fix(radius): allow OpenVPN TLS re-authentication for existing sessions

- exclude the current Acct-Session-Id from simultaneous-use checks
- prevent TLS renegotiation from being rejected as a second login
- keep Simultaneous-Use limited to fresh concurrent OpenVPN connections
- preserve the existing RADIUS accounting session during TLS re-authentication
This commit is contained in:
2026-09-21 20:04:27 +02:00
parent b7034c733d
commit da15f6ee51
+2
View File
@@ -237,6 +237,7 @@ simul_count_query = "\
LEFT OUTER JOIN nasreload n USING (NASIPAddress) \ LEFT OUTER JOIN nasreload n USING (NASIPAddress) \
WHERE UserName='%{SQL-User-Name}' \ WHERE UserName='%{SQL-User-Name}' \
AND AcctStopTime IS NULL \ AND AcctStopTime IS NULL \
AND AcctSessionId != '%{Acct-Session-Id}' \
AND (a.AcctStartTime > n.ReloadTime OR n.ReloadTime IS NULL)" AND (a.AcctStartTime > n.ReloadTime OR n.ReloadTime IS NULL)"
simul_verify_query = "\ simul_verify_query = "\
@@ -246,6 +247,7 @@ simul_verify_query = "\
LEFT OUTER JOIN nasreload n USING (nasipaddress) \ LEFT OUTER JOIN nasreload n USING (nasipaddress) \
WHERE UserName='%{SQL-User-Name}' \ WHERE UserName='%{SQL-User-Name}' \
AND AcctStopTime IS NULL \ AND AcctStopTime IS NULL \
AND AcctSessionId != '%{Acct-Session-Id}' \
AND (a.AcctStartTime > n.reloadtime OR n.reloadtime IS NULL)" AND (a.AcctStartTime > n.reloadtime OR n.reloadtime IS NULL)"
####################################################################### #######################################################################