• ACME pkg v1.0

    Pinned
    5
    3 Votes
    5 Posts
    245 Views
    jimpJ
    @Urbaman75 said in ACME pkg v1.0: I tried to update ACME on a 2.8.0 pfsense, actually stuck and broken the installation, can't get to pfsense Webgui or SSH. I'll get back with more info. Start a fresh thread for that. I tested it on 2.8.x and it worked fine there, so it probably isn't something to do with the package itself, but something else going on with your installation.
  • 0 Votes
    19 Posts
    411 Views
    M
    @raidflex said in updating to acme 1.0 breaks system beyond repair: need to restore from backup: maybe uninstall Crowdsec when applying other updates first. It seems like it doesn't help at least from what I see on my system... it changes something.. so it must be definitely reported to their github. I have never experienced that before and crowsec was installed.. maybe with 2.8.0 something have changed
  • Issue with ACME Certificates Refresh & Restarting HAProxy

    acme haproxy
    5
    1 Votes
    5 Posts
    2k Views
    GertjanG
    @EChondo What's your pfSense version ? The instructions are shown here : [image: 1753262126227-1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png] A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate. @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy: I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess. No need to wait x days. You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.
  • ZeroSSL - How to revoke/remove existing certificates

    2
    0 Votes
    2 Posts
    96 Views
    johnpozJ
    @MacUsers https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation edit: oh you prob out of luck You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates. the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.
  • ACME Gandi.net renewal

    8
    0 Votes
    8 Posts
    515 Views
    I
    @Gertjan Good point. I linked this thread in the Redmine issue. Possible a UI selection could fix this. Still, I'm no dev and I do not know where everything comes from. I'm also not using Git.
  • ACME Subdomain revoke Cert

    3
    0 Votes
    3 Posts
    566 Views
    M
    @jimp I know it's a nn ols thread but very similar to what I'm trying to find out, so piggy backing.......... I understabd it will expire in 90 days, but what if I really need to revoke the cert? This is one of the issue with ZeroSSL free offering, which only gives you four certifictes and until one os revoked, it wil use of one of the number from the quota - any idea how to actually revoke an external ACME certificate? 5yrs. later, I sill don't see any option to do that -S
  • Porkbun changed their api

    11
    0 Votes
    11 Posts
    2k Views
    GertjanG
    @luxor84 Why editing the pork_burn.sh file ? You started with a more clean solution : a patch. Why not including a patch for pork burn file ?
  • Let's Encrypt removing TLS Client Authentication EKU

    1
    5 Votes
    1 Posts
    328 Views
    No one has replied
  • ACME using dynv6

    17
    0 Votes
    17 Posts
    4k Views
    Bob.DigB
    @Gertjan said in ACME using dynv6: but I can't see the usefulness of publishing my "pfSense LAN-ipv6-address". You don't publish it, you use it, to update only the prefix part of a given dns-record. I for example changed to only use ULAs in my LANs. But also I have some "unused" VLANs set to "Track Interface" to get the daily changing prefixes to then use them with NPt for my ULA-LANs. I would benefit from what I have described before. If you, as an expert user, found a solution, that works for you, that is great. I still wait for pfSense to bring a better solution to this for the rest of us.
  • How to add dns provider to ACME?

    4
    0 Votes
    4 Posts
    590 Views
    F
    @SteveITS Feature request created: https://redmine.pfsense.org/issues/16150
  • how to use with no-ip.com

    2
    0 Votes
    2 Posts
    326 Views
    T
    I ended up signing up for duckdns and users still use my old no-ip.com ddns. apparently lets encrypt certs work on multiple domains
  • Multiple, Different Methods in Certificate leads to renewal failure

    1
    0 Votes
    1 Posts
    204 Views
    No one has replied
  • PHP error when navigating to ACME plugin page

    4
    0 Votes
    4 Posts
    681 Views
    M
    Thanks for the insight, that resolved the issue
  • Cannot renew or create new cert Godaddy API

    6
    0 Votes
    6 Posts
    1k Views
    C
    @Gertjan Yes it is but the GUI still laggs so at least now I know I can use the cert without waiting for GUI to update.
  • PHP error installing pfSense-pkg-acme: 0.9_1

    5
    0 Votes
    5 Posts
    843 Views
    I
    @Gertjan Thank you so much for the help. I've removed all of the child nodes of <acme>, reinstalled the package and it completed. Thanks again!
  • End of January 2025 : Support for OSCP Stapling will end begin may 2025.

    1
    0 Votes
    1 Posts
    364 Views
    No one has replied
  • Unable to delete TXT record

    4
    0 Votes
    4 Posts
    974 Views
    GertjanG
    @michmoor said in Unable to delete TXT record: My domain expired
  • acme-v01.api.letsencrypt.org Reprecated?

    4
    0 Votes
    4 Posts
    734 Views
    M
    @Gertjan Oh you helped solve the problem! Thank you!
  • BUG? 24.11 ACME IPV6 cloudflare issues, ipv4 not respected?

    1
    0 Votes
    1 Posts
    388 Views
    No one has replied
  • Crash - DNS-Al-inkl Kasserver

    2
    0 Votes
    2 Posts
    400 Views
    M
    The PHP error is a symptom of the configuration file being corrupted in some way. If I remember correctly, the corrupted configuration file is kept either in /tmp or /conf. If it exists, you can do a diff of the good and bad configuration file and post that here for review.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.