Ahem. I vaguely recall this issue during early beta tests or am I dreaming it?![]()
WireGuard VPN Manager
-
Doemela -
April 27, 2026 at 3:05 AM -
Thread is Resolved
-
-
Ahem. I vaguely recall this issue during early beta tests or am I dreaming it?

Could be, at boot connman-vpnd caught PIA wireguard config file mid-write ("does not contain any configuration that can be provisioned!"), creating a half-second window where both the addon and the LibreELEC settings service were racing for connman resources. On some specific hardware that window caused the permanent hang.
Two fixes are now in place for next v1.5.4:
- Cold boot connect gate — automatic VPN provisioning waits for a platform-specific settle time after service start before triggering the connection. This removes the startup overlap entirely.
- Atomic config writes (PIA only) — WireGuard configs are now written via temp-file + atomic rename. connman-vpnd will never see a truncated/empty file again, eliminating the "not provisionable" error.
-
Hi, I have Librelec and installed Wireguard Manager 1.5.3. I'd like to activate it with Proton. I downloaded the file .conf and renamed it .config. I added it to IMPORT Config. Everything is fine. When I click on Wireguard, it tries to connect but fails. This is the file:
Code
Display More[provider_wireguard] Type = WireGuard Name = Custom_Proton_CH Host = 138.199.6.178 DNS = 10.2.0.1, 2a07:b944::2:1 WireGuard.Address = 10.2.0.2/32, 2a07:b944::2:2/128 WireGuard.ListenPort = 51820 WireGuard.MTU = 1420 WireGuard.PrivateKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx #CH-FREE#3 PublicKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx WireGuard.AllowedIPs = 0.0.0.0/0, ::/0 WireGuard.EndpointPort = 138.199.6.178:51820 WireGuard.PersistentKeepalive = 25Can someone help me understand what I'm doing wrong? Thanks in advance.
-
Hi, I have Librelec and installed Wireguard Manager 1.5.3. I'd like to activate it with Proton. I downloaded the file .conf and renamed it .config. I added it to IMPORT Config. Everything is fine. When I click on Wireguard, it tries to connect but fails. This is the file:
Code
Display More[provider_wireguard] Type = WireGuard Name = Custom_Proton_CH Host = 138.199.6.178 DNS = 10.2.0.1, 2a07:b944::2:1 WireGuard.Address = 10.2.0.2/32, 2a07:b944::2:2/128 WireGuard.ListenPort = 51820 WireGuard.MTU = 1420 WireGuard.PrivateKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx #CH-FREE#3 PublicKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx WireGuard.AllowedIPs = 0.0.0.0/0, ::/0 WireGuard.EndpointPort = 138.199.6.178:51820 WireGuard.PersistentKeepalive = 25Can someone help me understand what I'm doing wrong? Thanks in advance.
Try this config:
Code
Display More[provider_wireguard] Type = WireGuard Name = Custom_Proton_CH Host = 138.199.6.178 DNS = 10.2.0.1 WireGuard.Address = 10.2.0.2/32 WireGuard.ListenPort = 51820 WireGuard.MTU = 1420 WireGuard.PrivateKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx #CH-FREE#3 PublicKey = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx WireGuard.AllowedIPs = 0.0.0.0/0, ::/0 WireGuard.EndpointPort = 51820 WireGuard.PersistentKeepalive = 25I need to see the log if it still fails. To post logs to this forum, copy and paste the following into SSH:
And post that URL here. How to post a log (wiki)
1. Enable debugging in Settings>System Settings>Logging
2. Restart Kodi
3. Replicate the problem
4. Generate a log URL (do not post/upload logs to the forum)
5. Use "Settings > LibreELEC > System > Paste system logs" or run "pastekodi" over SSH, then post the URL linkAlso read our wiki https://github.com/BrodjagaRatnik…rd.manager/wiki
Salute.
-
I printed the error logs, but I can't upload the log URL. It says "Error send log files." How do I run "pastekodi" via SSH ? Can you give me the commands? Sorry, but I'm not very experienced. Thanks for the help.
-
How do I run "pastekodi" via SSH ? Can you give me the commands?
Another method to log in background:
Create an advancedsettings.xml file at /storage/.kodi/userdata with this content:
Then boot or reboot your device to activate the new log level 1.
Now run pastekodi on SSH when the error appears. The result will be a URL with your log data.
Post that URL here. Passwords aren't visible in the log. You can have a look at the log in your browser first.
-
Code
I did as you wrote, but "pastekodi" doesn't give me any URLs. Anyway, I'll post the error I get when I run the "grep" command. There are no visible keys... grep -i "service.wireguard.manager" /storage/.kodi/temp/kodi.log | pastebinit curl: (60) SSL certificate problem: certificate is not yet valid More details here: https://curl.se/docs/sslcerts.html curl failed to verify the legitimacy of the server and therefore could not establish a secure connection to it. -
Hello rivmar
I can see the issue you're encountering. The error curl: (60) SSL certificate problem: certificate is not yet valid indicates that your LibreELEC device's system clock is likely incorrect (set to a date in the past), causing pastebinit (which uses curl) to fail when trying to verify the SSL certificate of the paste service.
Here is how to fix this and successfully get your log URL:
LibreELEC devices often lose time if they don't have NTP configured correctly.
- Connect via SSH to your LibreELEC device.
Run the following command to check the current time:
- If the date shown is in the past, this confirms the issue.
- Adjust the date/time to match your actual current time forcing an NTP sync:
Once the time is corrected, try running the grep command again:
Let me know if fixing the time resolves the pastebinit error, or feel free to do this:
Shell sessioncat ~/.kodi/temp/kodi.log | grep -iE "service.wireguard.manager" | nc termbin.com 9999Termbin does not use HTTPS — it runs over a plain TCP connection on port 9999 via netcat. Therefore, no SSL certificate verification is required, which completely bypasses the error ‘curl: (60) certificate is not yet valid’. The error message “certificate is not yet valid” almost certainly indicates that the system clock on the device is incorrect. This doesn’t matter for Termbin, but it’s still a good idea to check it using the `date` command, as an incorrect clock can also cause problems with other HTTPS connections.
Salute. -