| Message ID | 20200313130133.19045-1-samuli@openvpn.net |
|---|---|
| State | Changes Requested |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director11.mail.ord1d.rsapps.net ([172.30.191.6]) by backend30.mail.ord1d.rsapps.net with LMTP id aHteDoWEa15JGgAAIUCqbw for <patchwork@openvpn.net>; Fri, 13 Mar 2020 09:03:01 -0400 Received: from proxy18.mail.ord1d.rsapps.net ([172.30.191.6]) by director11.mail.ord1d.rsapps.net with LMTP id 4PBcDoWEa16uJgAAvGGmqA ; Fri, 13 Mar 2020 09:03:01 -0400 Received: from smtp1.gate.ord1c ([172.30.191.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy18.mail.ord1d.rsapps.net with LMTP id wIn4DYWEa15DJgAATCaURg ; Fri, 13 Mar 2020 09:03:01 -0400 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp1.gate.ord1c.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dkim=fail (signature verification failed) header.d=openvpn.net; dmarc=fail (p=none; dis=none) header.from=openvpn.net X-Suspicious-Flag: YES X-Classification-ID: f727d76a-652a-11ea-9bd8-842b2b47c027-1-1 Received: from [216.105.38.7] ([216.105.38.7:37202] helo=lists.sourceforge.net) by smtp1.gate.ord1c.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id 41/7F-22080-4848B6E5; Fri, 13 Mar 2020 09:03:00 -0400 Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.90_1) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1jCjwn-0000fa-1S; Fri, 13 Mar 2020 13:01:53 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) (envelope-from <samuli@openvpn.net>) id 1jCjwm-0000fI-3k for openvpn-devel@lists.sourceforge.net; Fri, 13 Mar 2020 13:01:52 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:Content-Type:MIME-Version :Message-Id:Date:Subject:Cc:To:From:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=KhyrI1JpMkcNAz/8z/bOaoJV3CCvzvBGS7jarmBVsOE=; b=DTgjZXNQlWvNqNbxsvIkLPNIyY Oy11X3UGv0EEi+pPG61T0fCXr+6mlHhUqv3a4zfhSXZhZTSvMfnwKb0r58Y8Z7eUUdwYbg6rD5HWn h/WnpFf5MyNN1UpF9OcyNWT0U0YVbHbbxG1crj+Eg/WmJPnjlyj/m6chEc0RZNNfEM3w=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:Content-Type:MIME-Version:Message-Id:Date: Subject:Cc:To:From:Sender:Reply-To:Content-ID:Content-Description:Resent-Date :Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=KhyrI1JpMkcNAz/8z/bOaoJV3CCvzvBGS7jarmBVsOE=; b=W RMLqno8eyWe85ckTROD+ePzt/4lLfAd+t6MecpmtpgvGlQSTura7OuCe+33cmZHNTyZ8c61qYJpd/ +EbQ/4buSSiGKimezzoOQfhorp6nYBAfEHiZgEeYjFxd9gxm5kQghGeURXrVLxfxaDaMCW3bY90Wn pr8DIaZ0IGzZtUIw=; Received: from smtp103.iad3b.emailsrvr.com ([146.20.161.103]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92.2) id 1jCjwe-000DCo-2O for openvpn-devel@lists.sourceforge.net; Fri, 13 Mar 2020 13:01:52 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=openvpn.net; s=20170822-45nk5nwl; t=1584104491; bh=xIx0ddrYMbG32aXCCKvXkYH6iNJZ2Al0xgc8de0eq/4=; h=From:To:Subject:Date:From; b=u7aDGwCh7Mx1YqFzdZwmdaCIRieJLLZBDTxKKxOxsvwx9CyWk+XAifubqJnvofr64 m7DqIgvY5GqVtO+n8ou6z4TpVJERgItT2qMwh1lHx0Zfr6ldZdUbJQNU4J8HnwOmF6 rCteBCkfpXTNcvP5i7Sw6gCtZl/y2uTWadQeh5Xc= X-Auth-ID: samuli@openvpn.net Received: by smtp21.relay.iad3b.emailsrvr.com (Authenticated sender: samuli-AT-openvpn.net) with ESMTPSA id 2C0D62013D; Fri, 13 Mar 2020 09:01:31 -0400 (EDT) X-Sender-Id: samuli@openvpn.net Received: from carbon.qantar.net (85-156-26-239.elisa-laajakaista.fi [85.156.26.239]) (using TLSv1.2 with cipher AES256-GCM-SHA384) by 0.0.0.0:465 (trex/5.7.12); Fri, 13 Mar 2020 09:01:31 -0400 From: samuli@openvpn.net To: openvpn-devel@lists.sourceforge.net Date: Fri, 13 Mar 2020 15:01:33 +0200 Message-Id: <20200313130133.19045-1-samuli@openvpn.net> X-Mailer: git-send-email 2.21.1 MIME-Version: 1.0 X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: openvpn.net] -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [146.20.161.103 listed in list.dnswl.org] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.1 AWL AWL: Adjusted score from AWL reputation of From: address X-Headers-End: 1jCjwe-000DCo-2O Subject: [Openvpn-devel] [PATCH] Document some limitations of --auth-user-pass X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
[Openvpn-devel] Document some limitations of --auth-user-pass
|
|
Commit Message
Samuli Seppänen
March 13, 2020, 2:01 a.m. UTC
From: Samuli Seppänen <samuli@openvpn.net> URL: https://community.openvpn.net/openvpn/ticket/757 Signed-off-by: Samuli Seppänen <samuli@openvpn.net> --- doc/openvpn.8 | 6 ++++++ 1 file changed, 6 insertions(+)
Comments
On 13/03/2020 14:01, samuli@openvpn.net wrote: > From: Samuli Seppänen <samuli@openvpn.net> > > URL: https://community.openvpn.net/openvpn/ticket/757 > Signed-off-by: Samuli Seppänen <samuli@openvpn.net> > --- > doc/openvpn.8 | 6 ++++++ > 1 file changed, 6 insertions(+) > > diff --git a/doc/openvpn.8 b/doc/openvpn.8 > index 864f94e8..9e54890e 100644 > --- a/doc/openvpn.8 > +++ b/doc/openvpn.8 > @@ -4127,6 +4127,12 @@ The server configuration must specify an > .B \-\-auth\-user\-pass\-verify > script to verify the username/password provided by > the client. > + > +Note that OpenVPN GUI on Windows does not prompt for the > +password if the file contains only the username. However, > +OpenVPN versions from 2.4 up bundle OpenVPN GUI version 11 > +which is able to cache usernames and passwords internally. > + Could we rephrase this, to not live in the past. This will go into master and probably also release/2.4. I also doubt anyone using man pages on 2.3 would even read this. If there are Windows users on 2.3, there are no excuse not to upgrade - unless it's an enterprise deployment, where end users most likely would not even care (they should anyway complain to their IT department regardless, for using outdated security software). I would just rephrase it to say: OpenVPN GUI v11 and newer uses its own internal username/password storage independent of the --auth-user-pass file provided. The file argument is ignored on such installations. (or something like that)
Hi, On Mon, Mar 16, 2020 at 8:39 AM David Sommerseth <openvpn@sf.lists.topphemmelig.net> wrote: > > On 13/03/2020 14:01, samuli@openvpn.net wrote: > > From: Samuli Seppänen <samuli@openvpn.net> > > > > URL: https://community.openvpn.net/openvpn/ticket/757 > > Signed-off-by: Samuli Seppänen <samuli@openvpn.net> > > --- > > doc/openvpn.8 | 6 ++++++ > > 1 file changed, 6 insertions(+) > > > > diff --git a/doc/openvpn.8 b/doc/openvpn.8 > > index 864f94e8..9e54890e 100644 > > --- a/doc/openvpn.8 > > +++ b/doc/openvpn.8 > > @@ -4127,6 +4127,12 @@ The server configuration must specify an > > .B \-\-auth\-user\-pass\-verify > > script to verify the username/password provided by > > the client. > > + > > +Note that OpenVPN GUI on Windows does not prompt for the > > +password if the file contains only the username. However, > > +OpenVPN versions from 2.4 up bundle OpenVPN GUI version 11 > > +which is able to cache usernames and passwords internally. > > + > > Could we rephrase this, to not live in the past. This will go into master and > probably also release/2.4. I also doubt anyone using man pages on 2.3 would > even read this. If there are Windows users on 2.3, there are no excuse not to > upgrade - unless it's an enterprise deployment, where end users most likely > would not even care (they should anyway complain to their IT department > regardless, for using outdated security software). > > I would just rephrase it to say: > > OpenVPN GUI v11 and newer uses its own internal username/password storage > independent of the --auth-user-pass file provided. The file argument is > ignored on such installations. I wish it behaved like that. Unfortunately the file argument is not ignored in such cases. If the file has only username, openvpn.exe reads it from the file and then fails to prompt for password as there is no console available. I propose to change this behaviour to: if --management-query-passwords is set (which the GUI does), ignore the file given in auth-user-pass and prompt both username and password from management. I think its only logical for a later option (in this case the one set by the GUI) to override a previous one. Anyway we do already ignore it if the file is "stdin". Selva
On 16/03/2020 14:48, Selva Nair wrote: [...snip...] >> I would just rephrase it to say: >> >> OpenVPN GUI v11 and newer uses its own internal username/password storage >> independent of the --auth-user-pass file provided. The file argument is >> ignored on such installations. > > I wish it behaved like that. Unfortunately the file argument is not > ignored in such cases. If the file has only username, openvpn.exe > reads it from the file and then fails to prompt for password as there > is no console available. Ouch ... that is a pointless misbehavior. Lets try to fix that. > I propose to change this behaviour to: if --management-query-passwords > is set (which the GUI does), ignore the file given in auth-user-pass > and prompt both username and password from management. I think its > only logical for a later option (in this case the one set by the GUI) > to override a previous one. Anyway we do already ignore it if the file > is "stdin". Agreed!
Hi, On Tue, Mar 17, 2020 at 11:06:53AM +0100, David Sommerseth wrote: > On 16/03/2020 14:48, Selva Nair wrote: > [...snip...] > >> I would just rephrase it to say: > >> > >> OpenVPN GUI v11 and newer uses its own internal username/password storage > >> independent of the --auth-user-pass file provided. The file argument is > >> ignored on such installations. > > > > I wish it behaved like that. Unfortunately the file argument is not > > ignored in such cases. If the file has only username, openvpn.exe > > reads it from the file and then fails to prompt for password as there > > is no console available. > > Ouch ... that is a pointless misbehavior. Lets try to fix that. Have you recovered from your latest adventures in "password query code in OpenVPN" already? :-) Not sure if the management commands permit the "we have a username but no password" flow today... Arne, Selva? But yes, this needs to be either a clear error, or "work correctly" > > I propose to change this behaviour to: if --management-query-passwords > > is set (which the GUI does), ignore the file given in auth-user-pass > > and prompt both username and password from management. I think its > > only logical for a later option (in this case the one set by the GUI) > > to override a previous one. Anyway we do already ignore it if the file > > is "stdin". > > Agreed! No, as this will break working configs *if* both username + password are in the file (did we ever merge the "inline auth-user-pass" patch?). gert
Hi, On Tue, Mar 17, 2020 at 6:25 AM Gert Doering <gert@greenie.muc.de> wrote: > > Hi, > > On Tue, Mar 17, 2020 at 11:06:53AM +0100, David Sommerseth wrote: > > On 16/03/2020 14:48, Selva Nair wrote: > > [...snip...] > > >> I would just rephrase it to say: > > >> > > >> OpenVPN GUI v11 and newer uses its own internal username/password storage > > >> independent of the --auth-user-pass file provided. The file argument is > > >> ignored on such installations. > > > > > > I wish it behaved like that. Unfortunately the file argument is not > > > ignored in such cases. If the file has only username, openvpn.exe > > > reads it from the file and then fails to prompt for password as there > > > is no console available. > > > > Ouch ... that is a pointless misbehavior. Lets try to fix that. > > Have you recovered from your latest adventures in "password query code > in OpenVPN" already? :-) > > Not sure if the management commands permit the "we have a username but > no password" flow today... Arne, Selva? > > But yes, this needs to be either a clear error, or "work correctly" > > > > I propose to change this behaviour to: if --management-query-passwords > > > is set (which the GUI does), ignore the file given in auth-user-pass > > > and prompt both username and password from management. I think its > > > only logical for a later option (in this case the one set by the GUI) > > > to override a previous one. Anyway we do already ignore it if the file > > > is "stdin". > > > > Agreed! > > No, as this will break working configs *if* both username + password > are in the file (did we ever merge the "inline auth-user-pass" patch?). See the patch in mail for what looks like an acceptable solution to me. Selva
Hi, On Fri, Mar 13, 2020 at 03:01:33PM +0200, samuli@openvpn.net wrote: > From: Samuli Seppänen <samuli@openvpn.net> > > URL: https://community.openvpn.net/openvpn/ticket/757 > Signed-off-by: Samuli Seppänen <samuli@openvpn.net> > --- I'm going to mark that patch in patchwork as "changes requested", given that Selva changed the issue towards "if this happens, we'll just ignore the stored username and ask management for both user+password". Not sure if we still need a documentation patch, but if we want one, it will have to be different text :) gert
diff --git a/doc/openvpn.8 b/doc/openvpn.8 index 864f94e8..9e54890e 100644 --- a/doc/openvpn.8 +++ b/doc/openvpn.8 @@ -4127,6 +4127,12 @@ The server configuration must specify an .B \-\-auth\-user\-pass\-verify script to verify the username/password provided by the client. + +Note that OpenVPN GUI on Windows does not prompt for the +password if the file contains only the username. However, +OpenVPN versions from 2.4 up bundle OpenVPN GUI version 11 +which is able to cache usernames and passwords internally. + .\"********************************************************* .TP .B \-\-auth\-retry type