Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cert Manager

    Scheduled Pinned Locked Moved webGUI
    7 Posts 5 Posters 853 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad
      last edited by

      Is it time to revisit the default cert lifetime defaults in the web GUI?

      https://www.theregister.co.uk/2020/02/20/apple_shorter_cert_lifetime/

      TLDR: Safari will, later this year, no longer accept new HTTPS certificates that expire more than 13 months from their creation date.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        Luckily the Let's Encrypt lifetime is ninety-day anyway. ;-)

        -Rico

        1 Reply Last reply Reply Quote 0
        • kiokomanK
          kiokoman LAYER 8
          last edited by

          it's time to ditch safari 😂
          it's funny to see how apple can rule the world

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          NogBadTheBadN 1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by

            BTW: jimp covered how to setup Let's Encrypt for the pfSense GUI in his great Let's Encrypt on pfSense hangout: https://www.netgate.com/resources/videos/lets-encrypt-on-pfsense.html

            -Rico

            1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @kiokoman
              last edited by

              @kiokoman said in Cert Manager:

              it's time to ditch safari 😂
              it's funny to see how apple can rule the world

              I doubt it will just be Apple.

              "Cutting certificate lifetimes has been mulled by Apple, Google, and other members of CA/Browser for months. The policy has its benefits and drawbacks"

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • pfSenseTestP
                pfSenseTest
                last edited by

                Already updated.
                https://redmine.pfsense.org/issues/9825

                2x SG-5100 | MBT-4220 (retired) | SG-1000 (retired)

                jimpJ 1 Reply Last reply Reply Quote 1
                • jimpJ
                  jimp Rebel Alliance Developer Netgate @pfSenseTest
                  last edited by

                  @pfSenseTest said in Cert Manager:

                  Already updated.
                  https://redmine.pfsense.org/issues/9825

                  Yep, we already saw that last week and enacted the lower lifetime. New installs will have the GUI cert set to that lifetime, or you can make a new one when pfSsh.php playback generateguicert if you're on a release or snapshot with the change.

                  Just the GUI cert lifetime change is in 2.4.5, but for 2.5.0 there are more benefits.

                  For example, the GUI has a visible warning when you exceed the limit for a server cert:

                  Selection_200.jpg

                  Plus in 2.5.0 where you can renew a cert in the GUI, there is an option to apply the lower limit at that time.

                  Selection_199.jpg

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 2
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.