• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfsense authentication server ldaps / wildcard problem

Scheduled Pinned Locked Moved General pfSense Questions
13 Posts 3 Posters 1.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    tsmalmbe @tsmalmbe
    last edited by Jan 5, 2021, 11:10 AM

    I think I have covered everything that is mentioned here https://docs.netgate.com/pfsense/en/latest/troubleshooting/authentication.html#Debugging_LDAP

    Security Consultant at Mint Security Ltd - www.mintsecurity.fi

    1 Reply Last reply Reply Quote 0
    • T
      tsmalmbe
      last edited by Jan 5, 2021, 2:33 PM

      Now I'm trying to wrap my head around this https://github.com/pfsense/pfsense/blob/master/src/etc/inc/auth.inc to understand where the checks are actually made.

      Security Consultant at Mint Security Ltd - www.mintsecurity.fi

      T 1 Reply Last reply Jan 5, 2021, 2:48 PM Reply Quote 0
      • T
        tsmalmbe @tsmalmbe
        last edited by Jan 5, 2021, 2:48 PM

        I think I have verified that the "Entrust Certification Authority - L1K" is not in /usr/local/share/certs/ca-root-nss.crt. Hence Global CA list will never work with the Entrust certs. Choosing any of the intermediates in the chain does not work either, as explained in the previous posts.

        Security Consultant at Mint Security Ltd - www.mintsecurity.fi

        T 1 Reply Last reply Jan 7, 2021, 11:58 AM Reply Quote 0
        • T
          tsmalmbe @tsmalmbe
          last edited by Jan 7, 2021, 11:58 AM

          So really, any discussion or commentary would be appreciated here.

          Security Consultant at Mint Security Ltd - www.mintsecurity.fi

          1 Reply Last reply Reply Quote 0
          • T
            tsmalmbe
            last edited by Jan 14, 2021, 8:44 AM

            Is it appropriate to say I would gladly pay a 100€ "bounty" if this could be fixed?

            Security Consultant at Mint Security Ltd - www.mintsecurity.fi

            V 1 Reply Last reply Jan 14, 2021, 10:15 AM Reply Quote 0
            • V
              viktor_g Netgate @tsmalmbe
              last edited by Jan 14, 2021, 10:15 AM

              @tsmalmbe Please create a detailed bugreport:
              https://docs.netgate.com/pfsense/en/latest/development/bug-reports.html

              T 1 Reply Last reply Jan 29, 2021, 11:18 AM Reply Quote 0
              • T
                tsmalmbe @viktor_g
                last edited by Jan 29, 2021, 11:18 AM

                @viktor_g It is here https://redmine.pfsense.org/issues/11332

                Security Consultant at Mint Security Ltd - www.mintsecurity.fi

                1 Reply Last reply Reply Quote 0
                • J
                  jimp Rebel Alliance Developer Netgate
                  last edited by Jan 29, 2021, 1:46 PM

                  There aren't enough details here yet to say what the problem is for sure. But your best bet is to use a 2.5.0 snapshot.

                  Import the chain into 2.5.0, and for the root and intermediates, check the box that adds them to the trust store.

                  The PHP LDAP code is cranky sometimes, but that can help. Also, when debugging, after any change in the LDAP settings, open a console menu and run option 16 then option 11.

                  If none of that helps, I'm not sure there is anything we can do to fix it -- it could be a problem in PHP LDAP itself.

                  We've also recently found that some things won't trust wildcard certificates on purpose, so you might try a server cert with only the SAN for the hostname if you can.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 1
                  • T
                    tsmalmbe
                    last edited by Feb 11, 2021, 10:42 AM

                    @jimp Okay, thanks for the input. I don't have the possibility to (easily) setup a test environment with a new version of the software, so I will have to test this once there is a release available.

                    Security Consultant at Mint Security Ltd - www.mintsecurity.fi

                    T 1 Reply Last reply Apr 16, 2021, 9:28 AM Reply Quote 0
                    • T
                      tsmalmbe @tsmalmbe
                      last edited by Apr 16, 2021, 9:28 AM

                      An update to this - there has been no change/improvement to this with 2.5.0 nor 2.5.1.

                      Security Consultant at Mint Security Ltd - www.mintsecurity.fi

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received