From bb7476e1a2f61504f274823ced93c5bb608a76c6 Mon Sep 17 00:00:00 2001 From: Giga Murphy Date: Thu, 24 Jul 2025 00:18:27 +0000 Subject: T7635: OpenConnect Certificate Authentication --- src/conf_mode/vpn_openconnect.py | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) (limited to 'src') diff --git a/src/conf_mode/vpn_openconnect.py b/src/conf_mode/vpn_openconnect.py index 68cd363f0..8522a325b 100755 --- a/src/conf_mode/vpn_openconnect.py +++ b/src/conf_mode/vpn_openconnect.py @@ -105,11 +105,17 @@ def verify(ocserv): if 'authentication' in ocserv: if 'mode' in ocserv['authentication']: if ( - 'local' in ocserv['authentication']['mode'] - and 'radius' in ocserv['authentication']['mode'] + ('local' in ocserv['authentication']['mode'] + and 'radius' in ocserv['authentication']['mode']) + or + ('local' in ocserv['authentication']['mode'] + and 'certificate' in ocserv['authentication']['mode']) + or + ('radius' in ocserv['authentication']['mode'] + and 'certificate' in ocserv['authentication']['mode']) ): raise ConfigError( - 'OpenConnect authentication modes are mutually-exclusive, remove either local or radius from your configuration' + 'OpenConnect authentication modes are mutually-exclusive. Only one of local, radius, or certificate.' ) if 'radius' in ocserv['authentication']['mode']: if 'server' not in ocserv['authentication']['radius']: @@ -203,6 +209,9 @@ def verify(ocserv): raise ConfigError('SSL certificate missing on OpenConnect config!') verify_pki_certificate(ocserv, ocserv['ssl']['certificate']) + if 'ca_certificate' not in ocserv['ssl'] and 'certificiate' in ocserv['authentication']['mode']: + raise ConfigError('CA certificate must be provided in certificate authentication mode!') + if 'ca_certificate' in ocserv['ssl']: for ca_cert in ocserv['ssl']['ca_certificate']: verify_pki_ca_certificate(ocserv, ca_cert) -- cgit v1.2.3