<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Upgrade to 21.02 -&gt; Client Cert on LDAP server no Longer Accepted]]></title><description><![CDATA[<p dir="auto">I have two authentication servers configured.  Both use the same CA which was generated by Samba4.  Both are using SSL/TLS Encrypted transport.</p>
<p dir="auto">One server has nothing defined for the "client certificate" and the other has a certificate which was imported from Samba.</p>
<p dir="auto">Pre-upgrade, both configurations worked.  Post-upgrade, the configuration with the Samba generated cert can no longer authenticate.</p>
<p dir="auto">When connecting via OpenVPN, the now non-working configuration logs the following:</p>
<p dir="auto">2021-02-19 09:04:43 AUTH: Received control message: AUTH_FAILED<br />
2021-02-19 09:04:44 SIGUSR1[soft,auth-failure] received, process restarting<br />
2021-02-19 09:04:53 ERROR: could not read Auth username/password/ok/string from management interface<br />
2021-02-19 09:04:53 Exiting due to fatal error</p>
<p dir="auto">Has anyone seen anything similar?</p>
]]></description><link>https://forum.netgate.com/topic/161087/upgrade-to-21-02-client-cert-on-ldap-server-no-longer-accepted</link><generator>RSS for Node</generator><lastBuildDate>Sun, 15 Mar 2026 14:15:10 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/161087.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 19 Feb 2021 14:30:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Upgrade to 21.02 -&gt; Client Cert on LDAP server no Longer Accepted on Mon, 19 Apr 2021 07:48:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/airwave">@<bdi>airwave</bdi></a> said in <a href="/post/978542">Upgrade to 21.02 -&gt; Client Cert on LDAP server no Longer Accepted</a>:</p>
<blockquote>
<p dir="auto">I updated to 2.5.1 AND now it works and a connection is established and traffic is been delivered, but ONLY ONCE after openvpn service start.<br />
When I then disconnect and reconnect, again I get a connection, but the communication / traffic (ping etc.) is not working. Only in the first connection traffic works. When I restart the openvpn service then, its again working once...</p>
</blockquote>
<p dir="auto">Hi all,</p>
<p dir="auto">I tested a bit deeper and found out, that the attribute "explicit-exit-notify" in the openvpn client configuration seems to remove my issue with "no communication on reconnect".</p>
<p dir="auto">So then I guess this problem is fixed with 2.5.1 and explicit-exit-notify.</p>
<p dir="auto">Cheers</p>
]]></description><link>https://forum.netgate.com/post/978621</link><guid isPermaLink="true">https://forum.netgate.com/post/978621</guid><dc:creator><![CDATA[Airwave]]></dc:creator><pubDate>Mon, 19 Apr 2021 07:48:51 GMT</pubDate></item><item><title><![CDATA[Reply to Upgrade to 21.02 -&gt; Client Cert on LDAP server no Longer Accepted on Sun, 18 Apr 2021 19:46:15 GMT]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">anyone has an idea so far with that issue, workaround etc.?</p>
<p dir="auto">I updated to 2.5.1 AND now it works and a connection is established and traffic is been delivered, but ONLY ONCE after openvpn service start.<br />
When I then disconnect and reconnect, again I get a connection, but the communication / traffic (ping etc.) is not working. Only in the first connection traffic works. When I restart the openvpn service then, its again working once...</p>
<p dir="auto">Anyone could help, guide?</p>
<p dir="auto">Thanks in advance.</p>
<p dir="auto">Cheers</p>
]]></description><link>https://forum.netgate.com/post/978542</link><guid isPermaLink="true">https://forum.netgate.com/post/978542</guid><dc:creator><![CDATA[Airwave]]></dc:creator><pubDate>Sun, 18 Apr 2021 19:46:15 GMT</pubDate></item><item><title><![CDATA[Reply to Upgrade to 21.02 -&gt; Client Cert on LDAP server no Longer Accepted on Mon, 22 Feb 2021 00:06:07 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">same issue here after updating pfsense to 2.5.0-RELEASE from before 2.4.5-RELEASE-p1 but with Authentication Servers --&gt; Local Database.<br />
Found out, when you try the same connection and put in user admin credentials, it works perfectly.<br />
So maybe the certificates could not be the issue?</p>
<p dir="auto">Thanks</p>
]]></description><link>https://forum.netgate.com/post/966469</link><guid isPermaLink="true">https://forum.netgate.com/post/966469</guid><dc:creator><![CDATA[Airwave]]></dc:creator><pubDate>Mon, 22 Feb 2021 00:06:07 GMT</pubDate></item></channel></rss>