Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN with only certificates, no users pfSense 2.0RC3

    Scheduled Pinned Locked Moved OpenVPN
    21 Posts 4 Posters 24.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      TLP
      last edited by

      I really cant export the certs from the Client Export utility without an user
      thats the strange thing, very odd

      1 Reply Last reply Reply Quote 0
      • R
        rkelleyrtp
        last edited by

        Same here.  No users = no export ability.

        1 Reply Last reply Reply Quote 0
        • N
          Nachtfalke
          last edited by

          Hi,

          I had a second user in the past when I installed Client Export utility but now there is only the default admin user.

          User.jpg
          User.jpg_thumb
          OVPN-Export.jpg
          OVPN-Export.jpg_thumb

          1 Reply Last reply Reply Quote 0
          • T
            TLP
            last edited by

            This is very strange, whats your pfsense version and package version???
            we are missing something

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              Read the note at the bottom there. If you can select your VPN from the export list and see no clients to export, you probably did not generate your client certificates from the same CA that the VPN is set to use. Double check the CA selected for the VPN.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • T
                TLP
                last edited by

                OK it worked now, what I did was recreate every cert (on cert manager and openvpn) but paying doubled attention to certificates and it showed now

                thanks all

                1 Reply Last reply Reply Quote 0
                • T
                  TLP
                  last edited by

                  OK just one problem, for every computer do I need to create a new certificate and a new openvpn server certificate??

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    You only have one server certificate/ca, you have one certificate per user.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • N
                      Nachtfalke
                      last edited by

                      @TLP:

                      OK just one problem, for every computer do I need to create a new certificate and a new openvpn server certificate??

                      1.) You don't need to create an further OpenVPN Server certificate.
                      2.) You can use the same certificate for different computers BUT then you have to configure this on your server to allow multiple connection from same common name. Further if you revoke a certificate, than alle clients with the same certificate cannot access anymore.
                      so the the way you should go is:
                      3.) For every Computer create a new certificate.

                      1 Reply Last reply Reply Quote 0
                      • T
                        TLP
                        last edited by

                        yeah i forgot the user manager  ;D

                        but thats cool, now I got it
                        thats exactly what i wanted
                        thanks all (again)  ;)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.