Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    openvpn webgui can't show full Peer Certificate Authority list.

    Scheduled Pinned Locked Moved 2.5 Development Snapshots (Retired)
    15 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • yon 0Y
      yon 0 @jimp
      last edited by

      @jimp
      I am the imported CA EC certificate, The previous PF2.4.5 version unanimously supports normal operation.

      1 Reply Last reply Reply Quote 0
      • yon 0Y
        yon 0
        last edited by yon 0

        openvpn support ecdh-curve secp256k1, i have running it longtime.

        -----BEGIN CERTIFICATE-----
        MIIBvzCCAWWgAwIBAgIUDgMzRJ5yKP1zLcUiqf886lh0cTAwCgYIKoZIzj0EAwIw
        FzEVMBMGA1UEAwwMdi54aWFveXUubmV0MB4XDTIwMDUwMTE1MDM1NloXDTMwMDQy
        OTE1MDM1NlowFzEVMBMGA1UEAwwMdi54aWFveXUubmV0MFYwEAYHKoZIzj0CAQYF
        K4EEAAoDQgAEsusHCkEPcghM3QXkh6unuklTpga7TaaBVeQQQJ9Gvl1bgXtz30PX
        XQr3HzcUBtpkebsXBntlJyT8oXSxLsQsSqOBkTCBjjAdBgNVHQ4EFgQUN5S+Pjbg
        CRGh+710yLmn1VVBtmwwUgYDVR0jBEswSYAUN5S+PjbgCRGh+710yLmn1VVBtmyh
        G6QZMBcxFTATBgNVBAMMDHYueGlhb3l1Lm5ldIIUDgMzRJ5yKP1zLcUiqf886lh0
        cTAwDAYDVR0TBAUwAwEB/zALBgNVHQ8EBAMCAQYwCgYIKoZIzj0EAwIDSAAwRQIg
        MAT7FDOLCon2NXTAFAf/WrOtjMcCnwxHku1SEL6F7VwCIQCiCTqrbRPHN+CFUD0z
        7el+fyGcN37LA/my30AgT/luIA==
        -----END CERTIFICATE-----
        
        
        yon 0Y 1 Reply Last reply Reply Quote 0
        • yon 0Y
          yon 0
          last edited by yon 0

          and please add Edward Curves for support, openvpn supported it also

          https://github.com/OpenVPN/easy-rsa/releases

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            2.4.5 did not support EC certificates, and support for EC on 2.4.x won't happen. OpenVPN may support it, but other components on 2.4.x do not.

            OpenVPN may support ED certs but PHP OpenSSL does not, so they cannot be added at this time.

            These are the only acceptable compatible curves for each service that are known to work: https://github.com/pfsense/pfsense/blob/523d8c3fb74a3f2c6a8917df239e82d159a89436/src/etc/inc/certs.inc#L2423

            The curve you mention is claimed to be supported by OpenVPN but does not function with OpenSSL 1.1.1: https://redmine.pfsense.org/issues/9744 https://community.openvpn.net/openvpn/ticket/1177

            Stick to the curves we have tested and know to work. There is a reason we have limited the list.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • yon 0Y
              yon 0
              last edited by

              @jimp said in openvpn webgui can't show full Peer Certificate Authority list.:

              OpenSSL 1.1.1

              OpenSSL 1.1.1 support ed25519
              https://www.openssl.org/docs/man1.1.1/man7/Ed25519.html

              1 Reply Last reply Reply Quote 0
              • yon 0Y
                yon 0
                last edited by

                @yon-0 said in openvpn webgui can't show full Peer Certificate Authority list.:

                secp256k1

                i have try use secp256k1 work in pf 2.4.5 openvpn , but new pf 2.5 not work.

                jimpJ 1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  I didn't say it didn't. Read my comment again.

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate @yon 0
                    last edited by

                    @yon-0 said in [openvpn webgui can't show full Peer Certificate Authority

                    i have try use secp256k1 work in pf 2.4.5 openvpn , but new pf 2.5 not work.

                    I explained why in my comment. Read it again.

                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • yon 0Y
                      yon 0 @yon 0
                      last edited by yon 0

                      @yon-0 said in openvpn webgui can't show full Peer Certificate Authority list.:

                      openvpn support ecdh-curve secp256k1, i have running it longtime.

                      -----BEGIN CERTIFICATE-----
                      MIIBvzCCAWWgAwIBAgIUDgMzRJ5yKP1zLcUiqf886lh0cTAwCgYIKoZIzj0EAwIw
                      FzEVMBMGA1UEAwwMdi54aWFveXUubmV0MB4XDTIwMDUwMTE1MDM1NloXDTMwMDQy
                      OTE1MDM1NlowFzEVMBMGA1UEAwwMdi54aWFveXUubmV0MFYwEAYHKoZIzj0CAQYF
                      K4EEAAoDQgAEsusHCkEPcghM3QXkh6unuklTpga7TaaBVeQQQJ9Gvl1bgXtz30PX
                      XQr3HzcUBtpkebsXBntlJyT8oXSxLsQsSqOBkTCBjjAdBgNVHQ4EFgQUN5S+Pjbg
                      CRGh+710yLmn1VVBtmwwUgYDVR0jBEswSYAUN5S+PjbgCRGh+710yLmn1VVBtmyh
                      G6QZMBcxFTATBgNVBAMMDHYueGlhb3l1Lm5ldIIUDgMzRJ5yKP1zLcUiqf886lh0
                      cTAwDAYDVR0TBAUwAwEB/zALBgNVHQ8EBAMCAQYwCgYIKoZIzj0EAwIDSAAwRQIg
                      MAT7FDOLCon2NXTAFAf/WrOtjMcCnwxHku1SEL6F7VwCIQCiCTqrbRPHN+CFUD0z
                      7el+fyGcN37LA/my30AgT/luIA==
                      -----END CERTIFICATE-----
                      
                      

                      i am srue change back pf2.4.5-p1 and the secp256k1 ca cert is work for openvpn now.

                      just i mean that it can work pf2.4.5 version, but it can't work in pf 2.5 version.

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        That may be the case but it was never supported properly in pfSense. If it worked, it worked by accident.

                        And I already stated above why it does not work on 2.5.0 (Due to an OpenVPN/OpenSSL 1.1.1 bug)

                        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • yon 0Y
                          yon 0
                          last edited by

                          I hope to update the latest and safe advanced technology. Safer and better performance is our goal.

                          http://safecurves.cr.yp.to/

                          1 Reply Last reply Reply Quote 0
                          • yon 0Y
                            yon 0
                            last edited by

                            cert bugs from pf2.4.5 to pf 2.5 upgrade

                            System_ Certificate Manager_ CAs.jpg

                            1 Reply Last reply Reply Quote 0
                            • yon 0Y
                              yon 0
                              last edited by

                              just now it is work that using Ed448 curves for opnvpn in pf2.5 built on Thu Aug 13 13:04:02 EDT 2020 tls-version-min 1.3

                              this is great !

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.