Community discussions

MikroTik App
 
Kurgan
just joined
Topic Author
Posts: 9
Joined: Mon Dec 17, 2012 1:20 am

Openvpn errors "AEAD Decrypt error: cipher final failed" on 7.17.2 on CCR2004

Thu Feb 20, 2025 12:33 am

I have quite a lot of Mikrotik routers (various models) set up as openvpn servers with no issues.
Today I set up a CCR2004 with fw 7.17.2 as I did for the others.

I have connected to it from my Linux client, and got a lot of errors like this: AEAD Decrypt error: cipher final failed

I have run some tests and I have discovered that using AES-256-GCM causes this. Using AES-256-CBC works fine.

I suppose it might be related to this change log I found in 7.18.rc3, that states:

ovpn - disable hardware accelerator for GCM on Alpine CPUs (introduced in v7.17)

I leave this post here hoping to help someone else. If you see these errors, use CBC instead of GCM. (Or use a firmware 7.16.x or 7.18.x)
 
walter217
just joined
Posts: 1
Joined: Wed Mar 12, 2025 5:34 am

Re: Openvpn errors "AEAD Decrypt error: cipher final failed" on 7.17.2 on CCR2004

Wed Mar 12, 2025 5:38 am

Excelente solucion, muchas gracias estando en la version 7.18 no pude usarlo, cambie a AES-256-CBC y funciono perfecto.

Mil gracias
You do not have the required permissions to view the files attached to this post.
 
User avatar
chechito
Forum Guru
Forum Guru
Posts: 3281
Joined: Sun Aug 24, 2014 3:14 am
Location: Bogota Colombia
Contact:

Re: Openvpn errors "AEAD Decrypt error: cipher final failed" on 7.17.2 on CCR2004

Wed Mar 12, 2025 7:13 pm

Excelente solucion, muchas gracias estando en la version 7.18 no pude usarlo, cambie a AES-256-CBC y funciono perfecto.

Mil gracias
Welcome to the forum.

However It's an English based forum, so please post using that language