Continuing my monolouge here
It seems like openSSL might have done some changes, that affects openVPN clients versioned 2.6.xx+
I think also something that affects certificate encryption.
And i noticed a new settings field in the 2.7 openVPN Client export.
[image: 1695188692911-f799358e-e425-4e15-8293-191dcf8cddec-image.png]
My steps to reproduce:
Have a Win PC with an openVPN Client export installer (latest from pfS 2.6) - Current Windows Installers (2.5.8-Ix04):
If you try to connect to the pfS 2.6 openVPN server , all is good.
Then you get/receive a pfSense 2.7 Client export install file , and install it (to install the new conf+certs for that connection) - Current Windows Installers (2.6.5-Ix001):
Now if i try to connect to the "Old pfS 2.6" OVPN Server, I get asked for uid/pwd as usual.
But after entering that correct, i get another "gui prompt" , asking for the cert passwd.
[image: 1695189784507-7ef967d0-5eb3-4afd-8f0c-8a95c1f77d81-image.png]
Since i never used/generated a cert passwd, i can't login anymore.
Connecting to the 2.7 OVPN server, with the new client, does not ask for a cert passwd.
It might be an "Odd test" , but I think someone could have both 2.7 & 2.6 openVPN servers in prod.
Could Netgate confirm the above issue/situation ?
/Bingo