Skip to content

Add OpenVPN private key password (askpass) support - #2164

Open
orcnd wants to merge 1 commit into
RaspAP:masterfrom
orcnd:feat/2109-openvpn-key-password
Open

orcnd wants to merge 1 commit into
RaspAP:masterfrom
orcnd:feat/2109-openvpn-key-password

Conversation

@orcnd

@orcnd orcnd commented Oct 3, 2026

Copy link
Copy Markdown

What

Adds an optional Private key password field to the OpenVPN client settings, in the Certificates panel. With it, .ovpn profiles that contain an encrypted inline <key> can be used.

Why

Without the passphrase, openvpn-client@client cannot decrypt the key without user input, so it exits with "can't ask for 'Enter Private Key Password'".

Fixes #2109

How

  • SaveOpenVPNConfig() accepts an optional $keyPassword. When it is set:
    • It is written to /tmp/ovpn/keypass (umask 0077, chmod 0600).
    • It is moved to /etc/openvpn/client/<name>_keypass.conf and symlinked as keypass.conf, the same way login.conf is handled.
    • These commands match the existing sudoers rules, so no sudoers changes are needed.
  • configauth.sh takes a 4th argument. When it is 1, the script replaces any existing askpass directive with askpass keypass.conf.
  • Activating a profile relinks keypass.conf, and deleting a profile removes its _keypass.conf.
  • Passwords that contain line breaks are rejected, because OpenVPN only reads the first line. The value is never echoed back into the form.
  • Arguments passed to configauth.sh are now shell-escaped.
  • The field is optional, so existing setups (username/password or certificate only) behave as before.

How tested

  • php -l passes on PHP 7.4, 8.2 and 8.5, and parallel-lint passes. phpcs (PSR-2) reports no new findings in the touched files.
  • I generated a CA and a client certificate with an encrypted key, built an inline .ovpn, and ran configauth.sh with sudo/iptables stubbed. The stale askpass line was removed and the new one was appended.
  • I ran OpenVPN 2.6 against that profile:
    • With the keypass file, the key loads and the client starts connecting.
    • With a wrong password, it fails with "private key password verification failed".
    • Without askpass, it fails the way the issue describes.
  • Not tested on a Raspberry Pi through the full web UI and systemd flow.

Notes

  • OpenVPN does not allow askpass together with auth-nocache.
  • Unrelated to this change: del_ovpncfg.php already used rm -f, which may not match the sudoers rule /bin/rm /etc/openvpn/client/*.conf. I kept the existing pattern rather than change it here.

AI disclosure: this change was prepared with the help of Claude Code and reviewed by me.

🤖 Generated with Claude Code

Adds an optional "Private key password" field to the OpenVPN client
settings for .ovpn files whose inline private key is encrypted.

When provided, the passphrase is written to <name>_keypass.conf
(mode 0600, created under a 0077 umask), symlinked as keypass.conf
the same way login.conf is handled, and configauth.sh replaces any
existing askpass directive with "askpass keypass.conf". Activating
or deleting a configuration now also relinks/removes its keypass
file. Arguments passed to configauth.sh are now shell-escaped.

Fixes RaspAP#2109

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add support for OpenVPN private key password in .ovpn configurations

1 participant