Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN (SSL/TLS + User Auth.) strange login behavior

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    12 Posts 3 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      REDHELL
      last edited by

      Thanks for the information.

      Do you think to change that in the near future?
      I made some other tests. I was able to log in with a certificate of a deleted user and the credentials of an existing user. I think this could be a security issue?

      Thank you!

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        We don't yet have a CRL GUI (I'm working on that right now) - once we do, it will revoke certificates of deleted users and prevent them from getting in.

        I opened a ticket to add the more strict auth setting as an option: http://redmine.pfsense.org/issues/887

        Not sure when it will go in, but it shouldn't take too long.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • R
          REDHELL
          last edited by

          great! You do a fantastic work!!  8)

          1 Reply Last reply Reply Quote 0
          • B
            bubble1975
            last edited by

            Very eager to see this feature implemented!!  We would definitely make heavy use of it.

            1 Reply Last reply Reply Quote 0
            • B
              bubble1975
              last edited by

              Just checking in on this feature, I'm chomping at the bit for it…  ;)

              Possible ETA of implementation?

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                No ETA, just that it will happen before 2.0.

                If a commercial support subscriber were to request it be done with some of their support time, or if a suitable bounty was offered, it might speed things up, but as-is it will happen when time allows. Updates will happen on the ticket when any progress is made.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • B
                  bubble1975
                  last edited by

                  Fair enough!  Thanks again.

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    I just checked in the last bits of code to do this in the GUI. The next snapshot should include this option.

                    When you are in SSL/TLS+User Auth mode, a checkbox will show up to enable the strict username/cn matching.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • B
                      bubble1975
                      last edited by

                      Yep, I just updated and checked this, works like a charm.  Thanks a million!

                      1 Reply Last reply Reply Quote 0
                      • R
                        REDHELL
                        last edited by

                        Great!!!  ;D thank you so much…

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.