Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    User Passwords

    Scheduled Pinned Locked Moved OpenVPN
    13 Posts 5 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      Then no. Sorry.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        If those users are defined in the pfSense GUI, with a username and password there, you could grant them the WebCfg - System: User Password Manager privilege and make sure the rules allow them access to the GUI port. Then when they login to the firewall they will only be able to reach a page to change their own password.

        The easiest way to do that is via group. Make a new group called OpenVPN or similar and add your OpenVPN users to it, and grant that privilege to users in that group. As long as they don't have any other privileges, then all they can do is login to OpenVPN and change their password.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 1
        • GilG
          Gil Rebel Alliance
          last edited by

          Very nice jimp.
          Simple to implement, and simple for the user to execute.
          Works for me, many thanks.

          11 cheers for binary

          1 Reply Last reply Reply Quote 0
          • GilG
            Gil Rebel Alliance
            last edited by

            If I may suggest:
            An ability to mandate a periodical password change?

            11 cheers for binary

            1 Reply Last reply Reply Quote 0
            • RicoR
              Rico LAYER 8 Rebel Alliance
              last edited by

              ...mostly results in Users setting weak passwords. ;-)

              -Rico

              1 Reply Last reply Reply Quote 0
              • GilG
                Gil Rebel Alliance
                last edited by

                We then get into the issue of minimum password complexities regardless of who creates them

                11 cheers for binary

                1 Reply Last reply Reply Quote 0
                • GrimsonG
                  Grimson Banned
                  last edited by

                  Feature Requests need to be placed on https://redmine.pfsense.org. Good Luck.

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    NIST removed the "periodic change" suggestion over a year ago, same for password complexity requirement suggestions. Password length is the only key factor now.

                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    GilG 1 Reply Last reply Reply Quote 0
                    • GilG
                      Gil Rebel Alliance @jimp
                      last edited by

                      @jimp said in User Passwords:

                      Password length is the only key factor now.

                      Is there a minimum enforced for a pfSense user?
                      I think NIST suggests a minimum of 8.

                      11 cheers for binary

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        pfSense does not impose any requirements on passwords at the moment. You will get a warning if the password is left as pfsense but that's it.

                        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.