Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Disable Expired Certificate notification

    Scheduled Pinned Locked Moved General pfSense Questions
    9 Posts 4 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Summer
      last edited by

      Dear Sirs,
      if I've revoked a certificate and now it is also expired, what should I do to avoid the daily notification that inform that the certificate is expired?
      I mean, it's alright that is expired and is also revoked.
      Thanks, BR

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        If it's expired it doesn't need to be revoked, as it's invalid either way. Just delete the certificate from the GUI at that point.

        Alternately, find the serial number of the certificate. Remove it from the CRL and GUI, then add it back to the CRL using the serial number.

        Then it's still revoked but you don't need to keep any of the extra cert metadata around.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        S 1 Reply Last reply Reply Quote 0
        • S
          Summer @jimp
          last edited by

          @jimp Thank you for your reply, but on this certificate on the GUI I don't see the icon for deletion next the others. On other certificates I can see that icon but on this one no.
          Are there other ways to delete it?
          Thanks, BR

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @Summer
            last edited by

            @summer said in Disable Expired Certificate notification:

            this certificate on the GUI I don't see the icon for deletion next the others.

            Because the GUI uses this cert ?!

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @Gertjan
              last edited by

              If your cert is in use, you won't see the delete button.

              certs.jpg

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • S
                Summer
                last edited by

                Is there a way to get the reference of who got the cert in use?
                I believe someting wrong has appened in previous upgrade, then I've tried to reissue the cert, but the valid until date didn't change correctly, so I've revoked the cert and this is what is shown now:

                227e24d7-e56a-4c06-b3b1-4a29acdb291b-image.png

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @Summer
                  last edited by

                  hmmm - off the top my head the quickest solution for you might be to just export the xml, delete the offending cert and then restore..

                  You should be able to spot it via the description

                  xml.jpg

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    Re-read my last reply above. It's probably not letting you delete it because it's used by a CRL. Get the cert serial, remove it from the CRL, then remove it from the GUI, and revoke it by using the cert serial.

                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      Summer @jimp
                      last edited by

                      @jimp thank you, I've reloaded the manually edited xml, now the errors are gone!

                      BR

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.