OpenVPN + LDAP auth + groups …. how is this meant to work ?
-
Hi,
I am using pfSense 2.0.1 and I have LDAP authentication working via "System/User Manager/Servers" option and specifying the appropriate credentials. The problem is it lets all users of our AD into the vpn and I would like to allow only members of a specific group.
I have tried to debug the auth.inc php code to see whats going on, and I can see all the groups being extracted for the user that's trying to log on correctly, but the only group it's trying to match against seems to be a group defined by pfsense called "all" with a GID of 1998 (the All Users group and hence why all users can access the vpn).
There doesn't seem to be any means to specify another group into the list without hacking the code.
Am I missing something here or is the "System: Authentication Servers" only meant to authenticate to users with no option to specifiy other groups ?
Thanks,
Andrew -
Group support isn't all there yet. There are some patches out there, but it's still considered an open feature:
http://redmine.pfsense.org/issues/1009