2fa radius challenge

This forum is for admins who are looking to build or expand their OpenVPN setup.

Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech

Forum rules
Please use the [oconf] BB tag for openvpn Configurations. See viewtopic.php?f=30&t=21589 for an example.
Post Reply
bergerf
OpenVpn Newbie
Posts: 1
Joined: Fri Nov 10, 2023 7:38 am

2fa radius challenge

Post by bergerf » Fri Nov 10, 2023 7:46 am

Hi!

I need some help for the radius/challenge setup.

My OpenVPN server is using radius for authentication. works fine.
The radius is now using an additional 2fa solution (PrivacyIDEA).

This is also working, for user without 2FA token or if the token is appended to the password.
This also works if the client is configured with "static-challenge" (<- but this works only for users with token...)

What I want is that the server is replying to the radius-challenge, which came if the user is having a token but is sending only the password.
So the 2nd Access-Request from OpenVPN should just contain the "state" attribute from the Challenge message.

I'm unable to bring this setup up, any hints?

Post Reply