• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

OpenVPN without username/password

OpenVPN
6
12
40.9k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    setchi
    last edited by Jan 17, 2012, 9:00 PM

    Is it possible to use the user manager just to create/maintain certificates and keys.
    I want my OpenVPN to NOT ask for username and password during connection and just
    authenticate the user by the key and certificate.

    Is there a howto or guide to setup OpenVPN on pfSense 2.0.1 without passwords?

    Thanks,
    Florian

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Jan 24, 2012, 3:02 PM

      Sure, just setup the OpenVPN server type as "SSL/TLS" (no auth) and then add certificates in the Cert Manager, you can still export client installers that way. They are not tied to usernames, just certificates. You don't need to add users since they do not need usernames and passwords.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • N
        nexusN
        last edited by Jun 11, 2012, 5:51 AM

        @jimp:

        Sure, just setup the OpenVPN server type as "SSL/TLS" (no auth) and then add certificates in the Cert Manager, you can still export client installers that way. They are not tied to usernames, just certificates. You don't need to add users since they do not need usernames and passwords.

        I am doing this, SSL/TLS only without User Auth, for a portion of VPN users(anonymously for some forum friends) …..... but I do have a worry on the safety of the connection. :(
        The above is used because when someone is going to spread the credentials, it has no difference if I actually use User Auth or not.
        No User Auth seems to be more convenient for them in connecting. ;D

        Would the connection in this way less secure than having User Auth? ???

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Jun 11, 2012, 2:42 PM

          It depends on what you mean by "secure".

          The level of encryption would be the same, with or without user authentication.

          User authentication is an extra layer of prevention to keep out unauthorized access.

          So in terms of access control, not having user auth makes it less secure.
          But in terms of encryption, the security would be equivalent.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • N
            nexusN
            last edited by Jun 15, 2012, 6:42 AM

            @jimp:

            It depends on what you mean by "secure".

            The level of encryption would be the same, with or without user authentication.

            User authentication is an extra layer of prevention to keep out unauthorized access.

            So in terms of access control, not having user auth makes it less secure.
            But in terms of encryption, the security would be equivalent.

            Sorry for getting back to you late, my question has been well answered :D
            In that way I should keep my current practice of having no user auth :P for the encryption being the same level.

            1 Reply Last reply Reply Quote 0
            • J
              jimp Rebel Alliance Developer Netgate
              last edited by Jun 15, 2012, 11:36 AM

              All you need to do is change the mode of the VPN from SSL/TLS+User Auth to simply SSL/TLS - then no auth will be required, but the rest of the settings can stay the same.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • N
                nexusN
                last edited by Jun 20, 2012, 4:45 AM

                @jimp:

                All you need to do is change the mode of the VPN from SSL/TLS+User Auth to simply SSL/TLS - then no auth will be required, but the rest of the settings can stay the same.

                Yes, I did exactly the same and it works like a charm :D

                1 Reply Last reply Reply Quote 0
                • D
                  da_zhuang
                  last edited by Aug 2, 2012, 9:24 PM

                  Dear Jimp:

                  I'm very new to openvpn and I'm not sure how to change the mode of the VPN from SSL/TLS+User Auth to simply SSL/TLS? Do I just modify the config file or do I need to reinstall with some other options enabled? Thanks.

                  1 Reply Last reply Reply Quote 0
                  • M
                    marvosa
                    last edited by Aug 2, 2012, 11:11 PM Aug 2, 2012, 11:09 PM

                    da_zhuang,
                    Edit your OpenVPN server, on the Server tab in the General information section use the drop down menu to change the Server Mode option to Remote Access (SSL/TLS).

                    1 Reply Last reply Reply Quote 0
                    • H
                      hugolia
                      last edited by Apr 16, 2013, 2:49 PM

                      Is it possible to have User/password for some users but not for all?
                      I am using OpenVPN for RoadWarriors users (mostly notebooks). But now I need to setup a connection to a site where I will have a server with a daemon client to establish the VPN between sites.

                      1 Reply Last reply Reply Quote 0
                      • M
                        marvosa
                        last edited by Apr 16, 2013, 3:02 PM

                        hugolia,
                        Yes.  Just configure a 2nd server on a different port.

                        1 Reply Last reply Reply Quote 0
                        • J
                          jimp Rebel Alliance Developer Netgate
                          last edited by Apr 16, 2013, 3:03 PM

                          @hugolia:

                          Is it possible to have User/password for some users but not for all?
                          I am using OpenVPN for RoadWarriors users (mostly notebooks). But now I need to setup a connection to a site where I will have a server with a daemon client to establish the VPN between sites.

                          Yes, but they would need to use separate server instances. You can have one server that does user/pass, one that does not, and others for site-to-site VPNs.

                          Any more detail than that belongs in its own thread specific to your implementation, though, so if you need more help than that, feel free to start a fresh thread and ask.

                          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                          Need help fast? Netgate Global Support!

                          Do not Chat/PM for help!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.