Serious login failure, security issue
Posted: Tue Sep 10, 2019 1:02 pm
I just discovered a weird login behavior by accident while setting up an OPNsense box. At first I thought this was an OPNsense issue but the same happens on a OpenBSD box which is in production since a while.
Issue found has also been reported on the OPNsense forum: https://forum.opnsense.org/index.php?topic=14152.0.
The issue is that I discovered that while using a user specific some_user.ovpn configuration (User A) to get VPN access, one is allowed to use the credentials of another user (User B).
Obviously this is not something I would expect. The user A config file does contain the personal cert and private key, so one would expect that only this user would be allowed to logon while using his own credentials.
I do consider this behavior as a security issue.
Any suggestions?
Issue found has also been reported on the OPNsense forum: https://forum.opnsense.org/index.php?topic=14152.0.
The issue is that I discovered that while using a user specific some_user.ovpn configuration (User A) to get VPN access, one is allowed to use the credentials of another user (User B).
Obviously this is not something I would expect. The user A config file does contain the personal cert and private key, so one would expect that only this user would be allowed to logon while using his own credentials.
I do consider this behavior as a security issue.
Any suggestions?