Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    After 2.3 upgrade no users in client export

    Scheduled Pinned Locked Moved OpenVPN
    12 Posts 7 Posters 3.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cwl
      last edited by

      Same with me. When I restore an old config, I see the clients. In the fresh install, it´s empty.

      1 Reply Last reply Reply Quote 0
      • D
        divsys
        last edited by

        Same with me. When I restore an old config, I see the clients. In the fresh install, it´s empty.

        Why would you expect to see your clients in a fresh install?
        Until you restore your previous config file, a new install has nothing but factory defaults.

        If you're saying that restoring a recent config file doesn't show your certs, but an older one does, then that points at a problem in your config files.

        Just for the record, I have upgraded at least four different systems and they all show clients in the export.
        Not to say there isn't a potential problem, but it's not seen by everyone.

        -jfp

        1 Reply Last reply Reply Quote 0
        • C
          cwl
          last edited by

          In the fresh install, I certainly created a new client  ;) - But he won't show up. I know that there must be a client configured to get something shown…

          1 Reply Last reply Reply Quote 0
          • D
            divsys
            last edited by

            The only time I've not been able to access a client cert in the Export util is when I create the cert using the wrong CA for the export server in question.

            -jfp

            1 Reply Last reply Reply Quote 0
            • N
              neo12_15
              last edited by

              Any advance?

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                Like divsys said, check that the Peer Certificate CA selected in the OpenVPN server and the Issuer of the user certificates match.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • PippinP
                  Pippin
                  last edited by

                  @Derelict:

                  Like divsys said, check that the Peer Certificate CA selected in the OpenVPN server and the Issuer of the user certificates match.

                  That is the case in my case, still no fun.

                  I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
                  Halton Arp

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    I haven't looked at the code yet but I know there have been some changes to the verification of the type of certificates used by the servers so they might be checking the type of certificates used by clients too. Are they, in fact, user certificates (Server: No)?

                    Any CAs/Certs expired?

                    When you view System > Cert.Manager, Certificates is the Issuer of the user certs the same CA that is listed as OpenVPN's Peer Certificate CA?

                    What is the Server Mode on your Remote Access OpenVPN instance?

                    Everything I have upgraded has just worked in this regard. Have to find what's peculiar about your setup.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • PippinP
                      Pippin
                      last edited by

                      @Derelict:

                      Are they, in fact, user certificates (Server: No)?

                      Yes.

                      Any CAs/Certs expired?

                      No, fresh install.

                      When you view System > Cert.Manager, Certificates is the Issuer of the user certs the same CA that is listed as OpenVPN's Peer Certificate CA?

                      Yes.

                      What is the Server Mode on your Remote Access OpenVPN instance?

                      Peer to Peer (SSL/TLS)  :o
                      I`m stupid, I know… ;D

                      I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
                      Halton Arp

                      1 Reply Last reply Reply Quote 0
                      • D
                        drazil
                        last edited by

                        OK, so all of the answers to the ultimate questions listed  were a 100% match for me.  This is what I had to do:  In pfSense, go to System - Package Manager - Available Packages. Find the package called openvpn-client-export and hit the install button, then confirm.  I wasn't aware that there were additional packages. And now it makes sense why folks who have fresh installs run across this.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.