Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Add this Certificate Authority to the Operating System Trust Store

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      shoulders
      last edited by

      Hi

      The official documentation says

      Trust Store
      
      Controls whether or not this CA is added to the certificate trust store on the firewall. When added to the trust store, a CA will be considered valid for all certificate operations performed by the operating system. If the firewall must contact a server using a certificate issued by a private CA, this allows such certificates to be trusted by client programs such as LDAP authentication, SMTP notifications, URL table connections, and many others.
      
      • I don't know when I should use this. Can some one give me some scenarios and why this would be used?
      • To which store does this get added, is it to remote clients? is this a certificate flag to prompt installation?

      thanks

      shoulders

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        You need to use it if the CA has to be used by some client on the firewall itself such as one of those listed. It adds the CA to the trust store on pfSense itself not to remote clients.
        Most users would not have to use that.

        Steve

        S 1 Reply Last reply Reply Quote 0
        • S
          shoulders @stephenw10
          last edited by

          @stephenw10 When you say client, do you mean like a 3rd party package installed on pfSense?

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Sorry I confusingly used clients twice. 😉

            I mean checking that box when importing or creating a CA does nothing for remote clients (like an OpenVPN client) that might need the CA cert later.

            It allows a client application on the firewall to connect to something using that CA that would otherwise not be trusted. So for example a local LDAP server using LDAPS can be added to the firewall and be authenticated.

            Steve

            S 1 Reply Last reply Reply Quote 1
            • S
              shoulders @stephenw10
              last edited by

              @stephenw10 I will get a issue raised and get this snippet of information added to the docs.

              Cheers, that sorted the issue out for me.

              1 Reply Last reply Reply Quote 1
              • S
                shoulders
                last edited by

                https://redmine.pfsense.org/issues/14174

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.