WireGuard VPN Manager

  • Ahem. I vaguely recall this issue during early beta tests or am I dreaming it?;)

    Could be, at boot connman-vpnd caught PIA wireguard config file mid-write ("does not contain any configuration that can be provisioned!"), creating a half-second window where both the addon and the LibreELEC settings service were racing for connman resources. On some specific hardware that window caused the permanent hang.

    Two fixes are now in place for next v1.5.4:

    1. Cold boot connect gate — automatic VPN provisioning waits for a platform-specific settle time after service start before triggering the connection. This removes the startup overlap entirely.
    2. Atomic config writes (PIA only) — WireGuard configs are now written via temp-file + atomic rename. connman-vpnd will never see a truncated/empty file again, eliminating the "not provisionable" error.
  • Hi, I have Librelec and installed Wireguard Manager 1.5.3. I'd like to activate it with Proton. I downloaded the file .conf and renamed it .config. I added it to IMPORT Config. Everything is fine. When I click on Wireguard, it tries to connect but fails. This is the file:

    Can someone help me understand what I'm doing wrong? Thanks in advance.

  • Hi, I have Librelec and installed Wireguard Manager 1.5.3. I'd like to activate it with Proton. I downloaded the file .conf and renamed it .config. I added it to IMPORT Config. Everything is fine. When I click on Wireguard, it tries to connect but fails. This is the file:

    Can someone help me understand what I'm doing wrong? Thanks in advance.

    Try this config:

    I need to see the log if it still fails. To post logs to this forum, copy and paste the following into SSH:

    Shell session
    grep -i "service.wireguard.manager" /storage/.kodi/temp/kodi.log | pastebinit

    And post that URL here. How to post a log (wiki)

    1. Enable debugging in Settings>System Settings>Logging
    2. Restart Kodi
    3. Replicate the problem
    4. Generate a log URL (do not post/upload logs to the forum)
    5. Use "Settings > LibreELEC > System > Paste system logs" or run "pastekodi" over SSH, then post the URL link

    Also read our wiki https://github.com/BrodjagaRatnik…rd.manager/wiki

    Salute.

  • I printed the error logs, but I can't upload the log URL. It says "Error send log files." How do I run "pastekodi" via SSH ? Can you give me the commands? Sorry, but I'm not very experienced. Thanks for the help.

  • How do I run "pastekodi" via SSH ? Can you give me the commands?

    Another method to log in background:

    Create an advancedsettings.xml file at /storage/.kodi/userdata with this content:

    Code
    <advancedsettings version="1.0">
        <loglevel>1</loglevel>  
    </advancedsettings>

    Then boot or reboot your device to activate the new log level 1.

    Now run pastekodi on SSH when the error appears. The result will be a URL with your log data.

    Post that URL here. Passwords aren't visible in the log. You can have a look at the log in your browser first.

  • Code
    I did as you wrote, but "pastekodi" doesn't give me any URLs. Anyway, I'll post the error I get when I run the "grep" command. There are no visible keys...
    
    grep -i "service.wireguard.manager" /storage/.kodi/temp/kodi.log | pastebinit
    curl: (60) SSL certificate problem: certificate is not yet valid
    More details here: https://curl.se/docs/sslcerts.html
    curl failed to verify the legitimacy of the server and therefore could not
    establish a secure connection to it. 
  • Hello rivmar

    I can see the issue you're encountering. The error curl: (60) SSL certificate problem: certificate is not yet valid indicates that your LibreELEC device's system clock is likely incorrect (set to a date in the past), causing pastebinit (which uses curl) to fail when trying to verify the SSL certificate of the paste service.

    Here is how to fix this and successfully get your log URL:

    LibreELEC devices often lose time if they don't have NTP configured correctly.

    1. Connect via SSH to your LibreELEC device.
    2. Run the following command to check the current time:

      Shell session
      date
    3. If the date shown is in the past, this confirms the issue.
    4. Adjust the date/time to match your actual current time forcing an NTP sync:
    Shell session
    ntpd -q -p pool.ntp.org

    Once the time is corrected, try running the grep command again:

    Shell session
    grep -i "service.wireguard.manager" /storage/.kodi/temp/kodi.log | pastebinit

    Let me know if fixing the time resolves the pastebinit error, or feel free to do this:

    Shell session
    cat ~/.kodi/temp/kodi.log | grep -iE "service.wireguard.manager" | nc termbin.com 9999

    Termbin does not use HTTPS — it runs over a plain TCP connection on port 9999 via netcat. Therefore, no SSL certificate verification is required, which completely bypasses the error ‘curl: (60) certificate is not yet valid’. The error message “certificate is not yet valid” almost certainly indicates that the system clock on the device is incorrect. This doesn’t matter for Termbin, but it’s still a good idea to check it using the `date` command, as an incorrect clock can also cause problems with other HTTPS connections.

    Salute.