Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WebConfigurator hands out expired certificate, but in Cert. Manager it seems up-to-date

    webGUI
    2
    8
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      fbmm
      last edited by

      Hello everybody,

      this morning my browser (Chrome) rejected connecting to pfsense's web interface because of an expired certificate. Tried with Firefox, same result. The certificate has expired on 8 May 2021 according to the browsers.

      However, when I log in to pfsense ignorning the certificate error, in the Certificate Manager the certificate seems to be valid and has an expiry date of 8 July 2021.

      Any ideas why web configurator is handing out the expired certificate when actually there is a valid one (that is assigned to web configurator). My searches didn't bring up any similar cases.

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @fbmm
        last edited by

        The selected certificate here System > Advanced > Admin Access IS the certificate that expires 8 July 2021 ?

        Try also console (or SSH) option 11.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        F 1 Reply Last reply Reply Quote 0
        • F
          fbmm @Gertjan
          last edited by

          @gertjan thank you very much. A restart of the web configurator via console option 11 solved the problem immediately. The correct certificate is now showing up.

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @fbmm
            last edited by

            Where did your certificate come from ?

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            F 1 Reply Last reply Reply Quote 0
            • F
              fbmm @Gertjan
              last edited by

              it's a Letsencrypt certificate requested via the ACME package. Worked well so far.

              GertjanG 1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @fbmm
                last edited by

                In that case :

                f1ee4af7-4192-4102-9797-b7d518c2c908-image.png

                is set ?

                What does the acme log file says ?
                It's here : /tmp/acme/[acme-account-name]/acme_issuecert.log
                Ctrl-F this text : "Run reload cmd:" Found it ?

                Look at the file uses by the reloadcmd.sh file :
                It should be here : /tmp/acme/[acme-account-name]/a reloadcmd.sh

                Take note : as the account name is used a a file name / path to a file name, it can not contain every possible character.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                F 1 Reply Last reply Reply Quote 0
                • F
                  fbmm @Gertjan
                  last edited by

                  @gertjan the shell command in the action wasn't set. Don't know how I could miss it. Maybe followed wrong tutorial. Command is set now. Thanks very much for your help!

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @fbmm
                    last edited by

                    @fbmm said in WebConfigurator hands out expired certificate, but in Cert. Manager it seems up-to-date:

                    Maybe followed wrong tutorial

                    There is only one ......

                    Let's Encrypt on pfSense

                    and the guy who wrote the package is explaining it.
                    What do you want more ?

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.