OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • OpenVPN CSO not write changes on filesystem - bug?
« previous next »
  • Print
Pages: [1]

Author Topic: OpenVPN CSO not write changes on filesystem - bug?  (Read 2853 times)

cbs1

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
OpenVPN CSO not write changes on filesystem - bug?
« on: November 20, 2018, 08:59:05 am »
Hello, we have got one problem:

Since about 1 month when we create a new OpenVPN CSO (client specific override) over the gui then nothing happens. After i research the problem i found out that on the file system (/var/etc/openvpn-csc/1) the entry doesn't will be write as a file. Therefore i change some of the existing entrys and even these entrys doesn't change on the filesystem. Is this a known bug or a configuration problem?

Version 18.7.7 in a VM

Thanks a lot.
Sascha
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6299
  • Karma: 434
    • View Profile
Re: OpenVPN CSO not write changes on filesystem - bug?
« Reply #1 on: November 20, 2018, 09:22:08 am »
It gets created when logging in. Can you verify this?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

cbs1

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: OpenVPN CSO not write changes on filesystem - bug?
« Reply #2 on: November 20, 2018, 12:42:30 pm »
Thanks for the fast reply, no the client get a ip address from the pool like there is no cso. But the old created cso works fine.

Greetings
Sascha
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6299
  • Karma: 434
    • View Profile
Re: OpenVPN CSO not write changes on filesystem - bug?
« Reply #3 on: November 20, 2018, 12:47:45 pm »
And the CSO is chained to the correct server instance?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

cbs1

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: OpenVPN CSO not write changes on filesystem - bug?
« Reply #4 on: November 20, 2018, 02:30:58 pm »
Yes - if I manually write a "cso" file to the correct folder for the instance, it works (but i dont see it in gui - was only for testing) - but even if remove an existing entry in the gui, the CSO file is not deleted and the client still gets the old cso.
Logged

fabio

  • Newbie
  • *
  • Posts: 46
  • Karma: 2
    • View Profile
Re: OpenVPN CSO not write changes on filesystem - bug?
« Reply #5 on: November 20, 2018, 03:09:10 pm »
Maybe try to flag the server option 'Force CSO Login Matching'
That use the login name instead the certificate CN to manage the CSO

--
Fabio
 
Logged

cbs1

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: OpenVPN CSO not write changes on filesystem - bug?
« Reply #6 on: November 20, 2018, 04:12:20 pm »
Thanks, i knew this option but we authorize by certificate CN not by login name
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6299
  • Karma: 434
    • View Profile
Re: OpenVPN CSO not write changes on filesystem - bug?
« Reply #7 on: November 20, 2018, 05:16:56 pm »
And you are using Remote Access at the server type?
You are sure your users are correctly logged out and try again?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

cbs1

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: OpenVPN CSO not write changes on filesystem - bug?
« Reply #8 on: November 21, 2018, 12:44:16 pm »
Yes we use remote access, the problem exists also when the whole opnsense is restarted.

The problem started about 1 - 2 month ago, before it worked with the same settings also when added new cso rules over 2 years. I think the problem has started after an update/upgrade but i'm not sure.

Thanks a lot
Sascha
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6299
  • Karma: 434
    • View Profile
Re: OpenVPN CSO not write changes on filesystem - bug?
« Reply #9 on: November 21, 2018, 01:06:05 pm »
Yep, the whole logic was reworked. Do you have some logs for me?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • OpenVPN CSO not write changes on filesystem - bug?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2