Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cipher missing from server post Server Certificate renewal

    Scheduled Pinned Locked Moved OpenVPN
    28 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NightlySharkN
      NightlyShark @prashant.joshi
      last edited by

      @prashant-joshi At this point of the head-scratching process, I would reinstall (remove and install) the OpenVPN package manually via cli.

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @Gertjan
        last edited by

        @Gertjan are you really on 23.05.1 ? I would move to current supported version 23.09.1 - there has been multiple changes, big one is jump to open ssl3, and I know the openvpn version has also been updated.

        23.05.1 is no longer on the supported list.

        If it was me, I would upgrade to current, and if your certs are still not working... Create new..

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        NightlySharkN GertjanG 2 Replies Last reply Reply Quote 1
        • NightlySharkN
          NightlyShark @johnpoz
          last edited by NightlyShark

          @johnpoz We tried TS via anydesk (as securely as possible...) and in the end, it was throwing the "libssl.so.30 not found" error. In about 3 hours (when their workplace will empty) they will attempt the update.

          I wonder why I was spared from that when I updated, with my 2+ year old certs... Maybe because I have everything ECDSA.

          johnpozJ GertjanG 2 Replies Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @NightlyShark
            last edited by

            @NightlyShark said in Cipher missing from server post Server Certificate renewal:

            ECDSA

            I am pretty much exclusively using those.. I just created a couple for my new cams I got.. I might have some older but have started using those for the last few years.. And using those for my openvpn stuff.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            NightlySharkN 2 Replies Last reply Reply Quote 1
            • NightlySharkN
              NightlyShark @johnpoz
              last edited by NightlyShark

              @johnpoz And... a little bird told me that the only secure curve that was not recommended by certain people that are known to be allergic to public encryption (caugh, PRISM!, caugh) was secp521r1...

              1 Reply Last reply Reply Quote 0
              • NightlySharkN
                NightlyShark @johnpoz
                last edited by

                @johnpoz That little bird is google, ok? hahaha

                1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan @NightlyShark
                  last edited by

                  @NightlyShark said in Cipher missing from server post Server Certificate renewal:

                  "libssl.so.30 not found"

                  That's your system telling you : don't stay on older versions of pfSense. Upgrade to the actual version (23.09.1) asap and you'll be fine.
                  And note somewhere for the future : "never ever upgrade / install / 'do things with' packages before you've upgrade pfSense to the latest available version first".

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  NightlySharkN 1 Reply Last reply Reply Quote 0
                  • NightlySharkN
                    NightlyShark @Gertjan
                    last edited by NightlyShark

                    @Gertjan It's not my system... Not my thread, even. I just talk too much, hahaha.

                    1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan @johnpoz
                      last edited by

                      @johnpoz said in Cipher missing from server post Server Certificate renewal:

                      @Gertjan are you really on 23.05.1 ?

                      Me ? Your kidding. 23.05.1 was ok, probably, I don't remember, 23.09.1 is pretty rock solid (for me). "VPN" (server) works well.
                      My bird says : if update is available, let the dust settle for a couple of days, and then click : upgrade.

                      Btw : I've still my 10 years certs in service :

                      1b570479-9c60-47e0-a205-57acb81393fe-image.png

                      Total Lifetime: 3650 days
                      Lifetime Remaining: 1027 days until expiration

                      These were the less secure days I guess ...

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      P 1 Reply Last reply Reply Quote 0
                      • P
                        prashant.joshi @Gertjan
                        last edited by

                        @Gertjan @NightlyShark Thanks for your support and advice. Post version upgrade the issue was resolved.

                        Things are in control now and working well...

                        Once again thank you everyone.....

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.