Hi,

I'm loading the openvpn-auth-ldap.so for user validation and then
loading the duo plugin for 2FA. It works, except it has an unwanted
behaviour if a user is not on the allowed groups in LDAP the
openvpn-auth-ldap.so will fail but will still trigger the push
notification. Shouldn't the 2nd plugin not be called if the previous
ends with error?

PLUGIN_CALL: POST
/usr/lib/openvpn/openvpn-auth-ldap.so/PLUGIN_AUTH_USER_PASS_VERIFY
status=1
PLUGIN_CALL: plugin function PLUGIN_AUTH_USER_PASS_VERIFY failed with
status 1: /usr/lib/openvpn/openvpn-auth-ldap.so
PLUGIN_CALL: POST /opt/duo/duo_openvpn.so/PLUGIN_AUTH_USER_PASS_VERIFY status=2


-- 
Com os melhores cumprimentos

--

Duarte Rocha <duarte.ro...@gmail.com>
_______________________________________
Programming today is a race between software
engineers striving to build bigger and better
idiot-proof programs, and the Universe trying to
produce bigger and better idiots.
So far, the Universe is winning.


_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to