Captive portal : Expired accounts still working
-
Hi,
The local created user/password stays working with the hotspot even after the account is expired .
any Idea why ? -
@moelharrak what pfSense version are you using?
The dev, 2.5.0 version?or the prod (2.4.5 ?)
-
I'm using the version 2.4.5
-
@moelharrak said in Captive portal : Expired accounts still working:
the account is expired
You mean this one :
I'm not using the pfSense local user manager myself, but I guess the access / no access is checked when you login. hen ok, your session is opened. Eventual soft and gard time outs will apply.
Test this : use an account that will expire after 5 minutes.
Use the account to login into the captive portal.
Have it last for 10 minutes - the use account will be expired.
No, using the GUI, throw the user of the portal.Use the same account to re login into the portal.
It should not work any more.The pfSense local user manager works well when you visit the GUI : every page you visit needs authentication. You won't have to login again, because that what cookies are all about (which also have a session duration).
"Vouchers" are the ones you're looking for if you want to control the max duration of the connection time.
Or Freeradius ..... -
I can't create user to expire after 5 min , I think I found where the issue come from, when I specify 02/03/2021 as the expiration date, means that the account will expire on 02/04/2021 , 03 is included.
-
@moelharrak using Local DB "expiration date" by Captive Portal is not realized,
Please create a bugreport:
https://docs.netgate.com/pfsense/en/latest/development/bug-reports.html -
@viktor_g Actually, it is...but you have to enable "re-authenticate users every minute" (which is hidden when you use local authentication method)
-
@free4 said in Captive portal : Expired accounts still working:
@viktor_g Actually, it is...but you have to enable "re-authenticate users every minute" (which is hidden when you use local authentication method)
hm, it's not hidden for local auth (tested on 2.5 and 2.4.5-p1)
-
@viktor_g
Hidden :( disabling the captive portal all together will also hide the option ^^ / doesn't make sense neither )