Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Error creating new internal certificate

    Scheduled Pinned Locked Moved OpenVPN
    9 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      miki_teleco
      last edited by

      Hi everyone,

      I am triying to create a new internal certificate to use it with a pfsense user. I tried by two ways:

      • The first way is creating an user and clicking on "Click to create a user certificate". It creates a certificate but in Distinguished Name (Cert. Manager) this certificate is empty.
      • Second one is Add new certificate in Cert. Manager and choose internal certificate. I get this error:
        ย  ย  openssl library returns: error:0906D06C:PEM routines:PEM_read_bio:no start line

      I used the same CA to create others internal certificates in past. I don't know how to debug/solve this problem.

      Thanks beforehand.

      1 Reply Last reply Reply Quote 0
      • M
        miki_teleco
        last edited by

        May be the cert of the CA is now corrupted by some way because of a software upgrade? I think this is the reason but i'm not sure.

        1 Reply Last reply Reply Quote 1
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          What does the CA look like in the certificate manager on the CA tab?

          An upgrade wouldn't touch, and couldn't "corrupt" a CA. Maybe you're choosing the wrong CA when creating these certificates?

          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • M
            miki_teleco
            last edited by

            Hi! Thanks beforehand for your reply.
            I attach a capture of my Ca Cert in Ca tab. I checked (again) if it is the correct certificate and it is.

            c1.jpg
            c1.jpg_thumb

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              That looks OK, at least what I can see. It's internal, not expired, etc. Maybe it's something in one of the fields of the certificate you are trying to create. Are you using any special/accented characters or other formatting that might throw it off?

              The fields should have encoding to protect all of that, but it's still worth checking just to be safe.

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • fabricioguzzyF
                fabricioguzzy
                last edited by

                hello gentlemen
                I am facing exactly the same problem after installing version 2.4.3.

                Error while generating a certificate. CA works fine bit not server/client certificates. CA looks great, no special characters, nothing. Same I always use.

                Error message:ย  openssl library returns: error:0906D06C:PEM routines:PEM_read_bio:no start line

                Fabricio.

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  Do you mind sending me a copy of the CA certificate (not the key) and the exact, unredacted, values you have used when trying to create this new certificate? You can send them via PM so they are not public.

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • fabricioguzzyF
                    fabricioguzzy
                    last edited by

                    hello Jimp
                    doing it right now.

                    Thanks
                    Fabricio.

                    1 Reply Last reply Reply Quote 0
                    • R
                      rostrander
                      last edited by

                      This post is deleted!
                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.