OPNsense Forum

English Forums => Virtual private networks => Topic started by: mmmmm on September 04, 2026, 11:57:49 AM

Title: OpenVPN server with Enforce local group
Post by: mmmmm on September 04, 2026, 11:57:49 AM
Hello,
I want to setup OpenVPN server instance with client certificates auth and limit who can use it by Enforcing local groups. I do not want any passwords for the authentification.
I noticed that when I don't configure anything in "Authentication", the local group membership is not enforced (I do have "Strict User/CN matching" enabled). When I enable Local database for Authentication, it asks for password, but my local users don't have any.

What is the correct way to configure this? e.g. Auth by certificates + group membership? I have 1 OpenVPN server instance for IT and one for generic users with different VLAN access. Or is the only way to use some random passwords and save them into the ovpn client files?