Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN remove client

    Scheduled Pinned Locked Moved OpenVPN
    20 Posts 3 Posters 4.7k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Allwan
      last edited by

      @viragomann said in OpenVPN remove client:

      Then you're lost. You need the certificate to revoke it.
      The OpenVPN is configured to accept any user cert which is issued by the CA you've set, as long it isn't in the selected CRL.
      Possibly you can restore the cert from a backup.

      Very well i understand
      thanks anyway

      V 1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann @Allwan
        last edited by

        @Allwan

        pfSense automatically saves config history:

        20a3f6d0-cfbd-411f-acbe-8347a1800109-grafik.png

        Possibly you can temporarily revert to a config where the cert still exists, use the cert manager to export it and the key and after revert back to the actual config.

        1 Reply Last reply Reply Quote 0
        • A Offline
          Allwan
          last edited by

          ah great !!!!
          very happy, I was able to find him.

          thanks you

          1 Reply Last reply Reply Quote 0
          • A Offline
            Allwan
            last edited by

            But I still have a connection.

            8ac6308d-5077-4a4d-b715-3859c045ce31-image.png

            d73166c7-eed6-41cf-b21d-d126bf31d8bc-image.png

            V 1 Reply Last reply Reply Quote 0
            • V Offline
              viragomann @Allwan
              last edited by

              @Allwan
              After revoking the cert, the client can still connect?
              Existing connections are not cut when adding the respective cert to the CRL.

              Did you assing the CRL the server?

              1 Reply Last reply Reply Quote 0
              • A Offline
                Allwan
                last edited by

                i will see

                1 Reply Last reply Reply Quote 0
                • V Offline
                  viragomann
                  last edited by

                  Just kill the connection:

                  dea18001-3963-459f-9e59-eb407d135525-grafik.png

                  1 Reply Last reply Reply Quote 0
                  • bingo600B Offline
                    bingo600
                    last edited by

                    Just for my understanding.

                    If you're changing the users passwd in the user manager & kill the connection.
                    Would that not prevent the user to login again ?
                    If not , then what good is the uid/pwd ??

                    I'd still revoke the cert , if i needed to ban a user permaneltly.

                    But for a temporarily disable (enable) login , i had hoped to use the
                    User Expiration date.

                    Ie. a Consultant that would have 1 week access for this specific task , and might need access later on.

                    /Bingo

                    If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                    pfSense+ 23.05.1 (ZFS)

                    QOTOM-Q355G4 Quad Lan.
                    CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                    LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                    V 1 Reply Last reply Reply Quote 0
                    • V Offline
                      viragomann @bingo600
                      last edited by

                      @bingo600 said in OpenVPN remove client:

                      Would that not prevent the user to login again ?

                      Sure, it does, when the server is in a "User auth" mode.

                      You can also revoke a user cert temporarily. After removing from the CRL it is accepted again by the server.

                      Also consider, when "Strict User-CN Matching" in the server settings is not checked it will be possible for a user to use another ones cert for authentication.

                      bingo600B 1 Reply Last reply Reply Quote 0
                      • bingo600B Offline
                        bingo600 @viragomann
                        last edited by

                        @viragomann said in OpenVPN remove client:

                        @bingo600 said in OpenVPN remove client:

                        Would that not prevent the user to login again ?

                        Sure, it does, when the server is in a "User auth" mode.

                        You can also revoke a user cert temporarily. After removing from the CRL it is accepted again by the server.

                        Also consider, when "Strict User-CN Matching" in the server settings is not checked it will be possible for a user to use another ones cert for authentication.

                        I'm using this (SSL/TLS + User auth)
                        d81e0a60-2b25-420c-87bb-1f6f1175dad9-image.png

                        And have
                        9a07cda2-d9ab-4b29-9a92-883ca7b7cdee-image.png

                        Thanx for the confirmation

                        /Bingo

                        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                        pfSense+ 23.05.1 (ZFS)

                        QOTOM-Q355G4 Quad Lan.
                        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.