• ACME pkg v1.1_1

    Pinned
    8
    6 Votes
    8 Posts
    345 Views
    jimpJ
    @zimnysbrain This thread is not for reporting issues, it's to announce the release and for awareness. Every issue really belongs in its own thread so the discussions can be focused on single issues.
  • 0 Votes
    6 Posts
    254 Views
    GertjanG
    Saw 1.1_1 and installed it. Case closed
  • When you have a new wild card certicate ....

    1
    3
    0 Votes
    1 Posts
    53 Views
    No one has replied
  • Hostup DNSAPI needed

    5
    0 Votes
    5 Posts
    339 Views
    jimpJ
    https://forum.netgate.com/topic/200015/acme-pkg-v1.1
  • Acme Account Key interface shows 4-digit codes

    10
    1
    0 Votes
    10 Posts
    270 Views
    jimpJ
    At some point after that version there were changes made to Font Awesome which required adjustments to the format used to display icons like that. It's possible your system has a package that is using the new format which the base OS isn't compatible with. Updating to a current supported version would almost certainly fix it.
  • Pfsense error renew cert on duckdns

    1
    1
    0 Votes
    1 Posts
    85 Views
    No one has replied
  • ACME Server - Google Production no EAB Key ID or HMAC key

    4
    1
    0 Votes
    4 Posts
    325 Views
    jimpJ
    It's not really a bug, but a missing feature. The ACME package itself has no support for EAB registration, though some of the CAs now require it or offer it as an option. https://redmine.pfsense.org/issues/16623
  • IPSec and upcoming Letsencrypt changes (introducing profiles)

    1
    0 Votes
    1 Posts
    82 Views
    No one has replied
  • 0 Votes
    2 Posts
    278 Views
    M
    Likely the same root issue as https://redmine.pfsense.org/issues/16030. Update to the latest pfSense version and it should work if so.
  • BUG: ACME, Method "Hetzner DNS"

    6
    1
    0 Votes
    6 Posts
    784 Views
    jimpJ
    https://github.com/pfsense/FreeBSD-ports/commit/5ee0e4d0d57f67684563c485d1b5a6e9198fe9af It's in the latest version of the ACME package, which should be up now for Plus 25.07.1 and CE 2.8.1, Plus 25.11 should be up shortly but there's some work that needs to be done on 25.11 package builds which should be resolved before long. (Ignore the "1.1" bit in the commit message, it should be 1.0.3 for Plus 25.07.1 and CE 2.8.1, and1.0.6 for Plus 25.11)
  • no-ip

    2
    0 Votes
    2 Posts
    169 Views
    GertjanG
    @techpro2004 See here (2020 so yeah, old) : Acme Package with No-IP. As said, this is probably old info now. maybe no-ip is supported, but if you chose them, you have to support them : with your wallet (!) but check first if no-ip can be used with acme.sh. If you want to have a registrar or DDNS supported, add requests here : the source : https://github.com/acmesh-official/acme.sh/pulls as pfSense pulls in the latest acme.sh from there.
  • BUG? 24.11 ACME IPV6 cloudflare issues, ipv4 not respected?

    3
    0 Votes
    3 Posts
    1k Views
    GPz1100G
    @agitelzon I have no issue connecting to LE servers from pf shell. The issue is cloudflare security setting is configured as a whitelist for api zone record changes. The whitelist includes my ipv4 address only, as a /32. As I mentioned, I could add the ipv6 prefix as a /64. Given that pf is configured to prefer ipv4, I thought that would carry over to acme as well.
  • Action list not executed after acme-webgui timeout

    1
    0 Votes
    1 Posts
    213 Views
    No one has replied
  • Porkbun changed their api

    13
    0 Votes
    13 Posts
    4k Views
    GertjanG
    @acaronmd Updating tends to solve issues. A more recent pfSense version gives you also a newer acme version.
  • ACME renew cert fail after update from v24.11 to v25.07.01

    Moved
    3
    0 Votes
    3 Posts
    5k Views
    A
    Hi, Please help to forward / report the bugs in ACME 1.0 package. Thanks.
  • Let's Encrypt Cert via ACME ask for oathtool (PFSende 2.8)

    5
    0 Votes
    5 Posts
    2k Views
    G
    @Gertjan well..... finally i created a new user for inwx and just gave him dns_management role only AND without 2FA. So now all is fine, my PFSense has the LE Cert as it should be. Thanks and kr Mike
  • ACME using dynv6

    18
    0 Votes
    18 Posts
    8k Views
    A
    Hello, I am also trying to use DNS-NSupdate / RFC 2136 with dynv6.com. I have used all the information in this and the other related thread, but acme.sh blocks when trying to read the key from the disk. The logs show that the key file is expected in /tmp/acme/home-mydomain-tld-test-dynv6/home.mydomain.tldnsupdatealias-mydomain-tld.dynv6.net.key but is actually in /tmp/acme/home-mydomain-tld-test-dynv6/home.mydomain.tldnsupdate_acme-challenge.alias-mydomain-tld.dynv6.net.key Did I mess up the parameters or is there a bug in the call to acme.sh? Thanks for your help, Atanis
  • SSL Cert Failing

    6
    0 Votes
    6 Posts
    2k Views
    W
    Problem solved. Fat fingers at work!
  • How do I fix this expiring ACME Certificate?

    4
    0 Votes
    4 Posts
    2k Views
    G
    Thanks @Popolou @Gertjan for the reply. TLDR; I just want to confirm that this isn't a pfSense/ACME bug. I'm just going to delete the deprecated cert and consider this matter closed unless this is a bug. FULL REPLY: Thanks @Popolou @Gertjan for the reply. Thanks for the info. I now understand what is going on with these certificates which is a win. I was expecting that pfSense would manage these certificates and clear out the ones that are no longer needed. No big deal as long as I know I can safely delete them. @Popolou said in How do I fix this expiring ACME Certificate?: @guardian Just check to see which certificates have been issued with the now defunct/expiring CA and if it is zero (which is highly likely), then you can delete it. Any new cert renewals will still take place and the appropriate CA chain will be downloaded and installed if required. You may find you have R10 and R11 (or newer) installed through this route. @Gertjan said in How do I fix this expiring ACME Certificate?: @guardian said in How do I fix this expiring ACME Certificate?: CN=R3 Euh, that one has been depreciated long time ago. Read : Thanks.... I actually found this and read it. @guardian said in How do I fix this expiring ACME Certificate?: Is there a place I can download a new CA certificate? Normally, you don't need to. If your pfSense is recent enough, you has them already. Not under "System > Certificates > Authorities" but in the FreeBSD Certificate storage folder, here /usr/share/certs/trusted/ Thanks for this info. It looks like the certs that I have in play have been downloaded, so I guess I will just delete the old cert and be done.
  • updated package, php error when accessing certificates tab

    5
    0 Votes
    5 Posts
    2k Views
    B
    @Gertjan oh. It's all working fine now. Once I did restore to previous, everything worked. I was able to request new certs via ACME and the OpenVPN service came up and I was able to navigate all the tabs. With my certs down (and just expired) it broke a lot of things. Lol.
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.