Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    webConfigurator certificate expiry notification - any action required?

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      ChrisJenk
      last edited by

      I recently enabled SMTP notifications and today I received this:

      3:01:00 The following CA/Certificate entries are expiring:
      Certificate: webConfigurator default (611e6eab692a2) (611e6eab692a2): Expiring soon, in 27 days

      Do I need to take any action here? Or will the certificate auto-renew and the notification is more just an FYI?

      Thanks.

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @ChrisJenk
        last edited by

        @chrisjenk

        Backup your settings.
        Then :

        bef25e03-1b10-4a16-8e46-162c2ff03bd8-image.png

        there is also a command line version ( can't recall ).

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        C 1 Reply Last reply Reply Quote 0
        • C
          ChrisJenk @Gertjan
          last edited by

          @gertjan Thanks, that did the trick. Bit surprised there isn't an auto-renew mechanism for this certificate. Ah well, it is only once a year so no big deal I guess.

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @ChrisJenk
            last edited by

            @chrisjenk said in webConfigurator certificate expiry notification - any action required?:

            isn't an auto-renew mechanism for this certificate

            I never have to click or think about renewing my pfSense GUI cert.
            I chose not to use mine - the one I showed above. As you can see, it's not 'in use'.

            The mechanism is : I'm using :

            f0294e9a-2448-4b54-93b6-2f66cc4a0f9e-image.png

            and that one is renewed automatically ๐Ÿ˜Š Every 60 days to be exact.

            And true , isn't not free : about 6 $ a year (the price of a dot net domain name).

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            C 1 Reply Last reply Reply Quote 0
            • C
              ChrisJenk @Gertjan
              last edited by ChrisJenk

              @gertjan I use (free) Let's Encrypt certificates elsewhere for my domain(s). I was wondering if it was possible to set something similar up for pfSense, though as the Web GUI is not accessible outside of my LAN there is no real need. Is there an automatic Lets's Encrypt setup in pfSense for this (I couldn't immediately find one) or did you have to set this up manually? Of course, for normal Let's Encrypt setup/renewal various things need to be publicly resolvable/accessible, which for me is a bit of a no-no.

              GertjanG 1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                You can use the ACME package:
                https://docs.netgate.com/pfsense/en/latest/packages/acme/index.html

                Steve

                1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan @ChrisJenk
                  last edited by

                  @chrisjenk
                  Letsencrypt is free, of course. Not the domain name you have to handover. Hence the 6$ I mentioned.

                  @chrisjenk said in webConfigurator certificate expiry notification - any action required?:

                  Is there an automatic Lets's Encrypt setup in pfSense for this

                  You've missed
                  ca2cd228-6258-48b1-b103-0561e45cfd5c-image.png

                  and

                  db135300-47a9-4ba3-84a9-c2c99f40f0a9-image.png

                  ๐Ÿ˜Š

                  @chrisjenk said in webConfigurator certificate expiry notification - any action required?:

                  there is no real need

                  Agreed.
                  My 'need' is based on 3 reasons :

                  • I use it (pfSense ACME + Letsencrypt) ) because I rent so many domain names already, one more at the end of the year won't bite me.
                  • And because I have pfSense at my fingertips daily, I can play with acme/Letsencrypt, try things out, and when I mess up it won't be a big deal. This is not the same for my web servers and mail servers : a cert error will break a lot, as with mails, for example, I use "DANE" and the smallest error wilt halt all mail traffic == dangerous for the company.
                  • I wanted to understand "how it works", as I say a lot (to myself) that all this isn't rocket science any more, but certificates, TLS etc is most often completely not understood, but it is also very important these days.

                  The only advantage I have when I use Letencrypt certs on my pfSense (actually all my local devices with a GUI) : all my devices trust the GUI out of the box - no need to click some extra "yeah yeah yeah I know, it's Ok -make an exception please".

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  C 1 Reply Last reply Reply Quote 0
                  • C
                    ChrisJenk @Gertjan
                    last edited by

                    @gertjan Makes sense. Thanks for the info/explanation. Good to know this is available should it be necessary.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.