<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How to generate a CSR with pfsense [SOLVED]]]></title><description><![CDATA[<p dir="auto">**Hello,<br />
I want to use an external certificate for the pfSense captive portal<br />
I buy SSL positive (By comodo) for the domain name electropro4545.click (which I own)<br />
Following my purchase I received an e-mail asking me to log in to my account and submit the CSR to get my SSL certificate.<br />
But a missing element is the ability of the pfSense Certification Authority to sign externally generated Certificate Signing Requests (CSRs).<br />
How to generate a CSR with pfsense</p>
<p dir="auto">thanks for the answers**</p>
]]></description><link>https://forum.netgate.com/topic/128077/how-to-generate-a-csr-with-pfsense-solved</link><generator>RSS for Node</generator><lastBuildDate>Sun, 07 Jun 2026 07:28:08 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/128077.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 11 Mar 2018 18:01:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How to generate a CSR with pfsense [SOLVED] on Wed, 14 Mar 2018 10:04:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a>:</p>
<blockquote>
<p dir="auto">You used the test facilities of Letsenscrypt.<br />
That explains the "Fake Intermediate X1" certificate.<br />
Generating these certificates is ok, for testing purposes. You can ask as many as you want - but they will not be trusted.</p>
<p dir="auto">Goto Services =&gt; Acme Certificate =&gt; Account keys, edit your certificate and select for "Acme Server" this "Let's Encrypt Production acme V1 (Applies rate limits to certificate requests".</p>
</blockquote>
<p dir="auto">thanks to you I solved the problem, I learned a lot of things<br />
Thank you</p>
<p dir="auto">![Sans titre-2.jpg](/public/<em>imported_attachments</em>/1/Sans titre-2.jpg)<br />
![Sans titre-2.jpg_thumb](/public/<em>imported_attachments</em>/1/Sans titre-2.jpg_thumb)<br />
![Sans titre-1.jpg](/public/<em>imported_attachments</em>/1/Sans titre-1.jpg)<br />
![Sans titre-1.jpg_thumb](/public/<em>imported_attachments</em>/1/Sans titre-1.jpg_thumb)</p>
]]></description><link>https://forum.netgate.com/post/755062</link><guid isPermaLink="true">https://forum.netgate.com/post/755062</guid><dc:creator><![CDATA[fmohcine26]]></dc:creator><pubDate>Wed, 14 Mar 2018 10:04:19 GMT</pubDate></item><item><title><![CDATA[Reply to How to generate a CSR with pfsense [SOLVED] on Mon, 12 Mar 2018 20:52:18 GMT]]></title><description><![CDATA[<p dir="auto">You used the test facilities of Letsenscrypt.<br />
That explains the "Fake Intermediate X1" certificate.<br />
Generating these certificates is ok, for testing purposes. You can ask as many as you want - but they will not be trusted.</p>
<p dir="auto">Goto Services =&gt; Acme Certificate =&gt; Account keys, edit your certificate and select for "Acme Server" this "Let's Encrypt Production acme V1 (Applies rate limits to certificate requests".</p>
]]></description><link>https://forum.netgate.com/post/755022</link><guid isPermaLink="true">https://forum.netgate.com/post/755022</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 12 Mar 2018 20:52:18 GMT</pubDate></item><item><title><![CDATA[Reply to How to generate a CSR with pfsense [SOLVED] on Mon, 12 Mar 2018 18:59:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a>:</p>
<blockquote>
<p dir="auto">When you use "acme", a CSR is generated and you can find it here :<br />
/tmp/acme/domain/domain/domain.csr</p>
<p dir="auto">Did you understand that when you use "acme" you do not need to use "SSL positive (By comodo)" anymore ?</p>
<p dir="auto">The acme package generates with the help of Letenscrypt certificates for free.</p>
</blockquote>
<p dir="auto">Thank you very much,<br />
I canceled the purchase of the positive certificate, however, the certificates generated by LetsEncrypte are not validated by the browser as if they were self-signed by pfsense<br />
Here are some details about the certificate obtained<br />
certificate information: Can not verify this certificate with a trusted certificate authority<br />
certification path:<br />
This root CA certificate is not trusted because it is not part of the Trusted Root Certification Authority store.<br />
screenshots showing more details on the certificate<br />
big thanks to you</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/Certificatjpg.jpg" alt="Certificatjpg.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Certificatjpg.jpg_thumb" alt="Certificatjpg.jpg_thumb" class=" img-fluid img-markdown" /><br />
![emeeteur certificat.jpg](/public/<em>imported_attachments</em>/1/emeeteur certificat.jpg)<br />
![emeeteur certificat.jpg_thumb](/public/<em>imported_attachments</em>/1/emeeteur certificat.jpg_thumb)<br />
<img src="/public/_imported_attachments_/1/details.jpg" alt="details.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/details.jpg_thumb" alt="details.jpg_thumb" class=" img-fluid img-markdown" /><br />
![chemin d'accès de certificat.jpg](/public/<em>imported_attachments</em>/1/chemin d'accès de certificat.jpg)<br />
![chemin d'accès de certificat.jpg_thumb](/public/<em>imported_attachments</em>/1/chemin d'accès de certificat.jpg_thumb)<br />
![chemin d'accès de certificaXt.jpg](/public/<em>imported_attachments</em>/1/chemin d'accès de certificaXt.jpg)<br />
![chemin d'accès de certificaXt.jpg_thumb](/public/<em>imported_attachments</em>/1/chemin d'accès de certificaXt.jpg_thumb)<br />
![etat de certificat.jpg](/public/<em>imported_attachments</em>/1/etat de certificat.jpg)<br />
![etat de certificat.jpg_thumb](/public/<em>imported_attachments</em>/1/etat de certificat.jpg_thumb)<br />
![The connection is not secure1.jpg](/public/<em>imported_attachments</em>/1/The connection is not secure1.jpg)<br />
![The connection is not secure1.jpg_thumb](/public/<em>imported_attachments</em>/1/The connection is not secure1.jpg_thumb)</p>
]]></description><link>https://forum.netgate.com/post/755006</link><guid isPermaLink="true">https://forum.netgate.com/post/755006</guid><dc:creator><![CDATA[fmohcine26]]></dc:creator><pubDate>Mon, 12 Mar 2018 18:59:03 GMT</pubDate></item><item><title><![CDATA[Reply to How to generate a CSR with pfsense [SOLVED] on Mon, 12 Mar 2018 12:54:37 GMT]]></title><description><![CDATA[<p dir="auto">When you use "acme", a CSR is generated and you can find it here :<br />
/tmp/acme/domain/domain/domain.csr</p>
<p dir="auto">Did you understand that when you use "acme" you do not need to use "SSL positive (By comodo)" anymore ?</p>
<p dir="auto">The acme package generates with the help of Letenscrypt certificates for free.</p>
]]></description><link>https://forum.netgate.com/post/754922</link><guid isPermaLink="true">https://forum.netgate.com/post/754922</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 12 Mar 2018 12:54:37 GMT</pubDate></item><item><title><![CDATA[Reply to How to generate a CSR with pfsense [SOLVED] on Mon, 12 Mar 2018 12:01:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a>:</p>
<blockquote>
<p dir="auto">Hi,</p>
<p dir="auto">Openssl is present, enter console, option 8.<br />
Then you have access to the command "openssl".<br />
How to generate a CRS file, see doc from comodo or even openssl. This is not pfSense related.</p>
<p dir="auto">But, why do this the manual way ?? pfSense has a package called acme - it can handle all the details for you.<br />
All you need is a domain name that you own - and you have it.</p>
<p dir="auto">And why posting your question in the Captive portal section ?<br />
<strong>And why posting like this ?</strong></p>
</blockquote>
<p dir="auto">I am sorry<br />
thank you very much for your help,<br />
With ACME, I managed to generate CRT, Exchange of personal information (.p12) and kye file but no CSR.<br />
I should transfer my question to the apropriate section</p>
]]></description><link>https://forum.netgate.com/post/754911</link><guid isPermaLink="true">https://forum.netgate.com/post/754911</guid><dc:creator><![CDATA[fmohcine26]]></dc:creator><pubDate>Mon, 12 Mar 2018 12:01:58 GMT</pubDate></item><item><title><![CDATA[Reply to How to generate a CSR with pfsense [SOLVED] on Sun, 11 Mar 2018 20:57:38 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">Openssl is present, enter console, option 8.<br />
Then you have access to the command "openssl".<br />
How to generate a CRS file, see doc from comodo or even openssl. This is not pfSense related.</p>
<p dir="auto">But, why do this the manual way ?? pfSense has a package called acme - it can handle all the details for you.<br />
All you need is a domain name that you own - and you have it.</p>
<p dir="auto">And why posting your question in the Captive portal section ?<br />
<strong>And why posting like this ?</strong></p>
]]></description><link>https://forum.netgate.com/post/754834</link><guid isPermaLink="true">https://forum.netgate.com/post/754834</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Sun, 11 Mar 2018 20:57:38 GMT</pubDate></item></channel></rss>