<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Let&#x27;s Encrypt &amp; ACME]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I have letsencrypt setup as CA within "Account Keys"</p>
<p dir="auto">I can successfully acquire a certificate when setting :</p>
<ul>
<li>Domainname to "<strong>domain.com</strong>" and</li>
<li>Method to "<strong>DNS-NSupdate / RFC 2136</strong>"</li>
</ul>
<p dir="auto">Yet, when logging into pfsense, the certificate warning "<strong>NET::ERR_CERT_COMMON_NAME_INVALID</strong>" is raised.</p>
<p dir="auto">However, setting the <strong>Domainname</strong> to the <strong>FQDN</strong> of the appliance, i.e. <strong>pfsense.domain.com</strong>, an Issue/Renew of the certificate results in:</p>
<pre><code>**[@time] adding _acme-challenge.pfsense.domain.com. 60 in txt "YOyoIfeZKqvNzBTVPI"
; TSIG error with server: tsig indicates error
update failed: NOTAUTH(BADKEY)
[@time] error updating domain
[@time] Error add txt for domain:_acme-challenge.pfsense.domain.com
</code></pre>
<p dir="auto">Simply changing the Domainname from "<strong>pfsense.domain.com</strong>" to "<strong>domain.com</strong>" and the certificate is once again issued successfully, yet with an invalid CN.</p>
<p dir="auto">Is "<strong>_acme-challenge.pfsense</strong>" seen as a subdomain of "<strong>domain.com</strong>" whereby BIND 9.10.3 then doesn't allow updating of the <strong>domain.com</strong> zone regardless of the correct key being specified for the domain?...</p>
<p dir="auto">I'm a bit lost on this one. Any help will be greatly appreciated.</p>
<p dir="auto">Thanks</p>
]]></description><link>https://forum.netgate.com/topic/143541/let-s-encrypt-acme</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 19:14:06 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/143541.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 21 May 2019 03:41:23 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Let&#x27;s Encrypt &amp; ACME on Tue, 28 May 2019 21:48:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/peek">@<bdi>Peek</bdi></a> said in <a href="/post/844231">Let's Encrypt &amp; ACME</a>:</p>
<blockquote>
<p dir="auto">_acme-challenge.pfsense.domain.com</p>
</blockquote>
<p dir="auto">What about asking for a wildcard cert for root "domain.com" ?<br />
Using<br />
domain.com<br />
and<br />
*.domain.com<br />
(twice) as "Domainname".</p>
<p dir="auto">You can use pfsense.domain.com, another.domain.com and something-else.domain.com, they will all 'work'.</p>
<p dir="auto">edit : btw :<br />
_acme-challenge.pfsense.domain.com<br />
is a sub domain do shouldn't exist already. It's just a 'random' place holder, so the acme check server can test for a TXT filed in "_acme-challenge.pfsense.domain.com" - which should contain the "VTTcvhklvFWaDrbJc" phrase. This proves that you control the domain "domain.com", thus the certificate can be handed over to you.</p>
]]></description><link>https://forum.netgate.com/post/845528</link><guid isPermaLink="true">https://forum.netgate.com/post/845528</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Tue, 28 May 2019 21:48:55 GMT</pubDate></item><item><title><![CDATA[Reply to Let&#x27;s Encrypt &amp; ACME on Wed, 22 May 2019 01:27:58 GMT]]></title><description><![CDATA[<p dir="auto">And then found it !</p>
<p dir="auto">Take note of the difference between the key-file and key-name within the key-file.</p>
]]></description><link>https://forum.netgate.com/post/844234</link><guid isPermaLink="true">https://forum.netgate.com/post/844234</guid><dc:creator><![CDATA[Peek]]></dc:creator><pubDate>Wed, 22 May 2019 01:27:58 GMT</pubDate></item><item><title><![CDATA[Reply to Let&#x27;s Encrypt &amp; ACME on Wed, 22 May 2019 00:16:29 GMT]]></title><description><![CDATA[<p dir="auto">Setting</p>
<p dir="auto">"Key Name" to "<strong>pfsense</strong>" and<br />
"Zone" to "<strong>domain.com</strong>"</p>
<p dir="auto">still tries to create TXT record<br />
<strong>_acme-challenge.pfsense.domain.com</strong><br />
rather than<br />
<strong>pfsense.domain.com</strong></p>
<pre><code>[@time] adding _acme-challenge.pfsense.domain.com. 60 in txt "VTTcvhklvFWaDrbJc"
; TSIG error with server: tsig indicates error
update failed: NOTAUTH(BADKEY)
[@time] error updating domain
[@time] Error add txt for domain:_acme-challenge.pfsense.domain.com
</code></pre>
]]></description><link>https://forum.netgate.com/post/844231</link><guid isPermaLink="true">https://forum.netgate.com/post/844231</guid><dc:creator><![CDATA[Peek]]></dc:creator><pubDate>Wed, 22 May 2019 00:16:29 GMT</pubDate></item></channel></rss>