
I'm loading the openvpn-auth-ldap.so for user validation and then
loading the duo plugin for 2FA. It works, except it has an unwanted
behaviour if a user is not on the allowed groups in LDAP the
openvpn-auth-ldap.so will fail but will still trigger the push
notification. Shouldn't the 2nd plugin not be called if the previous
ends with error?

PLUGIN_CALL: plugin function PLUGIN_AUTH_USER_PASS_VERIFY failed with
status 1: /usr/lib/openvpn/openvpn-auth-ldap.so
PLUGIN_CALL: POST /opt/duo/duo_openvpn.so/PLUGIN_AUTH_USER_PASS_VERIFY status=2

Com os melhores cumprimentos


Duarte Rocha <duarte.ro...@gmail.com>
Programming today is a race between software
engineers striving to build bigger and better
idiot-proof programs, and the Universe trying to
produce bigger and better idiots.
So far, the Universe is winning.

Openvpn-users mailing list

Reply via email to