Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HOWTO - OpenVPN + LDAP authentication in pfSense 1.2.2

    Scheduled Pinned Locked Moved OpenVPN
    28 Posts 11 Posters 56.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      federicoha
      last edited by

      I try to make my current openvpn add a ldap authenticate.

      For testing, i download a vmware image of 1.2.3 version of pfsense, configure a similar openvpn and work OK.

      Follow the steps in the eureka link (http://fusionnetwork.us/index.php/component/content/article/15-general-tutorials/31-howto-setup-openvpn-with-ldap-integration-on-pfsense-123), and work ok without the line of plugin.

      If i put the plugin line

      plugin /usr/local/lib/openvpn-auth-ldap.so /usr/local/etc/openvpn-auth-ldap.conf
      

      then openvpn doesnt start:

      Apr 19 13:31:05 	openvpn[1135]: OpenVPN 2.0.6 i386-portbld-freebsd7.2 [SSL] [LZO] built on Apr 16 2009
      Apr 19 13:31:03 	openvpn[428]: SIGTERM[hard,] received, process exiting
      Apr 19 13:31:03 	openvpn[428]: /etc/rc.filter_configure tun0 1500 1542 192.168.7.1 192.168.7.2 init
      Apr 19 13:31:03 	openvpn[428]: event_wait : Interrupted system call (code=4)
      

      Dont understan what happend, but for try only, change the openvpn-auth-ldap.so to openvpn-auth-pam.so and the openvpn start, but not function the authenticate.

      Install all pkg that eureka says. Someone can make function openvpn with ldap with this tutorial?
      Why openvpn cant start?

      Thanks for your help.

      Regards.

      1 Reply Last reply Reply Quote 0
      • E
        eureka
        last edited by

        Thats an interesting error!
        Try reinstalling openvpn. That may solve the issue.

        From Command line run the following:
        pkg_add -r openvpn

        That should force a reinstall of the openvpn package and its needed packages… Let me know if this fixes things for you.
        If not i can try to create a vhost image for you to check out. It could be something setup in the vhost image you are using possibly.

        -E

        1 Reply Last reply Reply Quote 0
        • F
          federicoha
          last edited by

          eureka, thanks for your answer..

          I try what you suggest, but cannnot reinstall openvpn

          # pkg_add -r openvpn
          Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/openvpn.tbz... Done.
          pkg_add: package 'openvpn-2.0.6_9' or its older version already installed
          #                                                                               
          

          i try force reinstall, but always tell me the same

          # pkg_add -F -r openvpn
          Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/openvpn.tbz... Done.
          pkg_add: package 'openvpn-2.0.6_9' or its older version already installed (ignored)
          

          Btw, try to connect the client again if something changes, but cannot…

          Can we try with the vhost you tell me?

          Thanks in advance.

          Regards.

          1 Reply Last reply Reply Quote 0
          • E
            eureka
            last edited by

            Ill see what I can do to get a vhost setup for you to play with.
            Do you prefer vmware or xen?

            -E

            @federicoha:

            eureka, thanks for your answer..

            I try what you suggest, but cannnot reinstall openvpn

            # pkg_add -r openvpn
            Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/openvpn.tbz... Done.
            pkg_add: package 'openvpn-2.0.6_9' or its older version already installed
            #                                                                               
            

            i try force reinstall, but always tell me the same

            # pkg_add -F -r openvpn
            Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7.2-release/Latest/openvpn.tbz... Done.
            pkg_add: package 'openvpn-2.0.6_9' or its older version already installed (ignored)
            

            Btw, try to connect the client again if something changes, but cannot…

            Can we try with the vhost you tell me?

            Thanks in advance.

            Regards.

            1 Reply Last reply Reply Quote 0
            • F
              federicoha
              last edited by

              Vmware please if you can.

              Thanks.

              1 Reply Last reply Reply Quote 0
              • E
                eureka
                last edited by

                Hi,
                Ive uploaded a virtual appliance of this here.

                www.fusionnetwork.us/tutorials/uploads/pfsense/PfSense_withOpenVPN_LDAP.zip

                This should work once you configure the ldap side of things correctly. If you still are having problems please post back. Also… Sorry this took so long to upload... Work is crazy o.0

                -E

                1 Reply Last reply Reply Quote 0
                • F
                  federicoha
                  last edited by

                  Eureka, thanks for your time…

                  I download your appliance and work ok, only have problem right now with the connection to AD, but is my problem now :)

                  When i get to work, i let you know...

                  Thanks for your help again...

                  1 Reply Last reply Reply Quote 0
                  • E
                    eureka
                    last edited by

                    @federicoha:

                    Eureka, thanks for your time…

                    I download your appliance and work ok, only have problem right now with the connection to AD, but is my problem now :)

                    When i get to work, i let you know...

                    Thanks for your help again...

                    Glad to hear you got it working. If you keep having problems with the AD setup let me know. I have a friend that has to work with AD a lot and might be useful =)

                    -E

                    1 Reply Last reply Reply Quote 0
                    • F
                      federicoha
                      last edited by

                      well :):)

                      If your friend can help me, i really appreciate

                      He need the error in system log?

                      Regards

                      1 Reply Last reply Reply Quote 0
                      • E
                        eureka
                        last edited by

                        @federicoha:

                        well :):)

                        If your friend can help me, i really appreciate

                        He need the error in system log?

                        Regards

                        Yeah, Any errors you have either on PF or in AD would be great!
                        -E

                        1 Reply Last reply Reply Quote 0
                        • C
                          chetansaundankar
                          last edited by

                          Thanks a lot for this. I was able to get it working.
                          However I have observed some strange behavior,

                          Setup
                          –-----

                          • My setup has pfsense 1.2.3 & OpenDS 2.2 as ldap provider.
                          • In ldap, I have base DN as "dc=baseorg,dc=com".
                          • There are two sub domains - "dc=orgone,dc=baseorg,dc=com", "dc=orgtwo,dc=baseorg,dc=com".
                          • Theres a user in each subdomain called "testuser".
                          • BaseDN in authorization section of the config is set to "dc=baseorg,dc=com".
                          • RequireGroup in authorization section of the config file is set to false

                          Behavior - 1
                          –-------------
                          Test: If I try to authenticate with testuser@baseorg.com
                          Expected Behavior - Ideally auth should fail as the user belongs to one of the sub-domain.
                          Actual Behavior - User gets authenticated successfully.
                          Question - Is this an expected behavior?

                          Behavior - 2
                          –-------------
                          Test: If I try to authenticate with junk values whatever@abcd.com
                          Expected Behavior - Ideally auth should fail with an error message for incorrect username or domain.
                          Actual Behavior - A line in openvpn log - Incorrect password supplied for LDAP DN "cn=testuser,dc=orgtwo,dc=baseorg,dc=com".
                          Question - How come "cn=testuser,dc=orgtwo,dc=baseorg,dc=com" is referred when the values are junk?

                          1 Reply Last reply Reply Quote 0
                          • E
                            eureka
                            last edited by

                            @chetansaundankar:

                            Thanks a lot for this. I was able to get it working.
                            However I have observed some strange behavior,

                            Setup
                            –-----

                            • My setup has pfsense 1.2.3 & OpenDS 2.2 as ldap provider.
                            • In ldap, I have base DN as "dc=baseorg,dc=com".
                            • There are two sub domains - "dc=orgone,dc=baseorg,dc=com", "dc=orgtwo,dc=baseorg,dc=com".
                            • Theres a user in each subdomain called "testuser".
                            • BaseDN in authorization section of the config is set to "dc=baseorg,dc=com".
                            • RequireGroup in authorization section of the config file is set to false

                            Behavior - 1
                            –-------------
                            Test: If I try to authenticate with testuser@baseorg.com
                            Expected Behavior - Ideally auth should fail as the user belongs to one of the sub-domain.
                            Actual Behavior - User gets authenticated successfully.
                            Question - Is this an expected behavior?

                            Behavior - 2
                            –-------------
                            Test: If I try to authenticate with junk values whatever@abcd.com
                            Expected Behavior - Ideally auth should fail with an error message for incorrect username or domain.
                            Actual Behavior - A line in openvpn log - Incorrect password supplied for LDAP DN "cn=testuser,dc=orgtwo,dc=baseorg,dc=com".
                            Question - How come "cn=testuser,dc=orgtwo,dc=baseorg,dc=com" is referred when the values are junk?

                            Hi!.
                            1. With the current setup that is the expected behavior. You have to modify the ldap strings to make it exclude all other sections when running a lookup. I may have this setup somewhere. Ill see if ive got an example.
                            2. I know it seems annoying that it is referencing the LDAP dn when a user's auth fails but I think that has more to do with the plugin used. Its referencing the DN as it is possible to have more than one DN. This way if you had users in different groups/areas you are trying to auth them from it would reference the correct location of the user to make it easier to track down.

                            1 Reply Last reply Reply Quote 0
                            • E
                              eureka
                              last edited by

                              Im not sure how valid my example is….this is from a system that i was at one time running LDAP auth for VPN.

                              Look at this section of your /usr/local/etc/openvpn-auth-ldap.conf file

                               <authorization># Base DN
                                      BaseDN          "ou=YourDomain,dc=hjs,dc=local"
                              
                                      # User Search Filter
                                      SearchFilter    "(&(uid=%u))"
                              
                                      # Require Group Membership
                                      RequireGroup    false
                              
                                      # Add non-group members to a PF table (disabled)
                                      #PFTable        ips_vpn_users
                              
                                      <group>BaseDN          "ou=YourDomain,dc=hjs,dc=local"
                                              SearchFilter    "ou=users"
                                              MemberAttribute uniqueMember
                                              # Add group members to a PF table (disabled)
                                              #PFTable        ips_vpn_eng</group></authorization> 
                              
                              

                              Take note of the:

                              # User Search Filter
                                      SearchFilter    "(&(uid=%u))"
                              and
                                      SearchFilter    "ou=users"

                              Sections.. Make sure this is a filter that will work for the group you want to authenticate users from.

                              I hope this helps. If you are still having problems let me know and I will see if i can dig up any other examples.

                              1 Reply Last reply Reply Quote 0
                              • C
                                chetansaundankar
                                last edited by

                                @eureka, Thanks for the suggestions.
                                I will try out your suggestions & get back to you with the results.

                                Before I try out though, I would like to tell you that sub-domain to search into is not known @ deployment time. Sub-domains & Users in that sub-domain are getting added dynamically, there could be hundreds of sub-domains in one root domain so fixing group BaseDN wont be possible. I had commented out <group>…</group> section completely when I had tested.

                                Also, I would like to know what exactly "%u" does in filter (&(uid=%u)).

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.