[Openvpn-devel] Start openvpn gui before windows login

2021-11-15 Thread Ruben Herold


hi,

at our company we run into problems with domain joined windows notebooks
during lock downs. We realized that there is no way to start openvpn gui 
before windows login to connect to the company network.

I asks our support contact at MS an got the information that this is
only possible via: Universal Windows Platform (UWP) VPN plug-ins.

It should be possible to add external vpn clients like cisco anyconnect:

https://docs.microsoft.com/en-us/windows/security/identity-protection/vpn/vpn-connection-type

"There are a number of Universal Windows Platform VPN applications, such
as Pulse Secure, Cisco AnyConnect, F5 Access, Sonicwall Mobile Connect,
and Check Point Capsule. If you want to use a UWP VPN plug-in, work with
your vendor for any custom settings needed to configure your VPN
solution."

As seen on the screenshoot at:

https://remote-learning.arizona.edu/campus-technology-how-tos/vpn-start-before-logon

It looks like they only start their client gui. 

The only documentation I could get so far is:

https://docs.microsoft.com/en-us/uwp/api/Windows.Networking.Vpn?view=winrt-22000
and this could be an example:

https://github.com/ysc3839/UWPToyVpn

I'm not a developer so I can't proof. But I have some contacts at MS to
ask for more informations if needed. 

I think this could be a very usefull extension to openvpn. 


Thx

    ruben



-- 
Ruben Herold 
ru...@puettmann.net


___
Openvpn-devel mailing list
Openvpn-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-devel


Re: [Openvpn-devel] Start openvpn gui before windows login

2021-11-15 Thread Ruben Herold
On Mon, Nov 15, 2021 at 02:45:53PM +0200, Lev Stipakov wrote:
 Hi,
 
 
> Things might have changed since then, but our priorities now are
> releasing 2.6 with the new dco/dco-win drivers, which significantly
> improve performance. We might have a look at UWP VPN after that again.

Cause from the screenshoots it looks like they have found a way to start
their own gui during login so that the user can use MFA and so on. Or do
they really do all their vpn stuff via UWP?

I'm not very deep in this Windows stuff, so it can be that I'm on the
complete wrong way.

 
> Are you sure your problem cannot be solved with openvpn service?
> 
> See, for example,
> https://openvpn.net/community-resources/running-openvpn-as-a-windows-service/
> Also this discussion might be relevant:
> https://github.com/OpenVPN/openvpn-gui/issues/77
> 
We are using user/pass auth against AD and MFA so this is not possible. 

Ruben
-- 
Ruben Herold 
ru...@puettmann.net


___
Openvpn-devel mailing list
Openvpn-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-devel