager. I get an error saying: The IP config of the VPN connection ****, was invalid. In the logs I get operation not permitted. I've tried to manually connect from the cli as a normal user and I get the same. Connecting as root works. So I guess for some reason we do not allow bringing up the tunnel as normal users? Is this to be consider a bug, or it will stay like this? -------------------- ESP session established with server ESP tunnel connected; exiting HTTPS mainloop. Configured as 192.168.222.12, with SSL disconnected and ESP established Session authentication will expire at Wed Sep 28 23:14:32 2022 Failed to bind local tun device (TUNSETIFF): Operation not permitted To configure local networking, openconnect must be running as root See https://www.infradead.org/openconnect/nonroot.html for more information Set up tun device failed POST https://domain.com/ssl-vpn/logout.esp SSL negotiation with domain.com Connected to HTTPS on domain.com with ciphersuite (TLS1.2)-(ECDHE-SECP256R1)-(RSA-SHA256)-(AES-256-GCM) Logout successful. Unrecoverable I/O error; exiting. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203842 Cosmin Tanczel <cosmin.tanczel@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Hardware|Other |x86-64 OS|Other |openSUSE Tumbleweed -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203842 Cosmin Tanczel <cosmin.tanczel@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Found By|--- |Community User -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203842 http://bugzilla.opensuse.org/show_bug.cgi?id=1203842#c2 --- Comment #2 from Cosmin Tanczel <cosmin.tanczel@gmail.com> --- Any news? -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203842 http://bugzilla.opensuse.org/show_bug.cgi?id=1203842#c3 --- Comment #3 from Cosmin Tanczel <cosmin.tanczel@gmail.com> --- Since openconnect seems not be be allowed to run as root*, I installed setcap (libcap-progs) and did a setcap cap_net_admin+ep /sbin/openconnect *openconnect[2210]: SIOCSIFMTU: Operation not permitted Now the operation not permitted error doesn't appear anymore but I now I get: (vpn0)]: invalid IP4 config received: no valid IP address/prefix (vpn0)]: did not receive valid IP config information It seems quite related to this one: https://gitlab.com/openconnect/openconnect/-/issues/391 Can anyone take a look? Thanks! -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203842 http://bugzilla.opensuse.org/show_bug.cgi?id=1203842#c4 Cosmin Tanczel <cosmin.tanczel@gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution|--- |FIXED --- Comment #4 from Cosmin Tanczel <cosmin.tanczel@gmail.com> --- Just tried and it seems now it's working. Will close this one, thanks! -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com