Latest openVPN (pfS 2.7) Clientexport Windows install package - Asks for Certificate paswd (none was set)
-
Hello
I have upgraded my test firewall to pfSense 2.7 , and was using Client Export to export the latest Windows installer.
After install i couldn't connect to the server (TLS + Passwd) , as after specifyint UID + PWD , I was asked for the Certificate password , and none was ever set ....Has anyone else experienced this "new feature" ???
This would totally stop me from upgrading my Central pfSense, as a functional VPN is 100% required.
Installing the previous "Install package" makes things work again.
/Bingo
-
It just occured to me, that i use a 2.7 "Client export Win installer" , in order to get my new pfSense (2.7) client installed on my Win test pc.
On that PC i also have older configs that points to my 2.6 pfSense.
It was when i tried to connect to the 2.6 pfSense i saw the issue.Could there be an issue, if i upgrade the openVPN client to a "2.7" client , and then try to connect to 2.6 server ??
/Bingo
-
Continuing my monolouge here
It seems like openSSL might have done some changes, that affects openVPN clients versioned 2.6.xx+
I think also something that affects certificate encryption.And i noticed a new settings field in the 2.7 openVPN Client export.
My steps to reproduce:
Have a Win PC with an openVPN Client export installer (latest from pfS 2.6) - Current Windows Installers (2.5.8-Ix04):
If you try to connect to the pfS 2.6 openVPN server , all is good.Then you get/receive a pfSense 2.7 Client export install file , and install it (to install the new conf+certs for that connection) - Current Windows Installers (2.6.5-Ix001):
Now if i try to connect to the "Old pfS 2.6" OVPN Server, I get asked for uid/pwd as usual.
But after entering that correct, i get another "gui prompt" , asking for the cert passwd.
Since i never used/generated a cert passwd, i can't login anymore.
Connecting to the 2.7 OVPN server, with the new client, does not ask for a cert passwd.
It might be an "Odd test" , but I think someone could have both 2.7 & 2.6 openVPN servers in prod.
Could Netgate confirm the above issue/situation ?
/Bingo