OpenVPN LDAPS Bind Bug
-
I think this is a bug, but I want to see if it is repeatable by others before I report it.
If you configure pfSense 's OpenVPN to use LDAP authentication with LDAPS (not StartTLS), pfSense's LDAPS connection tries to login an anonymous bind even when an authenticated bind user is defined in the LDAP configuration and 'Allow unauthenticated bind' is unchecked.
The WebConfigurator users will be able to log in correctly with the same profile. OpenVPN users will not be able to log in and get an AUTH_FAILED response from OpenVPN because the user verification bind attempt failed.
My LDAP server does not allow anonymous binds as that is best practice nowadays.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.