Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SSL/TLS + user auth / Openvpn two-factor authentication question

    Scheduled Pinned Locked Moved OpenVPN
    4 Posts 3 Posters 597 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nikkopegmail.com
      last edited by

      Hi. Is there a way to create openvpn server configuration with two factor authentication, SSL/TLS (cert) + username/password and export just one profile that could be used for all the users.
      In other words, do I have to export an openvpn profile for each user separately, or could this be handled so that one profile suits for all the users (that have the proper cert in their profile)
      Thanks in advance.

      br, pete

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        You should create a separate User cert and Password for each of your user for best Security, not share anything.
        If you give all Users the same certs and credentials...how would you handle the mess if some device gets compromised?

        -Rico

        1 Reply Last reply Reply Quote 2
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          Why bother to setup multiple factors of authentication only to nullify them?

          If you want one installer for everyone, do not use per-user certificates. You can use authentication only, plus the default random TLS key, and that is OK. It's best to have per-user certificates, however.

          There is always going to be a security vs convenience trade-off. If you want the best possible security, it takes the extra work to make it that way.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 2
          • N
            nikkopegmail.com
            last edited by

            @jimp

            Ok, Thanks Rico and Jimp !

            / br, pete

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.