Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Grant a User Permission to ONLY Start/Stop (OpenVPN) service

    Scheduled Pinned Locked Moved OpenVPN
    2 Posts 2 Posters 457 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      Lamia
      last edited by

      Hi,
      I have searched the forum and the Internet but no clue hence, I am posting the question here. I have set up a user and a new group. The user belongs to the group. I have added all permissions to OpenVPN yet on logging in, the user cannot stop or restart the service. At the moment, the animation is played on hitting the button i.e. restart shows a rolling wheel but the service is not restarted. The same goes for the stop button.

      I cannot drop the user in the admin group since they have a limited privilege. What privileges need to be added in addition to the below?

      VPNAdmins	WebCfg - OpenVPN: Client Specific Override	Allow access to the 'OpenVPN: Client Specific Override' page.	
      VPNAdmins	WebCfg - OpenVPN: Clients	Allow access to the 'OpenVPN: Clients' page.	
      VPNAdmins	WebCfg - OpenVPN: Clients Edit Advanced	Allow edit access to the 'OpenVPN: Clients' Advanced settings field. (admin privilege)	
      VPNAdmins	WebCfg - Diagnostics: Reboot System	Allow access to the 'Diagnostics: Reboot System' page.	
      VPNAdmins	WebCfg - System: Group Manager: Add Privileges	Allow access to the 'System: Group Manager: Add Privileges' page. (admin privilege)	
      VPNAdmins	WebCfg - System: User Manager: Add Privileges	Allow access to the 'System: User Manager: Add Privileges' page. (admin privilege)	
      	WebCfg - Status: OpenVPN	Allow access to the 'Status: OpenVPN' page.	
      Security notice: This user effectively has administrator-level access	
      
      

      I reckon all of these are not necessary, I will remove them. Kindly guide me. Thanks.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        There are no granular per-service privileges right now, so any user who must control a service requires access to status_services.php (WebCfg - Status: Services).

        All of the service control links, even in the shortcut bar, use that page to manage service control.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 1
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.