Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    User Passwords

    Scheduled Pinned Locked Moved OpenVPN
    13 Posts 5 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      Where are the passwords stored?

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • GilG
        Gil Rebel Alliance
        last edited by

        Local database on the OpenVPN Server

        11 cheers for binary

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          Then no. Sorry.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            If those users are defined in the pfSense GUI, with a username and password there, you could grant them the WebCfg - System: User Password Manager privilege and make sure the rules allow them access to the GUI port. Then when they login to the firewall they will only be able to reach a page to change their own password.

            The easiest way to do that is via group. Make a new group called OpenVPN or similar and add your OpenVPN users to it, and grant that privilege to users in that group. As long as they don't have any other privileges, then all they can do is login to OpenVPN and change their password.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 1
            • GilG
              Gil Rebel Alliance
              last edited by

              Very nice jimp.
              Simple to implement, and simple for the user to execute.
              Works for me, many thanks.

              11 cheers for binary

              1 Reply Last reply Reply Quote 0
              • GilG
                Gil Rebel Alliance
                last edited by

                If I may suggest:
                An ability to mandate a periodical password change?

                11 cheers for binary

                1 Reply Last reply Reply Quote 0
                • RicoR
                  Rico LAYER 8 Rebel Alliance
                  last edited by

                  ...mostly results in Users setting weak passwords. ;-)

                  -Rico

                  1 Reply Last reply Reply Quote 0
                  • GilG
                    Gil Rebel Alliance
                    last edited by

                    We then get into the issue of minimum password complexities regardless of who creates them

                    11 cheers for binary

                    1 Reply Last reply Reply Quote 0
                    • GrimsonG
                      Grimson Banned
                      last edited by

                      Feature Requests need to be placed on https://redmine.pfsense.org. Good Luck.

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        NIST removed the "periodic change" suggestion over a year ago, same for password complexity requirement suggestions. Password length is the only key factor now.

                        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        GilG 1 Reply Last reply Reply Quote 0
                        • GilG
                          Gil Rebel Alliance @jimp
                          last edited by

                          @jimp said in User Passwords:

                          Password length is the only key factor now.

                          Is there a minimum enforced for a pfSense user?
                          I think NIST suggests a minimum of 8.

                          11 cheers for binary

                          1 Reply Last reply Reply Quote 0
                          • jimpJ
                            jimp Rebel Alliance Developer Netgate
                            last edited by

                            pfSense does not impose any requirements on passwords at the moment. You will get a warning if the password is left as pfsense but that's it.

                            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                            Need help fast? Netgate Global Support!

                            Do not Chat/PM for help!

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.