Score:2

Does Ubuntu OpenVPN client supports static-challenge?

cy flag

I have a functional OpenVPN MFA Linux server setup that authenticates user with username/password and TOTP value from tools like Google Authenticator or similar.

Client configuration relevant part looks like this:

...
auth-user-pass
static-challenge "Enter Authenticator Code" 1
...

Everything works without problems on Windows once I install OpenVPN Connect client. User would get asked for username, password and then to "Enter Authenticator Code" (TOTP).

On Ubuntu (checked with 22.04) machines, the included OpenVPN client seems to ignore static-challenge directive in conf file. When I import the configuration the user is never asked for the TOTP code. If I use openvpn3 client then it works, and in that case the connection is established and works same as on Windows.

Problem is that openvpn3 is console only app, and as such not so convenient for users, specially since default client on Ubuntu has a nice GUI. Is it really the case that included client in Ubuntu does not support a way to ask for TOTP code? If that is the truth, is there any GUI that could be used for openvpn3 client on Linux?

Marko avatar
cy flag
Upon further investigation, it seems it does not. Ubuntu Network Manager UI is lagging a lot, and there are several duscussions on the internet on that topic - usually quite frustrated..
Marko avatar
cy flag
Update, new openvpn3 client for linux does support it https://github.com/OpenVPN/openvpn3-linux/ and I can confirm it works with 22.04, but it is missing GUI - command line only as far as I can see.
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.