• ACME pkg v0.9_1

    Pinned
    1
    3 Votes
    1 Posts
    487 Views
    No one has replied
  • ZeroSSL - How to revoke/remove existing certificates

    2
    0 Votes
    2 Posts
    29 Views
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • ACME Gandi.net renewal

    8
    0 Votes
    8 Posts
    410 Views
    I

    @Gertjan Good point. I linked this thread in the Redmine issue. Possible a UI selection could fix this. Still, I'm no dev and I do not know where everything comes from. I'm also not using Git.

  • ACME Subdomain revoke Cert

    3
    0 Votes
    3 Posts
    514 Views
    M

    @jimp I know it's a nn ols thread but very similar to what I'm trying to find out, so piggy backing..........

    I understabd it will expire in 90 days, but what if I really need to revoke the cert? This is one of the issue with ZeroSSL free offering, which only gives you four certifictes and until one os revoked, it wil use of one of the number from the quota - any idea how to actually revoke an external ACME certificate?

    5yrs. later, I sill don't see any option to do that

    -S

  • Porkbun changed their api

    11
    0 Votes
    11 Posts
    1k Views
    GertjanG

    @luxor84

    Why editing the pork_burn.sh file ?
    You started with a more clean solution : a patch. Why not including a patch for pork burn file ?

  • Let's Encrypt removing TLS Client Authentication EKU

    1
    5 Votes
    1 Posts
    302 Views
    No one has replied
  • ACME using dynv6

    17
    0 Votes
    17 Posts
    4k Views
    Bob.DigB

    @Gertjan said in ACME using dynv6:

    but I can't see the usefulness of publishing my "pfSense LAN-ipv6-address".

    You don't publish it, you use it, to update only the prefix part of a given dns-record.

    I for example changed to only use ULAs in my LANs. But also I have some "unused" VLANs set to "Track Interface" to get the daily changing prefixes to then use them with NPt for my ULA-LANs. I would benefit from what I have described before.
    If you, as an expert user, found a solution, that works for you, that is great. I still wait for pfSense to bring a better solution to this for the rest of us.

  • How to add dns provider to ACME?

    4
    0 Votes
    4 Posts
    544 Views
    F

    @SteveITS Feature request created: https://redmine.pfsense.org/issues/16150

  • how to use with no-ip.com

    2
    0 Votes
    2 Posts
    288 Views
    T

    I ended up signing up for duckdns and users still use my old no-ip.com ddns. apparently lets encrypt certs work on multiple domains

  • Multiple, Different Methods in Certificate leads to renewal failure

    1
    0 Votes
    1 Posts
    182 Views
    No one has replied
  • Issue with ACME Certificates Refresh & Restarting HAProxy

    3
    1 Votes
    3 Posts
    2k Views
    F

    @Maxpower said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    For this, I have configured the command /usr/local/etc/rc.d/haproxy.sh to restart HAProxy, as its described in the GUI

    What exactly did you do here ?
    Can you go into detail ?

  • PHP error when navigating to ACME plugin page

    4
    0 Votes
    4 Posts
    621 Views
    M

    Thanks for the insight, that resolved the issue

  • Cannot renew or create new cert Godaddy API

    6
    0 Votes
    6 Posts
    960 Views
    C

    @Gertjan Yes it is but the GUI still laggs so at least now I know I can use the cert without waiting for GUI to update.

  • PHP error installing pfSense-pkg-acme: 0.9_1

    5
    0 Votes
    5 Posts
    773 Views
    I

    @Gertjan Thank you so much for the help. I've removed all of the child nodes of <acme>, reinstalled the package and it completed.

    Thanks again!

  • End of January 2025 : Support for OSCP Stapling will end begin may 2025.

    1
    0 Votes
    1 Posts
    342 Views
    No one has replied
  • Unable to delete TXT record

    4
    0 Votes
    4 Posts
    891 Views
    GertjanG

    @michmoor said in Unable to delete TXT record:

    My domain expired

    😊

  • acme-v01.api.letsencrypt.org Reprecated?

    4
    0 Votes
    4 Posts
    678 Views
    M

    @Gertjan

    Oh you helped solve the problem!

    Thank you!

  • BUG? 24.11 ACME IPV6 cloudflare issues, ipv4 not respected?

    1
    0 Votes
    1 Posts
    344 Views
    No one has replied
  • Crash - DNS-Al-inkl Kasserver

    2
    0 Votes
    2 Posts
    370 Views
    M

    The PHP error is a symptom of the configuration file being corrupted in some way. If I remember correctly, the corrupted configuration file is kept either in /tmp or /conf. If it exists, you can do a diff of the good and bad configuration file and post that here for review.

  • Error add txt for domain:_acme-challenge

    5
    0 Votes
    5 Posts
    892 Views
    K

    @tinfoilmatt it looks like I have finally gotten the certificate to pop up but now I am dealing with getting 503 Service Unavailable error. Do you know if this is an HAProxy issue or on the cloudflare side?

    Screenshot 2024-12-05 at 12.51.02 PM.png

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.