Create certificate for all ldap users

  • Hello,

    I've a pfsense with a openvpn server, id like to link my ldap with the openvpn, but i have some requirements.

    Users should have a personal certificate (ok -> i create a certificate with the same CN).
    I need to push them a defined IP (ok -> CSC ifconfig)
    I need to export the user .exe (ok -> client export config)

    But i need to do that for ~300 users …

    All users are in a specific group in the ldap and have an attribute for the IP they need to have in the VPN

    What is the fastest way to achieve that ?

    Available API ? (planned for pfsense 3 i think) Custom script to call PHP functions / pages ? We hire a trainee ?

    I hope someone can help me on this one :)

  • Rebel Alliance Developer Netgate

    There is no automated way to accomplish that, you'd have to create the certificates individually. You could create the certificates using OpenSSL outside of pfSense, but to use the export package you'd still have to import them to pfSense.

