Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Expired Authorities update

    Scheduled Pinned Locked Moved ACME
    5 Posts 3 Posters 961 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • chudakC
      chudak
      last edited by

      Hello

      It might be a simple question, but I don't know how to answer it, so help is appreciated.

      I have the expired authority

      c5ef2966-d248-4622-8d90-c9e0b4b4380f-image.png

      How do I find what 3 certs are using it?

      And how do I update it?

      PS: I don't see much difference in my pfS behavior

      TIA

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @chudak
        last edited by

        @chudak

        Hey, your late to the party 😊
        Several others threads discuss the 'issue' already.
        The solution is simple : delete it.

        Btw : don't take "delete it" literal.
        Of course I also wanted to say : get a pfSense config copy 'in case off'. And then delete it.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        chudakC 1 Reply Last reply Reply Quote 0
        • chudakC
          chudak @Gertjan
          last edited by

          @Gertjan said in Expired Authorities update:

          @chudak

          Hey, your late to the party 😊
          Several others threads discuss the 'issue' already.
          The solution is simple : delete it.

          Btw : don't take "delete it" literal.
          Of course I also wanted to say : get a pfSense config copy 'in case off'. And then delete it.

          OK copy that

          But how do you what certificates it's associated with?

          johnpozJ GertjanG 2 Replies Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @chudak
            last edited by

            @chudak doesn't matter its the CA not the cert.. There is one of the threads @Gertjan mentioned where I deleted all of my acme CAs - then renewed my certs and it just put back the CAs it needed/wanted.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 2
            • GertjanG
              Gertjan @chudak
              last edited by

              @chudak said in Expired Authorities update:

              But how do you what certificates it's associated with?

              Keep in mind that the pfSense cert store isn't the only one that exists 😊
              Every Pad, Phone, PC, etc every device that makes TLS connections uses a system wide certificate file, here /usr/local/share/certs/ca-root-nss.crt - see also here /etc/ssl/certs/*

              You've noticed that the pfSense Certificate store doesn't list all the certs found in /usr/local/share/certs/ca-root-nss.crt and that's good. If people start to mess with that list, thing will go downhill fast.

              These are all 'auto signed' and are all the CAs that are 'trusted' out of the box. These lists are updated often as new trust chaines are signed (agreed upon) among the wold's ruling CA authorities.
              These two folders are used when pfSense connects (as a client) to the (example) upgrade.netgate.com update/upgrade package server.

              The pfSense Certificate store is a convenient place were the admin can keep the system's local certificates and intermediate certificates for the local server processes.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.