Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    User Passwords

    OpenVPN
    5
    13
    1.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GilG
      Gil Rebel Alliance
      last edited by

      Is it possible to force (or allow) a user change their own password for their Openvpn Road warrior connection?

      11 cheers for binary

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Where are the passwords stored?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • GilG
          Gil Rebel Alliance
          last edited by

          Local database on the OpenVPN Server

          11 cheers for binary

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Then no. Sorry.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              If those users are defined in the pfSense GUI, with a username and password there, you could grant them the WebCfg - System: User Password Manager privilege and make sure the rules allow them access to the GUI port. Then when they login to the firewall they will only be able to reach a page to change their own password.

              The easiest way to do that is via group. Make a new group called OpenVPN or similar and add your OpenVPN users to it, and grant that privilege to users in that group. As long as they don't have any other privileges, then all they can do is login to OpenVPN and change their password.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 1
              • GilG
                Gil Rebel Alliance
                last edited by

                Very nice jimp.
                Simple to implement, and simple for the user to execute.
                Works for me, many thanks.

                11 cheers for binary

                1 Reply Last reply Reply Quote 0
                • GilG
                  Gil Rebel Alliance
                  last edited by

                  If I may suggest:
                  An ability to mandate a periodical password change?

                  11 cheers for binary

                  1 Reply Last reply Reply Quote 0
                  • RicoR
                    Rico LAYER 8 Rebel Alliance
                    last edited by

                    ...mostly results in Users setting weak passwords. ;-)

                    -Rico

                    1 Reply Last reply Reply Quote 0
                    • GilG
                      Gil Rebel Alliance
                      last edited by

                      We then get into the issue of minimum password complexities regardless of who creates them

                      11 cheers for binary

                      1 Reply Last reply Reply Quote 0
                      • GrimsonG
                        Grimson Banned
                        last edited by

                        Feature Requests need to be placed on https://redmine.pfsense.org. Good Luck.

                        1 Reply Last reply Reply Quote 0
                        • jimpJ
                          jimp Rebel Alliance Developer Netgate
                          last edited by

                          NIST removed the "periodic change" suggestion over a year ago, same for password complexity requirement suggestions. Password length is the only key factor now.

                          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                          Need help fast? Netgate Global Support!

                          Do not Chat/PM for help!

                          GilG 1 Reply Last reply Reply Quote 0
                          • GilG
                            Gil Rebel Alliance @jimp
                            last edited by

                            @jimp said in User Passwords:

                            Password length is the only key factor now.

                            Is there a minimum enforced for a pfSense user?
                            I think NIST suggests a minimum of 8.

                            11 cheers for binary

                            1 Reply Last reply Reply Quote 0
                            • jimpJ
                              jimp Rebel Alliance Developer Netgate
                              last edited by

                              pfSense does not impose any requirements on passwords at the moment. You will get a warning if the password is left as pfsense but that's it.

                              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                              Need help fast? Netgate Global Support!

                              Do not Chat/PM for help!

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.