Can't connect to some older openvpn servers a few days ago

OpenSSL: error:0A00018E:SSL routines::ca md too weak

I know the ciphers are old, but we are in the middle of changing them. Meanwhile I need to connect to them and they have worked last month for sure.

Tried adding tls-cipher = DEFAULT:@SECLEVEL=0 to /etc/ssl/openssl.cnf but it doesn’t seem to work.

I found this as I had the same issues:

$ cd path/to/the/pfx-file
$ mv mykeys.pfx mykeys.pfx.bak
$ openssl pkcs12 -in mykeys.pfx.bak -out mykeys.pfx -aes256 -legacy

I wanted something global, so I wouldn’t have to change every config, but the only thing that works is changing every config like this:

https://jabriffa.wordpress.com/2022/09/19/vpn-errors-on-upgrade-to-ubuntu-22-04-lts/