• ACME not issuing certificate

    23
    1 Votes
    23 Posts
    3k Views
    johnpozJ
    @robert-de-wit DOH!!! I was looking in ddns services ;) hehehe I don't use who ever that is, so there is no way for me to test that. Working fine here with clouldflare.
  • ACME auto renew failed on DNS server check

    Moved
    2
    0 Votes
    2 Posts
    915 Views
    M
    Issue resolved , I did add domains manually that ACME try to resolve : Services > DNS Resolvers> General Settings> Host Overrides [image: 1649753242141-5be85b50-3522-407f-94b3-06afafc4018f-image.png]
  • 0 Votes
    1 Posts
    401 Views
    No one has replied
  • ACME cert with rackspace

    Moved
    2
    0 Votes
    2 Posts
    845 Views
    stephenw10S
    @mrjoli021 said in ACME cert with rackspace: tmp/acme/wc_some_domain.com/acme_issuecert.log What do you see in the file when it fails?
  • Getting error with 0.7.4 when trying to create new certificate

    1
    0 Votes
    1 Posts
    593 Views
    No one has replied
  • Please fix: Spelling mistake

    3
    0 Votes
    3 Posts
    729 Views
    A
    @jimp Excellent, thank you!
  • ACME package version 0.7_1

    3
    2 Votes
    3 Posts
    1k Views
    GertjanG
    DNS-NSupdate / RFC 2136 method, using my own domain name server, works. I knew I had to look up what "BuyPass" is. What it stand for, advantages, differences. Now there is SSL.com and ZeroSSL.
  • NET::ERR_CERT_AUTHORITY_INVALID : (STAGING) Artificial Apricot R3

    2
    0 Votes
    2 Posts
    768 Views
    jimpJ
    The staging server is for testing and is not publicly trusted. You need to edit the account key and set it to use the production server instead, then renew the certificate.
  • Error Updating Domain, Error Add Txt (Solved)

    4
    0 Votes
    4 Posts
    3k Views
    NollipfSenseN
    It turned out that, after digging deeply into the issue, my domain registrar does not support DNS_NSupdate RFC2136. So, I switched name server to Cloudflare and after a few stumble, got my certificate...wipe off sweat for lots of reading, swearing, and more reading. [Fri Feb 18 13:04:37 CST 2022] Your cert is in /tmp/acme/nollivoipserver_cert//nollivoipserver.nollicomm.net/nollivoipserver.nollicomm.net.cer [Fri Feb 18 13:04:37 CST 2022] Your cert key is in /tmp/acme/nollivoipserver_cert//nollivoipserver.nollicomm.net/nollivoipserver.nollicomm.net.key [Fri Feb 18 13:04:37 CST 2022] The intermediate CA cert is in /tmp/acme/nollivoipserver_cert//nollivoipserver.nollicomm.net/ca.cer [Fri Feb 18 13:04:37 CST 2022] And the full chain certs is there: /tmp/acme/nollivoipserver_cert//nollivoipserver.nollicomm.net/fullchain.cer [Fri Feb 18 13:04:37 CST 2022] Run reload cmd: /tmp/acme/nollivoipserver_cert/reloadcmd.sh
  • Fix for cleaning up txt record added by nsupdate

    1
    0 Votes
    1 Posts
    404 Views
    No one has replied
  • Acme and captive portal

    1
    0 Votes
    1 Posts
    595 Views
    No one has replied
  • Renew Certificate Downstream

    6
    0 Votes
    6 Posts
    1k Views
    NollipfSenseN
    @gertjan said in Renew Certificate Downstream: I never used something like HAproxy ; but, from what I make of it, if HAproxy is doing the TLS (https) front end, unpacking the TLS an sending plain http (NON TLS) to the back end, your PBX, then yes, no certs needed on the PBX. @johnpoz said in Renew Certificate Downstream: This is correct, if you do the ssl offload on haproxy - you don't need any sort of ssl on the backend your sending the traffic too if your sending it has just normal http traffic. Thank you all for the good sound of music...that's what I thought and is much better than leaving port 80 opens for Lets Encrypt on FreePBX to renew the certificate. This is just a cleaner method and basically creates a secure tunnel to the PBX.
  • Exporting certs to Windows machines

    Moved
    3
    0 Votes
    3 Posts
    1k Views
    T
    @gertjan Well thats the thing... I used to do it that way but what I'm trying to do is to automate the new cert propagation on the network to avoid having to go manually everywhere every 90 days when acme update the certs with letsencrypt...
  • renew certs from CLI

    4
    0 Votes
    4 Posts
    851 Views
    S
    @gertjan thanks for the info. Needed that on another system right now.
  • Creating WebGUI Certificate

    38
    0 Votes
    38 Posts
    7k Views
    NollipfSenseN
    @johnpoz I finally graduated from the University of Slow Learners after three years of repeating webGUI certificate class...wipe of sweat. [image: 1644723852620-screen-shot-2022-02-12-at-8.55.53-pm.png] [image: 1644723888355-screen-shot-2022-02-12-at-8.58.37-pm.png]
  • ACME Lets Encrypt HE.net unable to renew: Can not find account id url

    16
    0 Votes
    16 Posts
    3k Views
    B
    @gertjan Here is my thread on Let's Encrypt forum. Someone mentioned the curl POST was failing. I have the full log posted there.
  • Issues with ACME standalone HTTP server verification

    2
    0 Votes
    2 Posts
    642 Views
    Q
    Nevermind! I had the IP address entered wrong in my RP config! It worked now!
  • Certificat Validation Method Hosteur

    9
    0 Votes
    9 Posts
    1k Views
    W
    @johnpoz OMG, I just understood what you mean Sorry, it just took me few days ... I didn't knew we could do that, it's amazing ! Well, I will keep my first solution on that project as the person I'm working with also need to use domain from his clients which want keep managing their own zone. But dame, I keep that for later ! Thanks a lot !
  • HEADS UP: If you use TLS-ALPN, force a manual certificate renew ASAP

    1
    2 Votes
    1 Posts
    651 Views
    No one has replied
  • Help with ACME “Challenge-Alias” (AKA Alias mode)

    3
    0 Votes
    3 Posts
    2k Views
    L
    @gertjan I was able to get it working thanks in part for your suggestion of checking the option “Enable DNS domain alias mode”. The other part of the problem was that I typed the wrong CNAME information in my DNS provider. I had: _acme-challenge.cloud.MYDOMAIN.com --> MYDDNS.duckdns.org The acme challenge Alias needs this CNAME to be _acme-challenge.cloud.MYDOMAIN.com --> _acme-challenge.MYDDNS.duckdns.org [image: 1643276353764-cname-corrected.jpg] After making these corrections ACME was able to issue a certificate for my domain as expected. Thank you so much for the help.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.