Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
18.7 Legacy Series
»
OpenVPN CSO not write changes on filesystem - bug?
« previous
next »
Print
Pages: [
1
]
Author
Topic: OpenVPN CSO not write changes on filesystem - bug? (Read 4882 times)
cbs1
Newbie
Posts: 5
Karma: 0
OpenVPN CSO not write changes on filesystem - bug?
«
on:
November 20, 2018, 08:59:05 am »
Hello, we have got one problem:
Since about 1 month when we create a new OpenVPN CSO (client specific override) over the gui then nothing happens. After i research the problem i found out that on the file system (/var/etc/openvpn-csc/1) the entry doesn't will be write as a file. Therefore i change some of the existing entrys and even these entrys doesn't change on the filesystem. Is this a known bug or a configuration problem?
Version 18.7.7 in a VM
Thanks a lot.
Sascha
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: OpenVPN CSO not write changes on filesystem - bug?
«
Reply #1 on:
November 20, 2018, 09:22:08 am »
It gets created when logging in. Can you verify this?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
cbs1
Newbie
Posts: 5
Karma: 0
Re: OpenVPN CSO not write changes on filesystem - bug?
«
Reply #2 on:
November 20, 2018, 12:42:30 pm »
Thanks for the fast reply, no the client get a ip address from the pool like there is no cso. But the old created cso works fine.
Greetings
Sascha
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: OpenVPN CSO not write changes on filesystem - bug?
«
Reply #3 on:
November 20, 2018, 12:47:45 pm »
And the CSO is chained to the correct server instance?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
cbs1
Newbie
Posts: 5
Karma: 0
Re: OpenVPN CSO not write changes on filesystem - bug?
«
Reply #4 on:
November 20, 2018, 02:30:58 pm »
Yes - if I manually write a "cso" file to the correct folder for the instance, it works (but i dont see it in gui - was only for testing) - but even if remove an existing entry in the gui, the CSO file is not deleted and the client still gets the old cso.
Logged
fabio
Newbie
Posts: 46
Karma: 2
Re: OpenVPN CSO not write changes on filesystem - bug?
«
Reply #5 on:
November 20, 2018, 03:09:10 pm »
Maybe try to flag the server option 'Force CSO Login Matching'
That use the login name instead the certificate CN to manage the CSO
--
Fabio
Logged
cbs1
Newbie
Posts: 5
Karma: 0
Re: OpenVPN CSO not write changes on filesystem - bug?
«
Reply #6 on:
November 20, 2018, 04:12:20 pm »
Thanks, i knew this option but we authorize by certificate CN not by login name
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: OpenVPN CSO not write changes on filesystem - bug?
«
Reply #7 on:
November 20, 2018, 05:16:56 pm »
And you are using Remote Access at the server type?
You are sure your users are correctly logged out and try again?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
cbs1
Newbie
Posts: 5
Karma: 0
Re: OpenVPN CSO not write changes on filesystem - bug?
«
Reply #8 on:
November 21, 2018, 12:44:16 pm »
Yes we use remote access, the problem exists also when the whole opnsense is restarted.
The problem started about 1 - 2 month ago, before it worked with the same settings also when added new cso rules over 2 years. I think the problem has started after an update/upgrade but i'm not sure.
Thanks a lot
Sascha
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: OpenVPN CSO not write changes on filesystem - bug?
«
Reply #9 on:
November 21, 2018, 01:06:05 pm »
Yep, the whole logic was reworked. Do you have some logs for me?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
18.7 Legacy Series
»
OpenVPN CSO not write changes on filesystem - bug?