[Openvpn-users] Multiple users profiles

  • Subject: [Openvpn-users] Multiple users profiles
  From: Robert Hendrickx
  Date: Wed, 8 Dec 2004 14:10:25 +0100 (CET)


For the moment, if I want to give to different users different access rights (different IP range),
I need to start multiple openvpn instances, with for each one something like a different CA, or an
authentification script refering to some kind of user table...  I can also play with static
addresses... not really scalable !

I think it would be nice in only one instance, based on a user name or a list of client cert IDs,
to map each new connexion to some defined profiles, with a specific tap interface and a specific
configuration (IP range, policies, ...).
It would ease the moving of a user from one profile to the other (no client configuration to
change), and give a more scalable solution for complex needs (teleworking, extranets, ...)

In a perfect world, it would even be possible to receive this "profile" information from a LDAP

What do you think of this feature, for the 3.0 roadmap...  I know, you are already quite busy with
the 2.0 !

By the way, really thank you for this wonderfull application !


Robert Hendrickx.

Please, use only my address "robert.hendrickx@xxxxxxxxxxx"


