Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cant sign CSR - "Please select a valid Digest Algorithm."

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 2 Posters 464 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      EcceVery
      last edited by

      I'm using a pfSense VM as a small CA for a lab environment. It has worked fine for a year but now I've run intro trouble. The CA certificate is created on the same pfsense machine and kept there. I've used it to sign various stuff in my lab environment, server certificates mostly. I've created a CSR on a esxi host machine, but when signing it it says:

      The following input errors were detected:

      • Please select a valid Digest Algorithm.

      The default selection is SHA256, and it does not matter what I choose in the list, I still get that same error. If I try to click "Save" again it just gives up and send me back to the list of certificates already created.

      I'm not sure what log file to look in for this... I've looked around in various files in /var/log to get a clue, but so far I've got nothing. I've found a few bug reports similar to this when googling, but not exactly like my case.

      Ideas? :)

      pfSense is 2.4.4-RELEASE-p1 (amd64)

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by johnpoz

        I do recall a bug, thought it was corrected.. I would upgrade to p2..

        Found it.
        https://redmine.pfsense.org/issues/9180

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 1
        • E
          EcceVery
          last edited by EcceVery

          @johnpoz said in Cant sign CSR - "Please select a valid Digest Algorithm.":

          https://redmine.pfsense.org/issues/9180

          I found that one to, but to me it happens no matter what algoritm I choose, not just SHA512. But I didn't see the target version 2.4.4_2 there.... I'll upgrade and test again.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            Yeah its listed as fixed in the release notes for p2 as well
            https://docs.netgate.com/pfsense/en/latest/releases/2-4-4-p2-new-features-and-changes.html
            Fixed input validation that rejected certain valid hash algorithms when signing a CSR #9180

            If still have issues - come on back and try and I'll try and duplicate, and can reopen that or create a new redmine.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 1
            • E
              EcceVery
              last edited by

              Upgrade fixed it! Thanks.

              Impressive response time. 3 minutes. :)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.