Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cipher missing from server post Server Certificate renewal

    Scheduled Pinned Locked Moved OpenVPN
    28 Posts 4 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG
      Gertjan @prashant.joshi
      last edited by

      @prashant-joshi said in Cipher missing from server post Server Certificate renewal:

      23.05.1-RELEASE

      I've tried all sort of combinations with settings and certs to see if I could find the situation.

      But we don't have the same pfSense (I'm using 23.09.1) and OpenVPN version (I'm using 2.6.8) which makes comparing difficult.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      1 Reply Last reply Reply Quote 0
      • P
        prashant.joshi @NightlyShark
        last edited by

        @NightlyShark

        Did twice but no luck...

        NightlySharkN 1 Reply Last reply Reply Quote 0
        • NightlySharkN
          NightlyShark @prashant.joshi
          last edited by

          @prashant-joshi You deleted and recreated the server cert twice? Maybe you selected something in "Hardware Crypto"?

          P 1 Reply Last reply Reply Quote 0
          • P
            prashant.joshi @NightlyShark
            last edited by

            @NightlyShark I have simply renewed the cert not deleted the olderone.

            NightlySharkN 1 Reply Last reply Reply Quote 0
            • NightlySharkN
              NightlyShark @prashant.joshi
              last edited by

              @prashant-joshi I had stumbled upon a bug, where if the cert took a long time to generate (tried 16k RSA), the gui would behave like it had finished with the cert, but a background process remained active (creating the cert), for up to 20 minutes later...

              P 1 Reply Last reply Reply Quote 0
              • P
                prashant.joshi @NightlyShark
                last edited by

                @NightlyShark in my case cert shows properly renewed.

                Another thing I tried to save server settings it's giving me the "One or more of the selected Data Encryption Algorithms is not valid." error

                NightlySharkN 2 Replies Last reply Reply Quote 0
                • NightlySharkN
                  NightlyShark @prashant.joshi
                  last edited by NightlyShark

                  @prashant-joshi That means that when renewing the cert you changed ciphers and now it gets all confused. Just delete, both the cert and the server profile, and recreate. Unless there is a Gateway or a custom OpenVPN interface (for the fw rules) involved, then just try to delete the cert.

                  P 1 Reply Last reply Reply Quote 0
                  • NightlySharkN
                    NightlyShark @prashant.joshi
                    last edited by

                    @prashant-joshi Also, check out the logs for OpenVPN.

                    1 Reply Last reply Reply Quote 0
                    • P
                      prashant.joshi @NightlyShark
                      last edited by

                      @NightlyShark when I am trying to add new server still the left side Cipher is blank.

                      alt text

                      NightlySharkN 1 Reply Last reply Reply Quote 0
                      • NightlySharkN
                        NightlyShark @prashant.joshi
                        last edited by

                        @prashant-joshi You need to select a certificate, first :)

                        P 1 Reply Last reply Reply Quote 0
                        • P
                          prashant.joshi @NightlyShark
                          last edited by

                          @NightlyShark Even after selecting the server Cert nothing changed. Still the left side is missing and blank.

                          NightlySharkN 2 Replies Last reply Reply Quote 0
                          • NightlySharkN
                            NightlyShark @prashant.joshi
                            last edited by NightlyShark

                            @prashant-joshi Friend, I am this close to asking a stranger(you) to let me AnyDesk this...

                            1 Reply Last reply Reply Quote 0
                            • NightlySharkN
                              NightlyShark @prashant.joshi
                              last edited by

                              @prashant-joshi At this point of the head-scratching process, I would reinstall (remove and install) the OpenVPN package manually via cli.

                              1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator @Gertjan
                                last edited by

                                @Gertjan are you really on 23.05.1 ? I would move to current supported version 23.09.1 - there has been multiple changes, big one is jump to open ssl3, and I know the openvpn version has also been updated.

                                23.05.1 is no longer on the supported list.

                                If it was me, I would upgrade to current, and if your certs are still not working... Create new..

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                NightlySharkN GertjanG 2 Replies Last reply Reply Quote 1
                                • NightlySharkN
                                  NightlyShark @johnpoz
                                  last edited by NightlyShark

                                  @johnpoz We tried TS via anydesk (as securely as possible...) and in the end, it was throwing the "libssl.so.30 not found" error. In about 3 hours (when their workplace will empty) they will attempt the update.

                                  I wonder why I was spared from that when I updated, with my 2+ year old certs... Maybe because I have everything ECDSA.

                                  johnpozJ GertjanG 2 Replies Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator @NightlyShark
                                    last edited by

                                    @NightlyShark said in Cipher missing from server post Server Certificate renewal:

                                    ECDSA

                                    I am pretty much exclusively using those.. I just created a couple for my new cams I got.. I might have some older but have started using those for the last few years.. And using those for my openvpn stuff.

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    NightlySharkN 2 Replies Last reply Reply Quote 1
                                    • NightlySharkN
                                      NightlyShark @johnpoz
                                      last edited by NightlyShark

                                      @johnpoz And... a little bird told me that the only secure curve that was not recommended by certain people that are known to be allergic to public encryption (caugh, PRISM!, caugh) was secp521r1...

                                      1 Reply Last reply Reply Quote 0
                                      • NightlySharkN
                                        NightlyShark @johnpoz
                                        last edited by

                                        @johnpoz That little bird is google, ok? hahaha

                                        1 Reply Last reply Reply Quote 0
                                        • GertjanG
                                          Gertjan @NightlyShark
                                          last edited by

                                          @NightlyShark said in Cipher missing from server post Server Certificate renewal:

                                          "libssl.so.30 not found"

                                          That's your system telling you : don't stay on older versions of pfSense. Upgrade to the actual version (23.09.1) asap and you'll be fine.
                                          And note somewhere for the future : "never ever upgrade / install / 'do things with' packages before you've upgrade pfSense to the latest available version first".

                                          No "help me" PM's please. Use the forum, the community will thank you.
                                          Edit : and where are the logs ??

                                          NightlySharkN 1 Reply Last reply Reply Quote 0
                                          • NightlySharkN
                                            NightlyShark @Gertjan
                                            last edited by NightlyShark

                                            @Gertjan It's not my system... Not my thread, even. I just talk too much, hahaha.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.