Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ACLs to limit users to cert manager only?

    Scheduled Pinned Locked Moved webGUI
    3 Posts 2 Posters 461 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      SpaceBass
      last edited by

      hey folks,
      After a few months of testing out different open PKI platforms I've realized the interface I like the most is built into my router. I love how pfSense handles certificates and management.

      I'd like to stand up a dedicated pfsense install on an internal network (IE: no routing, dns, DHCP needed, etc) and allow LDAP users to log in and get their own user certificates and/or submit a CSR to get a machine cert.

      It doesn't seem like there's an ACL for end-user access to the cert manager. My testing feels like allowing access to the users section and the certmanager is the equivalent of root access - is that accurate? Or is there a way to make my pfPKI dream a reality?

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        What you are after is not possible because it's very weak from a security standpoint. You would be allowing anyone with LDAP credentials to download a certificate which could potentially gain them greater access. It effectively eliminates an additional security factor.

        Part of the security of certificates is protecting their distribution. Reducing that to only a username/password check (even on a local network) makes it little better than only using username/password to get into the VPN.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • S Offline
          SpaceBass
          last edited by

          Thanks @jimp - I thought that was the case. I’ve been testing OpenXPKI which has role definitions. A user can request a cert and download a CA, for instance, but only an admin can actually a cert and download keys. I was hoping I might be able to accomplish the same thing with pfSense and it’s ACLs. Oh well, I’ll stick with trying to get OpenXPKI to work.

          (I still think pfSense’s cert manager could it be it’s own product - it’s so much better than anything else I’ve seen so far!)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.