How to enable LDAP user authentication and TOTP.
-
Re: [Is it possible to combine OTP and LDAP authentication with FreeRadius ?](/topic/140922/is-it-possible-to-combine-otp-and-ldap-authentication-with-freeradius
I just tested it with pfSense 2.5.0 + FreeIPA 4.8.7
-
pfSense users are defined in FreeIPA LDAP
-
pfSense setup to authenticate user FreeIPA LDAP users (many manual online)
-
pfSense users have to login in FreeIPA WebUI once, create an OTP token, scan QR code to add OTP entry to FreeOTP app on their smartphones. After that password+OTP authentication type is enforced in user's settings (or in FreeIPA global LDAP service settings but first don't forget to add OTP to FreeIPA admin account!)
-
FreeIPA users login to pfSense webConfigurator with their usernames and <password><OTP> credentials.
I don't see why it won't work for OpenVPN access too.
Works jut perfect.
-