Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense won't stop creating lots of self-signed certs despite a trusted cert being installed already

    Scheduled Pinned Locked Moved webGUI
    2 Posts 2 Posters 350 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      arcza
      last edited by

      pfSense creates tons of spammy self-signed certs for the web UI, like below, and continually replaces my real, prod cert:

      0f163cb2-735f-41d2-9635-b28eaf8eecc5-image.png

      What causes this? The device is in a HA pair and this is incredibly annoying as the firewall is set up with a DNS record and the parent domain is registered for HSTS meaning only navigation by IP is possible (plus the red warning in Chrome).

      My guess is the HA sync option for Certificate Authorities, Certificates, and Certificate Revocation Lists, in which case this is a bug.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        When you have HA and XMLRPC config sync setup the certificates from the primary overwrite the secondary -- that is normal/expected, and not a bug.

        What you do in this case is add all certificates on the primary node, allow them to sync, and then choose the appropriate certificate on the secondary node after that sync finishes.

        This typically means using the same cert on both nodes and having its properties allow both hostnames/addresses to work, but you can use separate certs as well so long as the certificates are managed on the primary only.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 1
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.