Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WARNING: this configuration may cache passwords in memory OpenVPN

    Scheduled Pinned Locked Moved OpenVPN
    10 Posts 3 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      ceofreak
      last edited by

      Hi folks :)

      I tried to use the search option to fix this, but if you search for the error message every single post where someone posted their VPN Logs pops up :)

      So I got this message, how can you fix this with pfsense? I tried to enter the auth-nocache option in the additional commands under OpenVPN but it didn't help.

      Is this even a legit security risk?

      Thank you!

      ontzuevanhussenO 1 Reply Last reply Reply Quote 0
      • ontzuevanhussenO
        ontzuevanhussen @ceofreak
        last edited by

        @ceofreak Yes, same like me. Anyone can help?

        1 Reply Last reply Reply Quote 0
        • provelsP
          provels
          last edited by provels

          auth-nocache should be added to the client config, not the server. I have used auth-nocache before, but then I was prompted every hour to reconfirm credentials. There are quite a few posts on it. OpenVPN has a default data channel key renegotiation of one hour (3600 seconds). You can add

           reneg-sec 36000
          

          to your server's Advanced/Custom Options to increase that interval to 10 hours (for example).

          Peder

          MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
          BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

          ontzuevanhussenO 4 Replies Last reply Reply Quote 0
          • ontzuevanhussenO
            ontzuevanhussen @provels
            last edited by ontzuevanhussen

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • ontzuevanhussenO
              ontzuevanhussen @provels
              last edited by

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • ontzuevanhussenO
                ontzuevanhussen @provels
                last edited by

                @provels Ok, now work for me. Thank you so much!

                d1f9e108-a379-401b-b6b6-a2656b1cadd2-image.png

                1 Reply Last reply Reply Quote 1
                • ontzuevanhussenO
                  ontzuevanhussen @provels
                  last edited by

                  @provels said in WARNING: this configuration may cache passwords in memory OpenVPN:

                  to your server's Advanced/Custom

                  where this menu?

                  provelsP 1 Reply Last reply Reply Quote 0
                  • provelsP
                    provels @ontzuevanhussen
                    last edited by

                    @ontzuevanhussen
                    VPN/OpenVPN/<your server>/Edit/Advanced Configuration/Custom options

                    Peder

                    MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                    BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                    ontzuevanhussenO 1 Reply Last reply Reply Quote 0
                    • ontzuevanhussenO
                      ontzuevanhussen @provels
                      last edited by

                      @provels Ok, like this?
                      970a8841-8e69-4a22-ba53-69cac7420c41-image.png

                      provelsP 1 Reply Last reply Reply Quote 1
                      • provelsP
                        provels @ontzuevanhussen
                        last edited by

                        @ontzuevanhussen That's it!

                        Peder

                        MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                        BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.