Pritunl Client v1.4 Released

Pritunl Client v1.4 has been released. This release adds a new TUI interface, Flatpak support and CLI improvements.

Terminal User Interface

A new interactive terminal interface has been added to allow controlling the client from the terminal without needing to use the GUI. The terminal interface is included in the macOS, Linux and Windows clients. The Linux client has the pritunl-client package to install the client with only the terminal interface. Refer to the terminal user interface documentation for more information on using the terminal client.

Flatpak Support

The Pritunl Client is now built for Flatpak. This required a redesign of the connection management service to utilize NetworkManager to allow running the client without root system access. The new Flatpak client will run entirely under user permissions and does not require any elevated permissions. There is optional TPM access that can be provided to the Flatpak client with udev rules to allow device authentication to work.

As long as the tray icon is not enabled this is a very lightweight client with just one 20mb Go based background service. Currently only WireGuard connections are supported with the Flatpak client. The Pritunl Client Flatpak documentation has more information on installing and configuring the Flatpak client.

Optional background support if the tray icon is enabled.

The Flatpak client has the same user interface as the standard client.

The Flatpak client includes matching icons for Numix Circle and Numix Square icon themes.


Command Line Client User Profile Support

Previously the command line client only supported system profiles. The CLI now supports user profiles and the option to move profiles between the user and system. The new TUI also has full support for system and user profiles.

macOS Suspend Device Authentication Issues

Improvements have been made to device authentication on macOS to resolve issues where re-connection would fail after resuming from sleep. This was often due to the Secure Enclave being unavailable for the first few seconds after resuming from sleep.

After upgrading to Pritunl Client 1.4, the VPN tun0 interface is now shown by NetworkManager as unmanaged.

Previously, my NetworkManager dispatcher script triggered on tun0 up and applied a systemd-resolved routing domain for our internal DNS. In 1.4, the dispatcher no longer receives any tun0 events, while the interface is still created and works normally.

Was this behavior intentionally changed as part of the new NetworkManager-based connection management in 1.4? If so, what was the reason for keeping tun0 unmanaged by NetworkManager?

There should be no changes to how that is managed unless the client is installed with Flatpak. The NetworkManager code is only used when the client is running in Flatpak. Also assuming you are talking about OpenVPN the Flatpak client will only support WireGuard and all the NetworkManager code is for WireGuard.

Previously, tun0 generated a NetworkManager up event, so a script in /etc/NetworkManager/dispatcher.d/ could run automatically and apply the required systemd-resolved routing domain.

Now tun0 is shown by NetworkManager as unmanaged, so no dispatcher event is generated for it. The old hook therefore never runs, even though the VPN tunnel itself is created and works correctly.

Non-flatpak version of Pritunl Client v1.4.4744.47.

You may have been using a older release, this release didn’t have any changes that should have impacted that. Several improvements have been made to the DNS configuration in recent releases. It should no longer require any additional configuration to work on Linux. If there are issues with the DNS run the commands below to get the DNS configuration.

sudo bash -x << 'EOF'
set -x
cat /etc/resolv.conf
cat /etc/resolvconf.conf
cat /etc/resolv.conf.bak
ls -la /etc/resolv.conf
resolvectl status
resolvectl dns
systemctl status systemd-resolved
resolvconf -l
NetworkManager --print-config | grep rc-manager
EOF