Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Shell Command actions

    Scheduled Pinned Locked Moved ACME
    3 Posts 2 Posters 459 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pgb
      last edited by

      I'm generating a wildcard certificate in a pfSense box that acts as a reverse proxy. When I access the servers in the LAN, each server should serve using the same wildcard certificate as when accessing externally.

      So whenever I regenerate the certificate, I need to distribute it internally to a few servers on my LAN.

      Is there a way to access the certificate chain just generated from a Shell Command action? Do Shell Command actions receive any parameter that I can use to access the certificate?

      My plan is to keep the key a shared secret in all the servers, and push the upload the certificate to an internal git repository each server will be monitoring for changes, to get the fresh copy of the certificate periodically.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Not exactly. What you probably want is to enable Write Certificates on the General Settings tab. Then you can copy the certificates from /conf/acme on the firewall off to wherever you want. Or, better yet, have the servers fetch them via scp or similar function.

        Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        P 1 Reply Last reply Reply Quote 1
        • P
          pgb @jimp
          last edited by

          @jimp I completely missed that setting! Thank you!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.