Closed bgironx15 closed 5 months ago
Looks like your config file is not setup properly for dynamic challenge. OpenVPN is exiting on receiving the dynamic challenge query likely because you do not have auth-retry interact
in the config file. This is required for dynamic challenge to work.
Note that for instances started by the GUI it sets this option by default, but when started at boot as in PLAP, it has to be in the config file.
I normally use OpenVPN Connect v3 (OpenVPN3) so I don't need to add that line "auth-retry interact" on the Client Profile. That's the reason I didn't have that in my Client Profile when using OpenVPN GUI (OpenVPN2), but it looks like this is needed for Dynamic Challenge on OpenVPN2
I tested with the line "auth-retry interact" and worked
Thanks
The default in OpenVPN 2 is "auth-retry none" -- I've no idea why. We change that to "interact" when started by OpenVPN-GUI as its clearly an interactive session. For PLAP, I wanted to allow the user to decide how these pre-started sessions should behave.
Based on your report, now I feel it may be useful to automatically set auth-retry to interact when we attach from PLAP screen or at least when interactive authentication is in use.
It looks like the most (all?) issues users have with PLAP is due to (lack of) documentation. I just found this one but was wondering if we should put it in community wiki or some repo (openvpn-gui? openvpn-build?).
Let's close the ticket, but think what would be the best place to put documentation on PLAP feature. @flichtenheld
It is a openvpn-gui feature so the primary documentation ideally should be there. Then we could include it in the installer or link to it from the Wiki anyway.
Hello,
I'm testing the SBL/PLAP on OpenVPN GUI and this is working well so far
Now, I'm testing this with TOTP MFA and noticed that this works when using Static Challenge but doesn't work when using Dynamic Challenge
Some info
When using Static Challenge
When using Dynamic Challenge
From OpenVPN Access Server Logs when using Dynamic Challenge
From OpenVPN GUI Logs when using Dynamic Challenge