Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    TLS keydir direction

    Scheduled Pinned Locked Moved OpenVPN
    6 Posts 2 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vvasilev
      last edited by

      It appears that no matter what I set the value to, the '"TLS keydir direction" under VPN -> OpenVPN -> Clients isn't accepted and remains set to "Use default direction" on the web interface. However, the option is completely missing in the pfsense config file under. I should be under:

      <openvpn-client>
      ...
      <tlsauth_keydir></tlsauth_keydir> MISSING

      This breaks the tunnel I'm trying to bring up. Anyone experiencing the same?

      I'm running 2.4.5-RELEASE-p1.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        I tried on pfSense 2.4.5-p1 and 2.5.0 and in both cases, I was able to set the TLS key direction to any of the possible values and it changed as expected, and was reflected in config.xml

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        jimpJ 1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate @jimp
          last edited by

          Are you certain you have the VPN set to a mode where that is relevant? It would only be relevant in SSL/TLS mode with an active TLS key, not in shared key mode.

          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • V
            vvasilev
            last edited by

            I've got a simple PSK based VPN, but with directional keys. The server is on linux box where 0 follows the static key and the pfsense is the client where 1 would be set.

            [root@ovpnserver] # openvpn
            --ifconfig X.X.X.X X.X.X.X
            --dev tun
            --secret secret.key 0
            --verb 7

            Would in pfsense "TLS keydir direction" be only applicable to TLS/SSL mode? If so, PSK with directional keys isn't supported then?

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              A shared key is not a TLS key.

              The shared key setting in pfSense doesn't support a direction.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • V
                vvasilev
                last edited by

                I had this feeling and thanks for confirming it. I'll remove the direction.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.