Page MenuHomeVyOS Platform

openvpn: misleading "no openvpn shared-secrets in PKI" error for a dangling auth-key/crypt-key reference
In progress, NormalPublicBUG

Description

When tls auth-key, tls crypt-key or shared-secret-key references a name that isn't configured under pki openvpn shared-secret, commit fails with There are no openvpn shared-secrets in PKI configuration. It is raised from multiple paths (interfaces_openvpn.py:223 for the PSK shared-secret-key, :290 for tls auth-key/crypt-key) and doesn't say which leaf is at fault and it points at PKI instead of the offending interface line.

run generate pki ca install ovpn-ca

set interfaces openvpn vtun1 mode server
set interfaces openvpn vtun1 server subnet 10.20.30.0/24
set interfaces openvpn vtun1 tls ca-certificate ovpn-ca
set interfaces openvpn vtun1 tls auth-key NONEXISTENT
commit

Details

Version
1.5, 1.4
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)

Event Timeline

I would like to work on this task.

I plan to keep the validation behavior the same but make the OpenVPN
shared-secret errors leaf-specific, so dangling shared-secret-key,
tls auth-key, and tls crypt-key references report the offending interface
leaf and value instead of the generic PKI subtree message. I will add regression
coverage around the validation path.

Please assign the task to me if that scope is acceptable.