PageSourceSearch

https://q01-platform.github.io/assets/js/4a3b08c6.f7ae6373.js

js q01-platform.github.io collected 2026-10-03 09:50:08 UTC 4,717 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkq_01_docs=self.webpackChunkq_01_docs||[]).push([[9112],{4496:(e,n,s)=>{s.r(n),s.d(n,{assets:()=>o,contentTitle:()=>c,default:()=>h,frontMatter:()=>i,metadata:()=>a,toc:()=>l});var r=s(7624),t=s(2172);const i={id:"infrastructure-vpn",title:"Adding OpenVPN Remote Access Users",sidebar_label:"Cluster security",sidebar_position:2},c=void 0,a={id:"Infrastructure/infrastructure-vpn",title:"Adding OpenVPN Remote Access Users",description:"Adding users to the VPN using Local Database as OpenVPN server authentication method and backend",source:"@site/docs/Infrastructure/vpn.md",sourceDirName:"Infrastructure",slug:"/Infrastructure/infrastructure-vpn",permalink:"/docs/Infrastructure/infrastructure-vpn",draft:!1,unlisted:!1,tags:[],version:"current",sidebarPosition:2,frontMatter:{id:"infrastructure-vpn",title:"Adding OpenVPN Remote Access Users",sidebar_label:"Cluster security",sidebar_position:2},sidebar:"infrastructureSidebar",previous:{title:"Infrastructure overview",permalink:"/docs/Infrastructure/"}},o={},l=[];function d(e){const n={a:"a",code:"code",em:"em",li:"li",p:"p",strong:"strong",ul:"ul",...(0,t.M)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(n.p,{children:"Adding users to the VPN using Local Database as OpenVPN server authentication method and backend\nSee also"}),"\n",(0,r.jsx)(n.p,{children:"OpenVPN authenticates local database users based on their entries in the user manager."}),"\n",(0,r.jsx)(n.p,{children:"To create a new user with a certificate, follow these steps:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Navigate to ",(0,r.jsx)(n.strong,{children:"System > User Manager"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:"Click ![fa-plus] To add a user"}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:"Fill in the settings as follows:"}),"\n",(0,r.jsx)(n.p,{children:"Username"}),"\n",(0,r.jsx)(n.p,{children:"The username for this client."}),"\n",(0,r.jsx)(n.p,{children:"Password/Confirm password"}),"\n",(0,r.jsx)(n.p,{children:"The password for this client."}),"\n",(0,r.jsx)(n.p,{children:"Full Name"}),"\n",(0,r.jsx)(n.p,{children:"An optional longer name for this user."}),"\n",(0,r.jsx)(n.p,{children:"Click to create a user certificate"}),"\n",(0,r.jsx)(n.p,{children:(0,r.jsx)(n.em,{children:"Checked"})}),"\n",(0,r.jsx)(n.p,{children:"Descriptive Name"}),"\n",(0,r.jsxs)(n.p,{children:["Same value as the ",(0,r.jsx)(n.strong,{children:"Username"})]}),"\n",(0,r.jsx)(n.p,{children:"Certificate Authority"}),"\n",(0,r.jsx)(n.p,{children:"The CA used by the OpenVPN server."}),"\n",(0,r.jsx)(n.p,{children:"Key Type"}),"\n",(0,r.jsxs)(n.p,{children:["The type of private key to use for this certificate, either ",(0,r.jsx)(n.em,{children:"RSA"})," or ",(0,r.jsx)(n.em,{children:"ECDSA"})," and its accompanying ",(0,r.jsx)(n.strong,{children:"Key Length"})," (RSA) or ",(0,r.jsx)(n.strong,{children:"Curve"})," (ECDSA). The default is an acceptable choice."]}),"\n",(0,r.jsx)(n.p,{children:"Lifetime"}),"\n",(0,r.jsxs)(n.p,{children:["The number of days for which the certificate is valid. The default of ",(0,r.jsx)(n.code,{children:"3650"})," (approximately 10 years) is acceptable for a user certificate."]}),"\n",(0,r.jsx)(n.p,{children:"![../_images/openvpn_ra-usercert.png]"}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Click ",(0,r.jsx)(n.strong,{children:"Save"})]}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.p,{children:"To view or change the user:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsxs)(n.p,{children:["Navigate to ",(0,r.jsx)(n.strong,{children:"System > User Manager"})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:"Click ![fa-pencil] next to the row containing the user to see/edit"}),"\n"]}),"\n"]}),"\n",(0,r.jsx)(n.p,{children:"To export a user certificate and key:"}),"\n",(0,r.jsx)(n.p,{children:(0,r.jsx)(n.a,{href:"https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-ra-users.html",children:"https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-ra-users.html"})})]})}function h(e={}){const{wrapper:n}={...(0,t.M)(),...e.components};return n?(0,r.jsx)(n,{...e,children:(0,r.jsx)(d,{...e})}):d(e)}},2172:(e,n,s)=>{s.d(n,{I:()=>a,M:()=>c});var r=s(1504);const t={},i=r.createContext(t);function c(e){const n=r.useContext(i);return r.useMemo((function(){return"function"==typeof e?e(n):{...n,...e}}),[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:c(e.components),r.createElement(i.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.