Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Expired WebConfigurator Certificate - What Does It Mean and How to Fix It?

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 5 Posters 573 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      zikou
      last edited by

      Hi everyone,

      I'm using pfSense, and I recently noticed an issue in the Certificate Manager. It shows that my webConfigurator default certificate has expired several hundred days ago. The message states:

      "The following CA/Certificate entries are expiring:
      Certificate: webConfigurator default (63406c5da756f): Expired X days ago @ YYYY-MM-DD HH:MM:SS"

      My Questions:
      What does this expired certificate impact?
      Will this cause downtime or require a pfSense reboot?
      I want to make sure I'm handling this correctly and not causing any disruptions. Any guidance would be greatly appreciated!

      Thanks in advance!

      GertjanG 1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Some browsers may refuse to connect to it for example.
        You can just renew the cert in the cert manager. You will have to accept the new cert in the browser when you then connect to a new page in the gui. No downtime.

        1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @zikou
          last edited by

          @zikou

          Plan B : on the console : https://docs.netgate.com/pfsense/en/latest/config/advanced-admin.html

          This created a new GUI self-signed certicate, and the GUI was set to use it :

          98d86e58-43a5-4a04-bb43-b73c425f9e78-image.png

          But my browser (FF) refused to use it .... 😠
          ( I know, I can reset the GUI by set it to use http a and not https, now I can access the GUI,, export the new cert for the GUI, import in into my system so the browser won't complain anymore, and now switch back to https ... pfffff )

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          Z 1 Reply Last reply Reply Quote 0
          • Z
            zikou @Gertjan
            last edited by

            I saw renew
            what will happen will it fix that expired thing

            676831c8-71e5-4bd4-89f3-d292a0a18c12-image.png

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @zikou
              last edited by

              @zikou
              Renew will regenerate the certificate, and this will take care of the "Expired" issue.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • the otherT
                the other
                last edited by the other

                hey there,
                and while you're at it...instead of renewing, think about creating a new one, putting that default one to rest.
                Certificate manager makes that easy... :)
                Get your own CA, use that to issue your need future certs...works like a charm.
                I use it for internal use in my LAN, I had so far no issues with any browser in use here (FF and chromium).

                the other

                pure amateur home user, no business or professional background
                please excuse poor english skills and typpoz :)

                1 Reply Last reply Reply Quote 1
                • C
                  csaszykj
                  last edited by

                  Thanks for the useful info.

                  Mine was expired 150 days ago, but according to the info above, i've just renew-ed.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.