The key body is stored together with its -----BEGIN …----- wrapper line, but VyOS adds that wrapper itself when writing the key file. From op mode the printed set command simply won't paste. From configure mode the corrupt value is installed and committed without any error — and every OpenVPN tunnel using that PSK then fails to start.
Steps to reproduce:
- configure
- run generate pki openvpn shared-secret install psk1
- show pki openvpn shared-secret
- commit
vyos@vyos# run generate pki openvpn shared-secret install psk1
2 value(s) installed. Use "compare" to see the pending changes, and "commit" to apply.
vyos@vyos# show pki openvpn shared-secret
+shared-secret psk1 {
+ key "-----BEGIN OpenVPN Static key V1-----d0d47e46f69e91b9743f45d8144c9797a...
+ version 1
+}
vyos@vyos# commit
[edit]add a site-to-site tunnel using shared-secret-key psk1 and commit → the key file gets two BEGIN lines and OpenVPN dies:
-----BEGIN OpenVPN Static key V1-----
-----BEGIN OpenVPN Static key V1-----cabd205e440df1b01178f971afe7358dafa4f7bf...
openvpn-vtun0[6549]: Insufficient key material or header text not found in file
'/run/openvpn/vtun0_shared.key' (0/128/256 bytes found/min/max)
openvpn-vtun0[6549]: Exiting due to fatal errorRoot cause:
Regression of T9008 — "Refactor vyos.ifconfig module to use new cmdl() process execution helper"
The wrapper is stripped by position, which only worked while the output was piped through grep -o "^[^#]*" (that drops zero-length matches, so openvpn's three # lines vanished). T9008 replaced the pipeline with a per-line Python split that keeps those lines as empty strings, shifting the BEGIN line to index 3 where the slice no longer removes it