Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN remove client

    Scheduled Pinned Locked Moved OpenVPN
    20 Posts 3 Posters 4.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Allwan
      last edited by

      Hello,
      On openVPN, I would like to know how to delete a client so that he no longer has access to the VPN?
      I deleted :

      • his name in "user manager"
      • its certificate "certificate manager> certificates"
      • its name in "openvpn> client-specific rewrites"

      But I still see it connected.

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Revoke his certificate and configure the OpenVPN server to use that CRL.

        1 Reply Last reply Reply Quote 0
        • A
          Allwan
          last edited by

          Thank you for your answer
          I have two certificates :

          88d0cb36-b91b-4430-b463-f08ef6c5e42e-image.png

          and clients are configured with the "CERT_VPN_ALLWAN" certificates.

          585c2f68-7e62-4545-93cb-dd9d1ddedc5c-image.png

          my question is, if I revoke the "CERT_VPN_ALLWAN" certificate, will I lose connections on other clients?

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by viragomann

            Each client has to have his unique cert. If you revoke one that cert is no longer accepted by the server.
            If multiple clients use a single cert you will have a problem.

            @Allwan said in OpenVPN remove client:

            if I revoke the "CERT_VPN_ALLWAN" certificate

            The user certs have different names, "CERT_VPN_ALLWAN" is the issuer.

            1 Reply Last reply Reply Quote 0
            • A
              Allwan
              last edited by

              when I create a client, I choose this certificate

              3173b94e-cc81-41eb-9e2c-a2c37aae5f1d-image.png

              It's not good? because all my clients are like this :(

              1 Reply Last reply Reply Quote 0
              • V
                viragomann
                last edited by

                No, you choose the CA (issuer) here which is signing the client cert.

                1 Reply Last reply Reply Quote 0
                • A
                  Allwan
                  last edited by

                  so where do i remove the user certificate?

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    viragomann @Allwan
                    last edited by viragomann

                    @Allwan
                    Revoke not remove! The cert must still exist on pfSense.

                    05187b53-4843-4489-94ec-22a4cfded21a-grafik.png

                    If you haven't already any, add a Certificate Revocation List (CRL) to your CA.
                    Then you're able to add user certs to this list which you want to revoke, so that the cert can no longer be used to authenticate.

                    Add the CRL to your OpenVPN servers settings:

                    16395464-65e8-44dd-a63b-552adfde208f-grafik.png

                    1 Reply Last reply Reply Quote 0
                    • A
                      Allwan
                      last edited by

                      But I have deleted the certificate from the list of certificates suddenly I cannot revoke it.

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        viragomann @Allwan
                        last edited by

                        @Allwan
                        Then you're lost. You need the certificate to revoke it.

                        The OpenVPN is configured to accept any user cert which is issued by the CA you've set, as long it isn't in the selected CRL.

                        Possibly you can restore the cert from a backup.

                        1 Reply Last reply Reply Quote 0
                        • A
                          Allwan
                          last edited by

                          @viragomann said in OpenVPN remove client:

                          Then you're lost. You need the certificate to revoke it.
                          The OpenVPN is configured to accept any user cert which is issued by the CA you've set, as long it isn't in the selected CRL.
                          Possibly you can restore the cert from a backup.

                          Very well i understand
                          thanks anyway

                          V 1 Reply Last reply Reply Quote 0
                          • V
                            viragomann @Allwan
                            last edited by

                            @Allwan

                            pfSense automatically saves config history:

                            20a3f6d0-cfbd-411f-acbe-8347a1800109-grafik.png

                            Possibly you can temporarily revert to a config where the cert still exists, use the cert manager to export it and the key and after revert back to the actual config.

                            1 Reply Last reply Reply Quote 0
                            • A
                              Allwan
                              last edited by

                              ah great !!!!
                              very happy, I was able to find him.

                              thanks you

                              1 Reply Last reply Reply Quote 0
                              • A
                                Allwan
                                last edited by

                                But I still have a connection.

                                8ac6308d-5077-4a4d-b715-3859c045ce31-image.png

                                d73166c7-eed6-41cf-b21d-d126bf31d8bc-image.png

                                V 1 Reply Last reply Reply Quote 0
                                • V
                                  viragomann @Allwan
                                  last edited by

                                  @Allwan
                                  After revoking the cert, the client can still connect?
                                  Existing connections are not cut when adding the respective cert to the CRL.

                                  Did you assing the CRL the server?

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    Allwan
                                    last edited by

                                    i will see

                                    1 Reply Last reply Reply Quote 0
                                    • V
                                      viragomann
                                      last edited by

                                      Just kill the connection:

                                      dea18001-3963-459f-9e59-eb407d135525-grafik.png

                                      1 Reply Last reply Reply Quote 0
                                      • bingo600B
                                        bingo600
                                        last edited by

                                        Just for my understanding.

                                        If you're changing the users passwd in the user manager & kill the connection.
                                        Would that not prevent the user to login again ?
                                        If not , then what good is the uid/pwd ??

                                        I'd still revoke the cert , if i needed to ban a user permaneltly.

                                        But for a temporarily disable (enable) login , i had hoped to use the
                                        User Expiration date.

                                        Ie. a Consultant that would have 1 week access for this specific task , and might need access later on.

                                        /Bingo

                                        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                                        pfSense+ 23.05.1 (ZFS)

                                        QOTOM-Q355G4 Quad Lan.
                                        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                                        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                                        V 1 Reply Last reply Reply Quote 0
                                        • V
                                          viragomann @bingo600
                                          last edited by

                                          @bingo600 said in OpenVPN remove client:

                                          Would that not prevent the user to login again ?

                                          Sure, it does, when the server is in a "User auth" mode.

                                          You can also revoke a user cert temporarily. After removing from the CRL it is accepted again by the server.

                                          Also consider, when "Strict User-CN Matching" in the server settings is not checked it will be possible for a user to use another ones cert for authentication.

                                          bingo600B 1 Reply Last reply Reply Quote 0
                                          • bingo600B
                                            bingo600 @viragomann
                                            last edited by

                                            @viragomann said in OpenVPN remove client:

                                            @bingo600 said in OpenVPN remove client:

                                            Would that not prevent the user to login again ?

                                            Sure, it does, when the server is in a "User auth" mode.

                                            You can also revoke a user cert temporarily. After removing from the CRL it is accepted again by the server.

                                            Also consider, when "Strict User-CN Matching" in the server settings is not checked it will be possible for a user to use another ones cert for authentication.

                                            I'm using this (SSL/TLS + User auth)
                                            d81e0a60-2b25-420c-87bb-1f6f1175dad9-image.png

                                            And have
                                            9a07cda2-d9ab-4b29-9a92-883ca7b7cdee-image.png

                                            Thanx for the confirmation

                                            /Bingo

                                            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                                            pfSense+ 23.05.1 (ZFS)

                                            QOTOM-Q355G4 Quad Lan.
                                            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                                            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.