From da15f6ee5109ae2bed11a5a61efa0e013e04ed3e Mon Sep 17 00:00:00 2001 From: "noussair.hamrit" Date: Mon, 21 Sep 2026 20:04:27 +0200 Subject: [PATCH] fix(radius): allow OpenVPN TLS re-authentication for existing sessions - exclude the current Acct-Session-Id from simultaneous-use checks - prevent TLS renegotiation from being rejected as a second login - keep Simultaneous-Use limited to fresh concurrent OpenVPN connections - preserve the existing RADIUS accounting session during TLS re-authentication --- files/mods-config/postgres-queries.conf | 2 ++ 1 file changed, 2 insertions(+) diff --git a/files/mods-config/postgres-queries.conf b/files/mods-config/postgres-queries.conf index a503b0b..0ddce92 100644 --- a/files/mods-config/postgres-queries.conf +++ b/files/mods-config/postgres-queries.conf @@ -237,6 +237,7 @@ simul_count_query = "\ LEFT OUTER JOIN nasreload n USING (NASIPAddress) \ WHERE UserName='%{SQL-User-Name}' \ AND AcctStopTime IS NULL \ + AND AcctSessionId != '%{Acct-Session-Id}' \ AND (a.AcctStartTime > n.ReloadTime OR n.ReloadTime IS NULL)" simul_verify_query = "\ @@ -246,6 +247,7 @@ simul_verify_query = "\ LEFT OUTER JOIN nasreload n USING (nasipaddress) \ WHERE UserName='%{SQL-User-Name}' \ AND AcctStopTime IS NULL \ + AND AcctSessionId != '%{Acct-Session-Id}' \ AND (a.AcctStartTime > n.reloadtime OR n.reloadtime IS NULL)" #######################################################################