Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Certificate Autority

    Scheduled Pinned Locked Moved OpenVPN
    9 Posts 4 Posters 949 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      RenJ
      last edited by

      hI
      Is any body can help me?
      I receved this answer from Natgate support:

      TAC Lite is limited, for the most part, to the following:
      Hardware issues (while under warranty)
      pfSense firmware reinstallation (and downloads)
      Zero-to-ping -- connecting a single device to the firewall and establishing an internet connection, and verifying connectivity. Review the FAQ here for what ZTP entails.

      So, I bought a SG-2100 in september 26.
      I'm to the Certificate Manager.

      My question is:

      Why when I tried to meka a Autority Certificate I recived the answer:
      Invalid Certificate.

      Thank you

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @RenJ
        last edited by

        @renj what did you put in the fields? You pretty much give it a name and that is really all you have to do..

        So I take it your trying to import a ca? Do you have a CA cert? Where did you get it from?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • R
          RenJ
          last edited by

          Thank you for answer me!

          No I try to make my CA.
          Do I have to buy or somting other way?

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @RenJ
            last edited by johnpoz

            @renj no there is nothing to buy..

            example here is a new CA.

            ca.jpg

            You click the add button at the bottom of the CA tab, and look this is all I edited. And you don't even have to pick a country code if you don't want to. You don't even have to change the common name if you don't want to, it defaults to internal-ca. Then click save and have a new ca.

            So what did you put in? I mean its pretty cut and dry.. You just really have to fill in the Descriptive name field and hit save..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            R 1 Reply Last reply Reply Quote 0
            • R
              RenJ @johnpoz
              last edited by

              @johnpoz
              I did that but when I tried to use after I filled a client or server certificate I recived the answer: invalid CA.

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @RenJ
                last edited by

                @renj Going to need some details, like a screenshot of what you filled an and the error. Because here, I just created a cert from exampleca I created.

                servercert.jpg

                I don't even know how you could mess this up really to be honest.,

                What version of pfsense are you using?

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • R
                  RenJ
                  last edited by

                  Thank you Johnpaz
                  You was right!

                  Now, I'm on Packages Manager.
                  I have, under Instaled Packages window; two isntalled Packages.
                  At the bodom of this window, I have a message in red:
                  Package is configured but not (fully) installed or deprecated.
                  So, In the available packages window I have notting.
                  Probaly this red message is the problem?

                  What that mean?
                  I need those packages to finich my set-up!

                  Thank you verry much!

                  R GertjanG 2 Replies Last reply Reply Quote 0
                  • R
                    rcoleman-netgate Netgate @RenJ
                    last edited by

                    @renj I suggest a new topic under https://forum.netgate.com/category/5/installation-and-upgrades for that.

                    Screen shots are not required but are encouraged so that people can see exactly what you are. Feel free to redact serial numbers, NDIs and any public IP addresses from those images.

                    Ryan
                    Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                    Requesting firmware for your Netgate device? https://go.netgate.com
                    Switching: Mikrotik, Netgear, Extreme
                    Wireless: Aruba, Ubiquiti

                    1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan @RenJ
                      last edited by

                      @renj said in Certificate Autority:

                      So, In the available packages window I have notting.

                      You don't see these :

                      537b2daf-9e3b-4a71-8fb2-235e4a1ef86e-image.png

                      ?

                      @renj said in Certificate Autority:

                      I have, under Instaled Packages window; two isntalled Packages.
                      At the bodom of this window, I have a message in red:
                      Package is configured but not (fully) installed or deprecated.

                      We all have this :

                      a3d0d631-348e-418b-9c70-f850cfb5b53b-image.png

                      If an installed package is marked in red => now you know what that means.
                      If an installed package is marked in yellow => now you know what that means.

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.