Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Client export - no configurations available

    Scheduled Pinned Locked Moved OpenVPN
    2 Posts 2 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Modesty
      last edited by

      Hi

      After settingup VPN on pfsens i click export wizard.

      I expected to find something like this:
      e52df468-b251-4117-a77f-6316cbd49b29-image.png

      But i see this:
      34e5e665-274b-4b7e-93d6-9d631638c5a8-image.png

      The text under staes that:
      If a client is missing from the list it is likely due to a CA mismatch between the OpenVPN server instance and the client certificate, the client certificate does not exist on this firewall, or a user certificate is not associated with a user when local database authentication is enabled.

      This "help text" I dont understand what to do...

      I have used the wizard to create the vpn, i did create my own sertificate in the prosess.
      cdeba363-6b13-4a0c-9963-43d1d21b3faf-image.png

      Any help from you I appreciate

      M

      Everything can be rebuilt!

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @Modesty
        last edited by

        @modesty said in Client export - no configurations available:

        This "help text" I dont understand what to do...

        It says :

        If a client is missing from the list it is likely due to a CA mismatch between the OpenVPN server instance and the client certificate, the client certificate does not exist on this firewall, or a user certificate is not associated with a user when local database authentication is enabled.

        which means ... what it says.

        When a 'client' uses a VPN connection, it should 'authenticate' against the pfSense OpenVPN server, at the connection needs to be secured.
        And you have a choice :
        A user name and password.
        A certificate st, assigned for that user.
        Or a combination of both.

        You've set up a OpenVPN server, you can see the "access mode" :

        b2b463b7-c6ed-4354-9f17-389cf62b20e7-image.png

        You have made a choice here :

        93502a9d-2fd9-4634-af96-291a397d0474-image.png

        If could create a user + password here :

        5cc6ee04-8442-4c4e-8520-2a8cbf577233-image.png

        and - important, assigned it to the OpenVPN user group, the OpenVPN client export utility can't find a user to include in the export files.

        Or create a 'CA' certificate here :

        e87f5c2a-ba0f-437c-893a-b88034d5fc47-image.png

        I called it "CA-openvpn". As you can see,, it's in use by my OpenVPN server right now.
        This CA cert is only created ones.
        After that, for each user (do not share certificates among users !!) you create Certificates :

        11ba180a-74b8-45c8-be64-5f8c8bee5f53-image.png

        This one is for me, for my iPhone. I also created one for my pad, one or two for the PC's I use to remotely access this pfSense OpenVPN server.
        Again, this certificate is in use right now by the OpenVPN pfsense server.
        Note that this CA certificate is assigned to the OpenVP server :

        e5b7de2b-c61b-4ce3-aa04-dcaa31afcb53-image.png

        Because I chose :

        0104ea83-044d-4ebe-851b-5b723f41fcff-image.png

        which means 'only certificates' (and no user or password), I now have this listed on the OpenVPN client export list :

        ceaadc91-b136-4008-85d4-afce76204731-image.png

        Now, read again :

        If a client is missing from the list it is likely due to a CA mismatch between the OpenVPN server instance and the client certificate, the client certificate does not exist on this firewall, or a user certificate is not associated with a user when local database authentication is enabled.

        and I'll bet that all is clear now.

        and

        If you have Youtube installed, go here Youtube > Netgate > Configuring OpenVPN Remote Access in pfSense Software - it's a bare minimum 'need to know' video, but it explains the steps.
        Several other, far more detailed OpenVPN videos are also a viable. They are old, but do still apply.
        A couple of thousand other pfSense OpenVPN video's also exist.

        An there is the manual, in the top right corner, right in front of you, one click away.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.