Project

General

Profile

Actions

Feature #10999

closed

Allow to register OpenVPN Remote Access (User Auth) client in DNS Resolver

Added by Viktor Gurov about 4 years ago. Updated about 4 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Viktor Gurov
Category:
OpenVPN
Target version:
Start date:
10/22/2020
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:

Description

Starting from 2.4.5 OpenVPN server supports "Username as Common Name" (#8289) option:

When a user authenticates, if this option is enabled then the username of the client will be used in place of the certificate common name for purposes such as determining Client Specific Overrides.

This option allows to use "Register connected OpenVPN clients in the DNS Resolver" feature for "Remote Access (User Auth)" mode


Files

Actions #2

Updated by Renato Botelho about 4 years ago

  • Status changed from New to Feedback
  • Assignee set to Viktor Gurov

PR has been merged. Thanks!

Actions #3

Updated by Viktor Gurov about 4 years ago

  • % Done changed from 0 to 100
Actions #5

Updated by Kris Phillips about 4 years ago

Tested this and it doesn't appear to work. We have a client who applied this patch to 2.4.5p1 and enabled both the Common Name and DNS Resolver settings, but it did not work. This firewall had the DNS Resolver in Forwarding Mode, but DHCP leases work fine. See attached screenshots.

Actions #6

Updated by Viktor Gurov about 4 years ago

  • Status changed from Feedback to Resolved

Kris Phillips wrote:

Tested this and it doesn't appear to work. We have a client who applied this patch to 2.4.5p1 and enabled both the Common Name and DNS Resolver settings, but it did not work. This firewall had the DNS Resolver in Forwarding Mode, but DHCP leases work fine. See attached screenshots.

You need to restart/re-save OpenVPN server after enabling 'Register connected OpenVPN clients in the DNS Resolver' in DNS Resolver

tested on 2.5.0.a.20201023.1850 - works as expected

Actions

Also available in: Atom PDF