Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    send certificate by mail on renew?

    General pfSense Questions
    2
    5
    555
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      noviceiii
      last edited by noviceiii

      Dear all

      The VPN on my pfsense uses a certificate that renews every few weeks automatically.

      Is there a way to send the certificate by e-mail (as attachment) after every renewal automatically?

      Kind regards
      N3

      1 Reply Last reply Reply Quote 0
      • jimpJ jimp moved this topic from Problems Installing or Upgrading pfSense Software on
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        If the server certificate renews that wouldn't have to be loaded/updated on the client.

        You only have to update the client if the CA itself changes or if the client also uses a certificate and it gets renewed.

        You didn't say what type of VPN this was (IPsec? OpenVPN?) but the same is true of both.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • N
          noviceiii
          last edited by

          Thank you, jimp.

          You make a good point about no need to update the certificate on the client side. I'll investigate on that.

          To complete the picture: its for an IPsec VPN with a LetsEncryptCertificate.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Then you probably have nothing to update on the client, the server will update itself and so long as the client can validate it against the CA, it's good. With LE, it's publicly trusted, so it doesn't need a manual addition of the CA on the client.

            You should be OK as-is without any manual intervention.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            N 1 Reply Last reply Reply Quote 1
            • N
              noviceiii @jimp
              last edited by

              @jimp I've restarted the service and that solved the problem.... HACKERMAAAAN ๐Ÿ•บ

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.