I think it makes no sense sharing the same user/pwd or digital certificates , since both should be strictly personals !! Over that , using the static ip address assignement , based on username or certificate and then share these data…
I use this config. for having a control on “authorization network” ( via iptables), foo , with its own ip address while connected via vpn can go there (nas as well as ip-cam), while mickey mouse can’t , he can only access an internal web server…
anyway , to avoid the use at the same time of the same certificate ( i use X509+pwd) , I copied in /Database the file vpn_start , located in the /root/kerbynet.cgi/scripts/ directory , then I have removed the parameter –duplicate-cn , saved and in preboot I’ve added this line
cp -r /Database/vpn_start /root/kerbynet.cgi/scripts/vpn_start
I hope can help