• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

openvpn-client-export -> Sent to email

Scheduled Pinned Locked Moved pfSense Packages
6 Posts 4 Posters 1.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Y
    yyovchev
    last edited by Jan 12, 2022, 4:35 PM

    Hello everyone. Great plugin is openvpn-client-export, but can you have a feature for sending via email the certificate/config directly from pfsense. Just have a some window for some text,subject and the certificate for attachment. Can use some SMTP settings etc.

    Best regards,

    G 1 Reply Last reply Jan 12, 2022, 10:54 PM Reply Quote 0
    • G
      Gertjan @yyovchev
      last edited by Jan 12, 2022, 10:54 PM

      @yyovchev
      That's what most people wind up doing, I guess.
      It's also the most don-t-do-that if security counts.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      1 Reply Last reply Reply Quote 0
      • B
        bingo600
        last edited by Jan 13, 2022, 5:29 PM

        I would NEVER send a client-export file , "unprotected" by e-mail.
        I usually ZIP Encrypt it with an ugly passwd , e-mail it , and send the pass via SMS or Teams or whatever OTHER transport method

        But ymmw ...

        /Bingo

        If you find my answer useful - Please give the post a 👍 - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

        1 Reply Last reply Reply Quote 0
        • Y
          yyovchev
          last edited by yyovchev Jan 13, 2022, 6:00 PM Jan 13, 2022, 5:59 PM

          Hello all. Thanks for yours reply.
          My VPN server use username/password authentication (connected to external authentication system via Radius ) + Certificates. So it's not a problem if somebody receive email with vpn config (including certs), because he don't know the username and password for authentication system and can't connect to the VPN server. In this case, the config files are useless and its not security issue.

          Best regards,

          B 1 Reply Last reply Jan 13, 2022, 9:04 PM Reply Quote 0
          • B
            bingo600 @yyovchev
            last edited by Jan 13, 2022, 9:04 PM

            @yyovchev
            If that's the way you look at your certificates , then i suppose you can just e-mail.

            I would pwesonally be more worried about an exposed cert , than a password.
            And any exposed cert of mine, would end on CRL immediately.
            But having read that a large CRL will not make pfSense GUI Cert performance "happy", i would like to keep the CRL short.

            But again ymmv

            If you find my answer useful - Please give the post a 👍 - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

            1 Reply Last reply Reply Quote 0
            • B
              bp81
              last edited by Jan 19, 2022, 7:01 PM

              The security issues here would be somewhat less of a problem if OpenVPN didn't store the client certificate's private key in plain text in the config file 🙄 🙄 🙄

              A possible modification to the OP's suggestion based on some responses here: an option to email the client config file as an encrypted, passworded zip file. After that it is on the VPN admin to ensure that the encrypted zip file's password is communicated by an alternative communications method.

              1 Reply Last reply Reply Quote 0
              1 out of 6
              • First post
                1/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received