Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ACME error? Or maybe not?

    Scheduled Pinned Locked Moved ACME
    4 Posts 2 Posters 491 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      oguruma
      last edited by

      I am trying to set up ACME so I can use the cert in haProxy.

      I am using Azure for DNS. When I issue/renew the cert, I get the error below.

      I checked the acme_issuecert.log and there are about a bajillion lines, but none of them lead me to believe anything went wrong.

      O 1 Reply Last reply Reply Quote 0
      • O
        oguruma @oguruma
        last edited by

        I have to add this as a reply because apparently things the post is spam if I include it in the OP

        When I look at System -> Certificates the CERT is listed there, and sure enough it only has the key data, not the certificate.

        When I refresh my Azure DNS portal as the certificate renews, I can see that it's adding/removing the _acme-challenge.domain.com TXT records.

        When I try to start haProxy with that cert I get

        O 1 Reply Last reply Reply Quote 0
        • O
          oguruma @oguruma
          last edited by

          Errors found while starting haproxy
          [NOTICE] (81300) : haproxy version is 2.8.3-86e043a
          [NOTICE] (81300) : path to executable is /usr/local/sbin/haproxy
          [ALERT] (81300) : config : parsing [/var/etc/haproxy_test/haproxy.cfg:25] : 'bind 123.1.1.123:443' in section 'frontend' : 'crt-list' : unable to load certificate from file '/var/etc/haproxy_test/https-domain.com.pem': no start line.
          [ALERT] (81300) : config : Error(s) found in configuration file : /var/etc/haproxy_test/haproxy.cfg
          [ALERT] (81300) : config : Fatal errors found in configuration.```

          I checked the acme_issuecert.log and there are about a bajillion lines, but none of them lead me to believe anything went wrong.

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @oguruma
            last edited by

            @oguruma

            When you renew manually, by clicking on the

            fff4a4e1-f2ba-4d77-a65d-108b5f195d92-image.png

            button, after a while (DNS Sleep setting) you will see a green box/recap.
            Succes at the end ?

            When you check, for example here : System > Certificates > Certificates did you find the cert with new start and end dates ?

            You see the same info here :

            222f4321-96d9-4d22-ab91-3aac33350769-image.png

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.