Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Admin access on HTTPS

    Scheduled Pinned Locked Moved webGUI
    10 Posts 4 Posters 810 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      ixu1
      last edited by

      pfs 2.44 release p3

      Hello,

      Why i can't use https on my pfsense webui ?

      webui.png

      Alternate hostname is note valid hsotname ..

      Best regards

      JF

      PS: it's fraich install

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        It isn't the HTTPS option to blame there.

        What do you have in the Alternate Hostnames box on that page?

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          Exactly - what do you have in the alternative name box farther down the page

          Here is where its at
          alternatename.jpg

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • I
            ixu1
            last edited by

            wahoo , I'm confused

            it works!

            Thank you so much.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              Confused about what? What did you have in that box?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • I
                ixu1
                last edited by

                an IP !

                1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan
                  last edited by

                  An IP isn't really a host name ;)

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  I 1 Reply Last reply Reply Quote 0
                  • I
                    ixu1 @Gertjan
                    last edited by

                    @Gertjan
                    that's why I'm confused

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan @ixu1
                      last edited by Gertjan

                      @ixu1 said in Admin access on HTTPS:

                      that's why I'm confused

                      Note this one down some where : a name is not a number.

                      Btw : these alternate host name must also be part of your certificate !
                      It's true that some cert authorities accept that you put into your cert alternate host names real IP's like "192.168.1.1". That way, you can access your pfSense like
                      https://192.168.1.1

                      ( and think about an IPv6 while you're ordering your cert ^^ )

                      Note that LetsEncrypts (used by the acme package - or by your own methods) doesn't allow that.

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        Yeah that alternate name is not the same as SAN in the cert.. That is so you don't get rebind or http_referer problems..

                        IP would not be valid there ever..

                        If you want to do rfc1918 IP in your cert, you would have to have your own local CA sign the cert. There is no public CA that would sign a cert with rfc1918 IPs in them..

                        I use san for my rfc1918 address in my web gui.. Where did you get that cert? From a public CA, or did you create the cert with CA you have running on pfsense?

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.