diff --git a/security/openvpn-client-export/Makefile b/security/openvpn-client-export/Makefile index 307161ebbada..02cac2e75e16 100644 --- a/security/openvpn-client-export/Makefile +++ b/security/openvpn-client-export/Makefile @@ -1,16 +1,15 @@ -# $FreeBSD$ - PORTNAME= openvpn-client-export -PORTVERSION= 2.5.8 +PORTVERSION= 2.6.5 CATEGORIES= security MASTER_SITES= https://files.netgate.com/packages/openvpn-client-export/ MAINTAINER= jimp@netgate.com COMMENT= OpenVPN Client Export +WWW= https://docs.netgate.com/pfsense/en/latest/packages/openvpn-client-export.html LICENSE= APACHE20 -RUN_DEPENDS= openvpn>=2.5.0:security/openvpn +RUN_DEPENDS= openvpn>=2.6.0:security/openvpn USES= tar:tgz diff --git a/security/openvpn-client-export/distinfo b/security/openvpn-client-export/distinfo index df21f0d63f3e..92e866d9d596 100644 --- a/security/openvpn-client-export/distinfo +++ b/security/openvpn-client-export/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1673897306 -SHA256 (openvpn-client-export-2.5.8.tgz) = 26376925d491049ba9e86b0f2af5a345266b7d4f361a97a5a0ff7c0d0a0f06ad -SIZE (openvpn-client-export-2.5.8.tgz) = 16630366 +TIMESTAMP = 1688753407 +SHA256 (openvpn-client-export-2.6.5.tgz) = f1a4b2d187df570cea879a3cdfab1dcde1f1673e9b33ab5b0c2b97c98f4b8645 +SIZE (openvpn-client-export-2.6.5.tgz) = 24167301 diff --git a/security/openvpn-client-export/pkg-descr b/security/openvpn-client-export/pkg-descr index 401f8adc3ff1..fe88d1757737 100644 --- a/security/openvpn-client-export/pkg-descr +++ b/security/openvpn-client-export/pkg-descr @@ -1,4 +1,2 @@ -Allows a pre-configured OpenVPN Windows Client or Mac OSX's Viscosity -configuration bundle to be exported directly from pfSense. - -WWW: https://docs.netgate.com/pfsense/en/latest/packages/openvpn-client-export.html +Windows client binary files for exporting pre-configured OpenVPN Client +configurations directly from pfSense software. diff --git a/security/openvpn-client-export/pkg-plist b/security/openvpn-client-export/pkg-plist index 66a02ffd43d3..dcc3de9559d1 100644 --- a/security/openvpn-client-export/pkg-plist +++ b/security/openvpn-client-export/pkg-plist @@ -1,8 +1,10 @@ share/openvpn/client-export/template/7zsd_All.sfx share/openvpn/client-export/template/config-import share/openvpn/client-export/template/config-standard -share/openvpn/client-export/template/OpenVPN-2.5.8-I604-amd64.msi -share/openvpn/client-export/template/OpenVPN-2.5.8-I604-x86.msi +share/openvpn/client-export/template/OpenVPN-2.5.9-I601-amd64.msi +share/openvpn/client-export/template/OpenVPN-2.5.9-I601-x86.msi +share/openvpn/client-export/template/OpenVPN-2.6.5-I001-amd64.msi +share/openvpn/client-export/template/OpenVPN-2.6.5-I001-x86.msi share/openvpn/client-export/template/openvpn-install-2.4.12-I601-Win10.exe share/openvpn/client-export/template/openvpn-install-2.4.12-I601-Win7.exe share/openvpn/client-export/template/openvpn-postinstall.exe diff --git a/security/pfSense-pkg-openvpn-client-export/Makefile b/security/pfSense-pkg-openvpn-client-export/Makefile index 63b2cfe0fcf2..39f3d7f2ca17 100644 --- a/security/pfSense-pkg-openvpn-client-export/Makefile +++ b/security/pfSense-pkg-openvpn-client-export/Makefile @@ -1,7 +1,5 @@ -# $FreeBSD$ - PORTNAME= pfSense-pkg-openvpn-client-export -PORTVERSION= 1.8 +PORTVERSION= 1.9 CATEGORIES= security MASTER_SITES= # empty DISTFILES= # empty @@ -9,11 +7,12 @@ EXTRACT_ONLY= # empty MAINTAINER= coreteam@pfsense.org COMMENT= pfSense package openvpn-client-export +WWW= https://docs.netgate.com/pfsense/en/latest/packages/openvpn-client-export.html LICENSE= APACHE20 -RUN_DEPENDS= openvpn>=2.5.2:security/openvpn \ - openvpn-client-export>=2.5.8:security/openvpn-client-export \ +RUN_DEPENDS= openvpn>=2.6.0:security/openvpn \ + openvpn-client-export>=2.6.0:security/openvpn-client-export \ zip>0:archivers/zip \ 7-zip>0:archivers/7-zip diff --git a/security/pfSense-pkg-openvpn-client-export/files/usr/local/pkg/openvpn-client-export.inc b/security/pfSense-pkg-openvpn-client-export/files/usr/local/pkg/openvpn-client-export.inc index 9f5f5e70ad7d..eeffef0632ce 100644 --- a/security/pfSense-pkg-openvpn-client-export/files/usr/local/pkg/openvpn-client-export.inc +++ b/security/pfSense-pkg-openvpn-client-export/files/usr/local/pkg/openvpn-client-export.inc @@ -27,11 +27,17 @@ require_once("shaper.inc"); require_once("util.inc"); require_once("pfsense-utils.inc"); -global $current_openvpn_version, $current_openvpn_version_rev, $legacy_openvpn_version, $legacy_openvpn_version_rev; -$current_openvpn_version = "2.5.8"; -$current_openvpn_version_rev = "04"; +global $current_openvpn_version, $current_openvpn_version_rev; +$current_openvpn_version = "2.6.5"; +$current_openvpn_version_rev = "001"; + +global $previous_openvpn_version, $previous_openvpn_version_rev; +$previous_openvpn_version = "2.5.9"; +$previous_openvpn_version_rev = "601"; + +global $legacy_openvpn_version, $legacy_openvpn_version_rev; $legacy_openvpn_version = "2.4.12"; -$legacy_openvpn_version_rev = "01"; +$legacy_openvpn_version_rev = "601"; /* Ciphers not supported by legacy clients */ $legacy_incompatible_ciphers = array("CHACHA20-POLY1305"); @@ -64,26 +70,66 @@ function openvpn_client_export_prefix($srvid, $usrid = null, $crtid = null) { $filename_addition = ""; if (isset($usrid) && is_numeric($usrid)) { $filename_addition = "-" . $config['system']['user'][$usrid]['name']; - } elseif (isset($crtid) && is_numeric($crtid) && function_exists("cert_get_cn")) { + } elseif (isset($crtid) && is_numeric($crtid)) { $filename_addition = "-" . str_replace(' ', '_', cert_get_cn($config['cert'][$crtid]['crt'])); } return "{$host}-{$prot}-{$port}{$filename_addition}"; } -function openvpn_client_pem_to_pk12($outpath, $outpass, $crtpath, $keypath, $capath = false) { +function openvpn_client_pem_to_pk12($outpath, $outpass, $p12encryption, $crtpath, $keypath, $descr = "", $capath = false) { $eoutpath = escapeshellarg($outpath); $eoutpass = escapeshellarg($outpass); $ecrtpath = escapeshellarg($crtpath); + if ($keypath) { $key = '-inkey ' . escapeshellarg($keypath); } else { $key = '-nokeys'; } + + /* Encryption and Digest */ + switch ($p12encryption) { + case 'legacy': + $algo = '-certpbe PBE-SHA1-RC2-40 -keypbe PBE-SHA1-RC2-40'; + $hash = ''; + break; + case 'low': + $algo = '-certpbe PBE-SHA1-3DES -keypbe PBE-SHA1-3DES'; + $hash = '-macalg SHA1'; + break; + case 'high': + default: + $algo = '-aes256 -certpbe AES-256-CBC -keypbe AES-256-CBC'; + $hash = '-macalg sha256'; + } + + $tempdir = $g['tmp_path'] . "/openvpn-export-p12-".uniqid(); + mkdir($tempdir, 0700, true); + + /* Set the friendly name if available */ + $edescr = ""; + if (!empty($descr)) { + $edescr = escapeshellarg($descr); + $edescr = "-name {$edescr} -CSP {$edescr}"; + } + + /* Passphrase handling */ + if (!empty($outpass)) { + /* Use passphrase text file so the passphrase is not visible in + * process list. */ + $passfile = "{$tempdir}/passphrase.txt"; + file_put_contents($passfile, $outpass . "\n"); + $pass = '-passout file:' . escapeshellarg($passfile); + } else { + /* Null password + disable encryption of the keys */ + $pass = '-passout pass: -nodes'; + } + if ($capath) { $ecapath = escapeshellarg($capath); - exec("/usr/bin/openssl pkcs12 -export -in {$ecrtpath} {$key} -certfile {$ecapath} -out {$eoutpath} -passout pass:{$eoutpass}"); + exec("/usr/bin/openssl pkcs12 -export -in {$ecrtpath} {$key} -certfile {$ecapath} -out {$eoutpath} {$pass} {$edescr} {$algo} {$hash}"); } else { - exec("/usr/bin/openssl pkcs12 -export -in {$ecrtpath} {$key} -out {$eoutpath} -passout pass:{$eoutpass}"); + exec("/usr/bin/openssl pkcs12 -export -in {$ecrtpath} {$key} -out {$eoutpath} {$pass} {$edescr} {$algo} {$hash}"); } unlink($crtpath); @@ -91,6 +137,7 @@ function openvpn_client_pem_to_pk12($outpath, $outpass, $crtpath, $keypath, $cap if ($capath) { unlink($capath); } + @rmdir_recursive($tempdir); } function openvpn_client_export_validate_config($srvid, $usrid, $crtid) { @@ -116,9 +163,7 @@ function openvpn_client_export_validate_config($srvid, $usrid, $crtid) { if (!$server_ca) { $input_errors[] = "Could not locate the CA reference for the server certificate."; } - if (function_exists("cert_get_cn")) { - $servercn = cert_get_cn($server_cert['crt']); - } + $servercn = cert_get_cn($server_cert['crt']); } // lookup user info @@ -159,7 +204,7 @@ function openvpn_client_export_validate_config($srvid, $usrid, $crtid) { return array($settings, $server_cert, $server_ca, $servercn, $user, $cert, $nokeys); } -function openvpn_client_export_config($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $nokeys = false, $proxy, $expformat = "baseconf", $outpass = "", $skiptls = false, $doslines = false, $advancedoptions = "", $usepkcs11, $pkcs11providers, $pkcs11id) { +function openvpn_client_export_config($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $nokeys = false, $proxy, $expformat = "baseconf", $outpass = "", $p12encryption, $skiptls = false, $doslines = false, $advancedoptions = "", $usepkcs11, $pkcs11providers, $pkcs11id) { global $input_errors, $g, $legacy_incompatible_ciphers; $validconfig = openvpn_client_export_validate_config($srvid, $usrid, $crtid); @@ -193,7 +238,7 @@ EOF; // add basic settings $devmode = empty($settings['dev_mode']) ? "tun" : $settings['dev_mode']; - if (($expformat != "inlinedroid") && ($expformat != "inlineios")) { + if (($expformat != "inlinedroid") && ($expformat != "inlineconnect")) { $conf .= "dev {$devmode}{$nl}"; } @@ -201,47 +246,29 @@ EOF; if ($legacy && (!empty($settings['tunnel_networkv6']) && ($expformat != "inlinedroid") && - ($expformat != "inlineios"))) { + ($expformat != "inlineconnect"))) { $conf .= "tun-ipv6{$nl}"; } $conf .= "persist-tun{$nl}"; $conf .= "persist-key{$nl}"; -// if ((($expformat != "inlinedroid") && ($expformat != "inlineios")) && ($proto == "tcp")) -// $conf .= "proto tcp-client{$nl}"; - - $data_ciphers = ""; - /* This only exists on pfSense 2.5.0 with OpenVPN 2.5.0 */ - if (function_exists('openvpn_build_data_cipher_list')) { - $cipher = $settings['data_ciphers_fallback']; - $data_ciphers = openvpn_build_data_cipher_list($settings['data_ciphers'], $cipher, ($settings['ncp_enable'] != "disabled")); - } else { - /* 2.4.x or earlier */ - $cipher = $settings['crypto']; - $data_ciphers = $settings['ncp-ciphers']; - } - - $data_ciphers = explode(',', $data_ciphers); + $cipher = $settings['data_ciphers_fallback']; + $data_ciphers = explode(',', openvpn_build_data_cipher_list($settings['data_ciphers'], $cipher)); if ($legacy) { $data_ciphers = array_diff($data_ciphers, $legacy_incompatible_ciphers); } $data_ciphers = implode(':', $data_ciphers); - if ($settings['ncp_enable'] == "disabled") { - $conf .= "ncp-disable{$nl}"; - $conf .= "cipher {$cipher}{$nl}"; - } else { - /* If the data ciphers list is empty, don't specify a list so OpenVPN's default will be used. */ - if (!empty($data_ciphers)) { - $conf .= (($legacy) ? "ncp-ciphers" : "data-ciphers") . " {$data_ciphers}{$nl}"; - } - $conf .= (($legacy) ? "cipher" : "data-ciphers-fallback") . " {$cipher}{$nl}"; + /* If the data ciphers list is empty, don't specify a list so OpenVPN's default will be used. */ + if (!empty($data_ciphers)) { + $conf .= (($legacy) ? "ncp-ciphers" : "data-ciphers") . " {$data_ciphers}{$nl}"; } + $conf .= (($legacy) ? "cipher" : "data-ciphers-fallback") . " {$cipher}{$nl}"; $conf .= "auth {$digest}{$nl}"; $conf .= "tls-client{$nl}"; $conf .= "client{$nl}"; - if (($expformat != "inlinedroid") && ($expformat != "inlineios")) { + if (($expformat != "inlinedroid") && ($expformat != "inlineconnect")) { $conf .= "resolv-retry infinite{$nl}"; } $conf .= "$remotes{$nl}"; @@ -365,18 +392,12 @@ EOF; } } - // Prevent MITM attacks by verifying the server certificate. - // - Disable for now, it requires the server cert to include special options - //$conf .= "remote-cert-tls server{$nl}"; - - // Extra protection for the server cert, if it's supported - if (function_exists("cert_get_purpose")) { - if (is_array($server_cert) && ($server_cert['crt'])) { - $crt_details = openssl_x509_parse(base64_decode($server_cert['crt'])); - $eku_list = explode(',', $crt_details['extensions']['extendedKeyUsage']); - if (in_array('TLS Web Server Authentication', $eku_list)) { - $conf .= "remote-cert-tls server{$nl}"; - } + // Extra protection against for the server cert, if it's supported + if (is_array($server_cert) && ($server_cert['crt'])) { + $crt_details = openssl_x509_parse(base64_decode($server_cert['crt'])); + $eku_list = explode(',', $crt_details['extensions']['extendedKeyUsage']); + if (in_array('TLS Web Server Authentication', $eku_list)) { + $conf .= "remote-cert-tls server{$nl}"; } } @@ -461,9 +482,9 @@ EOF; // convert to pkcs12 format $p12file = "{$tempdir}/{$prefix}.p12"; if ($usetoken) { - openvpn_client_pem_to_pk12($p12file, $outpass, $crtfile, $keyfile); + openvpn_client_pem_to_pk12($p12file, $outpass, $p12encryption, $crtfile, $keyfile, $prefix); } else { - openvpn_client_pem_to_pk12($p12file, $outpass, $crtfile, $keyfile, $cafile); + openvpn_client_pem_to_pk12($p12file, $outpass, $p12encryption, $crtfile, $keyfile, $prefix, $cafile); } } $command = "cd " . escapeshellarg("{$tempdir}/..") @@ -477,7 +498,7 @@ EOF; // creates: conf file content. case "inline": case "inlinedroid": - case "inlineios": + case "inlineconnect": case "inlinevisc": // Inline CA $conf .= "{$nl}" . trim($server_ca) . "{$nl}{$nl}"; @@ -564,24 +585,33 @@ EOF; } } -function openvpn_client_export_installer($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $outpass, $proxy, $advancedoptions, $openvpn_version = "x64-msi", $usepkcs11, $pkcs11providers, $pkcs11id, $silent) { - global $g, $input_errors, $current_openvpn_version, $current_openvpn_version_rev, $legacy_openvpn_version, $legacy_openvpn_version_rev; +function openvpn_client_export_installer($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $outpass, $p12encryption, $proxy, $advancedoptions, $openvpn_version = "x64-current", $usepkcs11, $pkcs11providers, $pkcs11id, $silent) { + global $g, $input_errors; + global $current_openvpn_version, $current_openvpn_version_rev; + global $previous_openvpn_version, $previous_openvpn_version_rev; + global $legacy_openvpn_version, $legacy_openvpn_version_rev; switch ($openvpn_version) { case "Win7": $legacy = true; - $client_install_exe = "openvpn-install-{$legacy_openvpn_version}-I6{$legacy_openvpn_version_rev}-Win7.exe"; + $client_install_exe = "openvpn-install-{$legacy_openvpn_version}-I{$legacy_openvpn_version_rev}-Win7.exe"; break; case "Win10": $legacy = true; - $client_install_exe = "openvpn-install-{$legacy_openvpn_version}-I6{$legacy_openvpn_version_rev}-Win10.exe"; + $client_install_exe = "openvpn-install-{$legacy_openvpn_version}-I{$legacy_openvpn_version_rev}-Win10.exe"; break; - case "x86-msi": - $client_install_exe = "OpenVPN-{$current_openvpn_version}-I6{$current_openvpn_version_rev}-x86.msi"; + case "x86-previous": + $client_install_exe = "OpenVPN-{$previous_openvpn_version}-I{$previous_openvpn_version_rev}-x86.msi"; break; - case "x64-msi": + case "x64-previous": + $client_install_exe = "OpenVPN-{$previous_openvpn_version}-I{$previous_openvpn_version_rev}-amd64.msi"; + break; + case "x86-current": + $client_install_exe = "OpenVPN-{$current_openvpn_version}-I{$current_openvpn_version_rev}-x86.msi"; + break; + case "x64-current": default: - $client_install_exe = "OpenVPN-{$current_openvpn_version}-I6{$current_openvpn_version_rev}-amd64.msi"; + $client_install_exe = "OpenVPN-{$current_openvpn_version}-I{$current_openvpn_version_rev}-amd64.msi"; break; } @@ -617,7 +647,7 @@ function openvpn_client_export_installer($srvid, $usrid, $crtid, $useaddr, $veri /* OpenVPN Win7/Win10 installer stub is 32-bit, but could need to read a 64-bit registry. * Using the 64-bit-aware openvpn-postinstall works fine even on 32-bit Windows 10. */ - if (in_array($openvpn_version, array('Win7', 'Win10', 'x64-msi'))) { + if (in_array($openvpn_version, array('Win7', 'Win10', 'x64-previous', 'x64-current'))) { rename("{$tempdir}/openvpn-postinstall64.exe", "{$tempdir}/openvpn-postinstall.exe"); } @@ -630,7 +660,7 @@ function openvpn_client_export_installer($srvid, $usrid, $crtid, $useaddr, $veri $pwdfle .= "{$proxy['password']}\r\n"; file_put_contents("{$confdir}/{$proxy['passwdfile']}", $pwdfle); } - $conf = openvpn_client_export_config($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $nokeys, $proxy, "", "baseconf", false, true, $advancedoptions, $usepkcs11, $pkcs11providers, $pkcs11id); + $conf = openvpn_client_export_config($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $nokeys, $proxy, "baseconf", "", $p12encryption, false, true, $advancedoptions, $usepkcs11, $pkcs11providers, $pkcs11id); if (!$conf) { $input_errors[] = "Could not create a config to export."; return false; @@ -656,9 +686,9 @@ function openvpn_client_export_installer($srvid, $usrid, $crtid, $useaddr, $veri // convert to pkcs12 format $p12file = "{$tempdir}/config/{$prefix}.p12"; if ($usetoken) { - openvpn_client_pem_to_pk12($p12file, $outpass, $crtfile, $keyfile); + openvpn_client_pem_to_pk12($p12file, $outpass, $p12encryption, $crtfile, $keyfile, "{$prefix}-{$user['name']}"); } else { - openvpn_client_pem_to_pk12($p12file, $outpass, $crtfile, $keyfile, $cafile); + openvpn_client_pem_to_pk12($p12file, $outpass, $p12encryption, $crtfile, $keyfile, "{$prefix}-{$user['name']}", $cafile); } } @@ -702,7 +732,7 @@ function openvpn_client_export_installer($srvid, $usrid, $crtid, $useaddr, $veri return $outfile; } -function viscosity_openvpn_client_config_exporter($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $outpass, $proxy, $advancedoptions, $usepkcs11, $pkcs11providers, $pkcs11id) { +function viscosity_openvpn_client_config_exporter($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $outpass, $p12encryption, $proxy, $advancedoptions, $usepkcs11, $pkcs11providers, $pkcs11id) { global $g; $uniq = uniqid(); @@ -731,7 +761,7 @@ function viscosity_openvpn_client_config_exporter($srvid, $usrid, $crtid, $usead file_put_contents("{$tempdir}/{$proxy['passwdfile']}", $pwdfle); } - $conf = openvpn_client_export_config($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, true, $proxy, "baseconf", $outpass, true, true, $advancedoptions, $usepkcs11, $pkcs11providers, $pkcs11id); + $conf = openvpn_client_export_config($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, true, $proxy, "baseconf", $outpass, $p12encryption, true, true, $advancedoptions, $usepkcs11, $pkcs11providers, $pkcs11id); if (!$conf) { return false; } @@ -850,7 +880,7 @@ function openvpn_client_export_build_remote_lines($settings, $useaddr, $interfac $proto .= "-client"; } - if (($expformat == "inlineios") && ($proto == "tcp-client")) { + if (($expformat == "inlineconnect") && ($proto == "tcp-client")) { $proto = "tcp"; } diff --git a/security/pfSense-pkg-openvpn-client-export/files/usr/local/www/vpn_openvpn_export.php b/security/pfSense-pkg-openvpn-client-export/files/usr/local/www/vpn_openvpn_export.php index edf0d3fb297c..541ad3e821a6 100644 --- a/security/pfSense-pkg-openvpn-client-export/files/usr/local/www/vpn_openvpn_export.php +++ b/security/pfSense-pkg-openvpn-client-export/files/usr/local/www/vpn_openvpn_export.php @@ -25,9 +25,13 @@ require_once("guiconfig.inc"); require_once("openvpn-client-export.inc"); require_once("pfsense-utils.inc"); require_once("pkg-utils.inc"); +require_once("certs.inc"); require_once("classes/Form.class.php"); -global $current_openvpn_version, $current_openvpn_version_rev, $legacy_openvpn_version, $legacy_openvpn_version_rev, $dyndns_split_domain_types; +global $current_openvpn_version, $current_openvpn_version_rev; +global $previous_openvpn_version, $previous_openvpn_version_rev; +global $legacy_openvpn_version, $legacy_openvpn_version_rev; +global $dyndns_split_domain_types, $p12_encryption_levels; $pgtitle = array("OpenVPN", "Client Export Utility"); @@ -67,7 +71,7 @@ foreach ($a_server as $server) { init_config_arr(array('cert')); $ecdsagood = array(); foreach ($config['cert'] as $cert) { - if (!empty($cert['prv']) && function_exists('cert_check_pkey_compatibility') && + if (!empty($cert['prv']) && !cert_check_pkey_compatibility($cert['prv'], 'OpenVPN')) { continue; } else { @@ -257,6 +261,12 @@ if (!empty($act)) { $password = $cfg['pass']; } } + if (isset($_POST['p12encryption']) && + array_key_exists($_POST['p12encryption'], $p12_encryption_levels)) { + $p12encryption = $_POST['p12encryption']; + } else { + $p12encryption = 'high'; + } $want_cert = false; if (($srvcfg['mode'] == "server_tls_user") && ($srvcfg['authmode'] == "Local Database")) { @@ -349,9 +359,9 @@ if (!empty($act)) { $exp_name = urlencode($exp_name . "-android-config.ovpn"); $expformat = "inlinedroid"; break; - case "confinlineios": - $exp_name = urlencode($exp_name . "-ios-config.ovpn"); - $expformat = "inlineios"; + case "confinlineconnect": + $exp_name = urlencode($exp_name . "-connect-config.ovpn"); + $expformat = "inlineconnect"; break; case "confinlinevisc": $exp_name = urlencode($exp_name . "-viscosity-config.ovpn"); @@ -361,12 +371,12 @@ if (!empty($act)) { $exp_name = urlencode($exp_name . "-config.ovpn"); $expformat = "baseconf"; } - $exp_path = openvpn_client_export_config($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $nokeys, $proxy, $expformat, $password, false, false, $advancedoptions, $usepkcs11, $pkcs11providers, $pkcs11id); + $exp_path = openvpn_client_export_config($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $nokeys, $proxy, $expformat, $password, $p12encryption, false, false, $advancedoptions, $usepkcs11, $pkcs11providers, $pkcs11id); } if ($act == "visc") { $exp_name = urlencode($exp_name . "-Viscosity.visc.zip"); - $exp_path = viscosity_openvpn_client_config_exporter($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $password, $proxy, $advancedoptions, $usepkcs11, $pkcs11providers, $pkcs11id); + $exp_path = viscosity_openvpn_client_config_exporter($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $password, $p12encryption, $proxy, $advancedoptions, $usepkcs11, $pkcs11providers, $pkcs11id); } if (substr($act, 0, 4) == "inst") { @@ -375,29 +385,34 @@ if (!empty($act)) { switch ($openvpn_version) { case "Win7": $legacy = true; - $exp_name .= "{$legacy_openvpn_version}-I6{$legacy_openvpn_version_rev}-Win7.exe"; + $exp_name .= "{$legacy_openvpn_version}-I{$legacy_openvpn_version_rev}-Win7.exe"; break; case "Win10": $legacy = true; - $exp_name .= "{$legacy_openvpn_version}-I6{$legacy_openvpn_version_rev}-Win10.exe"; + $exp_name .= "{$legacy_openvpn_version}-I{$legacy_openvpn_version_rev}-Win10.exe"; break; - case "x86-msi": - $exp_name .= "{$current_openvpn_version}-I6{$current_openvpn_version_rev}-x86.exe"; + case "x86-previous": + $exp_name .= "{$previous_openvpn_version}-I{$previous_openvpn_version_rev}-x86.exe"; break; - case "x64-msi": + case "x64-previous": + $exp_name .= "{$previous_openvpn_version}-I{$previous_openvpn_version_rev}-amd64.exe"; + break; + case "x86-current": + $exp_name .= "{$current_openvpn_version}-I{$current_openvpn_version_rev}-x86.exe"; + break; + case "x64-current": default: - $exp_name .= "{$current_openvpn_version}-I6{$current_openvpn_version_rev}-amd64.exe"; + $exp_name .= "{$current_openvpn_version}-I{$current_openvpn_version_rev}-amd64.exe"; break; } $exp_name = urlencode($exp_name); - $exp_path = openvpn_client_export_installer($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $password, $proxy, $advancedoptions, substr($act, 5), $usepkcs11, $pkcs11providers, $pkcs11id, $silent); + $exp_path = openvpn_client_export_installer($srvid, $usrid, $crtid, $useaddr, $verifyservercn, $blockoutsidedns, $legacy, $bindmode, $usetoken, $password, $p12encryption, $proxy, $advancedoptions, substr($act, 5), $usepkcs11, $pkcs11providers, $pkcs11id, $silent); } - /* pfSense 2.5.0 with OpenVPN 2.5.0 has ciphers not compatible with + /* pfSense >= 2.5.0 with OpenVPN >= 2.5.0 has ciphers not compatible with * legacy clients, check for those and warn */ - if ($legacy && function_exists('openvpn_build_data_cipher_list')) { - /* This will only be reached for pfSense 2.5.0 with OpenVPN 2.5.0 */ + if ($legacy) { global $legacy_incompatible_ciphers; $settings = get_openvpnserver_by_id($srvid); if (in_array($settings['data_ciphers_fallback'], $legacy_incompatible_ciphers)) { @@ -521,7 +536,7 @@ $section->addInput(new Form_Checkbox( $section->addInput(new Form_Checkbox( 'legacy', 'Legacy Client', - 'Do not include OpenVPN 2.5 settings in the client configuration.', + 'Do not include OpenVPN 2.5 and later settings in the client configuration.', $cfg['legacy'] ))->setHelp("When using an older client (OpenVPN 2.4.x), check this option to prevent the exporter from placing known-incompatible settings into the client configuration."); @@ -576,7 +591,7 @@ $section->addInput(new Form_Checkbox( $section->addInput(new Form_Checkbox( 'usepass', 'Password Protect Certificate', - 'Use a password to protect the pkcs12 file contents or key in Viscosity bundle.', + 'Use a password to protect the PKCS#12 file contents or key in Viscosity bundle.', $cfg['usepass'] )); @@ -587,6 +602,14 @@ $section->addPassword(new Form_Input( $cfg['pass'] ))->setHelp('Password used to protect the certificate file contents.'); +$section->addInput(new Form_Select( + 'p12encryption', + 'PKCS#12 Encryption', + 'high', + $p12_encryption_levels +))->setHelp('Select the level of encryption to use when exporting a PKCS#12 archive. ' . + 'Encryption support varies by Operating System and program'); + $form->add($section); $section = new Form_Section('Proxy Options'); @@ -710,13 +733,14 @@ print($form);

" . +"Clients using OpenSSL 3.0 may not work with older or weaker ciphers and hashes, such as SHA1, including when those were used to sign CA and certificate entries." . +"

" . "OpenVPN 2.4.8+ requires Windows 7 or later"), 'info', false); ?> Links to OpenVPN clients for various platforms:

-
- -
-
: or -
-
- @@ -843,6 +867,8 @@ function download_begin(act, i, j) { } } + var p12encryption = document.getElementById("p12encryption").value; + var useproxy = 0; var useproxypass = 0; if (document.getElementById("useproxy").checked) { @@ -912,6 +938,7 @@ function download_begin(act, i, j) { if (usepass) { exportform.appendChild(make_form_variable("password", pass)); } + exportform.appendChild(make_form_variable("p12encryption", p12encryption)); if (useproxy) { exportform.appendChild(make_form_variable("proxy_type", proxytype)); exportform.appendChild(make_form_variable("proxy_addr", proxyaddr)); @@ -987,7 +1014,7 @@ function server_changed() { cell2.innerHTML += "   "; cell2.innerHTML += " Android<\/a>"; cell2.innerHTML += "   "; - cell2.innerHTML += " OpenVPN Connect (iOS/Android)<\/a>"; + cell2.innerHTML += " OpenVPN Connect (iOS/Android)<\/a>"; cell2.innerHTML += "- Bundled Configurations:"; cell2.innerHTML += "   "; cell2.innerHTML += " Archive<\/a>"; @@ -995,9 +1022,14 @@ function server_changed() { cell2.innerHTML += " Config File Only<\/a>"; cell2.innerHTML += "- Current Windows Installers ():"; cell2.innerHTML += "   "; - cell2.innerHTML += " 64-bit<\/a>"; + cell2.innerHTML += " 64-bit<\/a>"; cell2.innerHTML += "   "; - cell2.innerHTML += " 32-bit<\/a>"; + cell2.innerHTML += " 32-bit<\/a>"; + cell2.innerHTML += "- Previous Windows Installers ():"; + cell2.innerHTML += "   "; + cell2.innerHTML += " 64-bit<\/a>"; + cell2.innerHTML += "   "; + cell2.innerHTML += " 32-bit<\/a>"; cell2.innerHTML += "- Legacy Windows Installers ():"; cell2.innerHTML += "   "; cell2.innerHTML += " 10/2016/2019<\/a>"; @@ -1029,7 +1061,7 @@ function server_changed() { cell2.innerHTML += "   "; cell2.innerHTML += " Android<\/a>"; cell2.innerHTML += "   "; - cell2.innerHTML += " OpenVPN Connect (iOS/Android)<\/a>"; + cell2.innerHTML += " OpenVPN Connect (iOS/Android)<\/a>"; cell2.innerHTML += "- Bundled Configurations:"; cell2.innerHTML += "   "; cell2.innerHTML += " Archive<\/a>"; @@ -1037,9 +1069,15 @@ function server_changed() { cell2.innerHTML += " Config File Only<\/a>"; cell2.innerHTML += "- Current Windows Installer ():"; cell2.innerHTML += "   "; - cell2.innerHTML += " 64-bit<\/a>"; + cell2.innerHTML += " 64-bit<\/a>"; cell2.innerHTML += "   "; - cell2.innerHTML += " 32-bit<\/a>"; + cell2.innerHTML += " 32-bit<\/a>"; + cell2.innerHTML += "   "; + cell2.innerHTML += "- Previous Windows Installer ():"; + cell2.innerHTML += "   "; + cell2.innerHTML += " 64-bit<\/a>"; + cell2.innerHTML += "   "; + cell2.innerHTML += " 32-bit<\/a>"; cell2.innerHTML += "   "; cell2.innerHTML += "- Legacy Windows Installers ():"; cell2.innerHTML += "   "; @@ -1080,7 +1118,7 @@ function server_changed() { cell2.innerHTML += "   "; cell2.innerHTML += " Android<\a>"; cell2.innerHTML += "   "; - cell2.innerHTML += " OpenVPN Connect (iOS/Android)<\/a>"; + cell2.innerHTML += " OpenVPN Connect (iOS/Android)<\/a>"; cell2.innerHTML += "- Bundled Configurations:"; cell2.innerHTML += "   "; cell2.innerHTML += " Archive<\/a>"; @@ -1088,9 +1126,14 @@ function server_changed() { cell2.innerHTML += " Config File Only<\/a>"; cell2.innerHTML += "- Current Windows Installer ():"; cell2.innerHTML += "   "; - cell2.innerHTML += " 64-bit<\/a>"; + cell2.innerHTML += " 64-bit<\/a>"; cell2.innerHTML += "   "; - cell2.innerHTML += " 32-bit<\/a>"; + cell2.innerHTML += " 32-bit<\/a>"; + cell2.innerHTML += "- Previous Windows Installer ():"; + cell2.innerHTML += "   "; + cell2.innerHTML += " 64-bit<\/a>"; + cell2.innerHTML += "   "; + cell2.innerHTML += " 32-bit<\/a>"; cell2.innerHTML += "- Legacy Windows Installers ():"; cell2.innerHTML += "   "; cell2.innerHTML += " 10/2016/2019<\/a>"; diff --git a/security/pfSense-pkg-openvpn-client-export/pkg-descr b/security/pfSense-pkg-openvpn-client-export/pkg-descr index 1403b3da5737..b1960706f3c3 100644 --- a/security/pfSense-pkg-openvpn-client-export/pkg-descr +++ b/security/pfSense-pkg-openvpn-client-export/pkg-descr @@ -1,2 +1,2 @@ -Allows a pre-configured OpenVPN Windows Client or Mac OS X's Viscosity -configuration bundle to be exported directly from pfSense. +Exports pre-configured OpenVPN Client configurations directly from pfSense +software.