<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[ACME 60 day renewal schedule and scheduled Firewall Rule for HTTP &amp; HTTPS allow]]></title><description><![CDATA[<p dir="auto">Hi Team<br />
A month ago I successfully setup the Lets Encrypt ACME certificates for my pfSense edge appliance and some internal servers within. In creating the ACME certs, I added the 60 day auto-renewal.</p>
<p dir="auto">My pfSense appliance doesn't normally allow HTTP and HTTPS connections from the world so i (unsuccessfully) created a Firewall alias to allow HTTP and HTTPS connections from ACME's FQDN's <img src="/assets/uploads/files/1693452662082-screenshot-from-2023-08-31-11-29-29.png" alt="Screenshot from 2023-08-31 11-29-29.png" class=" img-fluid img-markdown" /> I don't think this is thorough enough for Lets Encrypt as manually renewing the certs created LOTS of inbound connections from LOTS of sources in the firewall logs.</p>
<p dir="auto">Option 2: Create a Firewall schedule that allows HTTP and HTTPS inbound connections from the world for the same 60 day / time period. The Firewall schedule has a 15 minute min time period. (the below s/shots are 3 separate pfSense tabs)<br />
<img src="/assets/uploads/files/1693453471810-pfsense-acme-and-firewall-schedule-screenshots.png" alt="pfsense acme and firewall schedule screenshots.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Has anyone had any success doing this -or- are there better ways to accomplish what I'm trying to do? Would I be better off to combine the 2 separate cron job commands into 1 cron job?</p>
]]></description><link>https://forum.netgate.com/topic/182537/acme-60-day-renewal-schedule-and-scheduled-firewall-rule-for-http-https-allow</link><generator>RSS for Node</generator><lastBuildDate>Wed, 12 Aug 2026 02:01:21 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/182537.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 31 Aug 2023 03:49:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to ACME 60 day renewal schedule and scheduled Firewall Rule for HTTP &amp; HTTPS allow on Fri, 01 Sep 2023 15:15:28 GMT]]></title><description><![CDATA[<p dir="auto">Another benefit of using the ACME DNS method is wildcard names. I'd previously been using the http method with my namecheap hosted domain. I could not use their DNS API with my account. I then realised I could switch nameservers, on my namecheap account, to cloudflare and can now use the DNS method with pfSense ACME package.</p>
]]></description><link>https://forum.netgate.com/post/1123598</link><guid isPermaLink="true">https://forum.netgate.com/post/1123598</guid><dc:creator><![CDATA[darcey]]></dc:creator><pubDate>Fri, 01 Sep 2023 15:15:28 GMT</pubDate></item><item><title><![CDATA[Reply to ACME 60 day renewal schedule and scheduled Firewall Rule for HTTP &amp; HTTPS allow on Thu, 31 Aug 2023 14:42:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/josho_sai">@<bdi>Josho_SAI</bdi></a></p>
<p dir="auto">Even for small entities, or even for individuals : use RFC 2136 or something that's close to that.<br />
Most serious ( ? ) domain name registrars offer such a service.</p>
<p dir="auto">It works like this :<br />
It cert renewal time.<br />
Ask Letenscrypt for a random hash.<br />
Place this txt record in the domain name's DNS zone (in the registrar). That's what all these acme dns methods are al about.<br />
Wait for a minute or two to give DNS the time to update the zone over all the DNS slaves.<br />
Then tell Letsencrypt : go ahead, check.<br />
Undo the txt recods.<br />
Get the certificate.<br />
Done.</p>
]]></description><link>https://forum.netgate.com/post/1123416</link><guid isPermaLink="true">https://forum.netgate.com/post/1123416</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Thu, 31 Aug 2023 14:42:55 GMT</pubDate></item><item><title><![CDATA[Reply to ACME 60 day renewal schedule and scheduled Firewall Rule for HTTP &amp; HTTPS allow on Thu, 31 Aug 2023 12:01:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/keyser">@<bdi>keyser</bdi></a><br />
Big organisations wouldn't be using the Let's Encrypt Webroot certificates</p>
]]></description><link>https://forum.netgate.com/post/1123378</link><guid isPermaLink="true">https://forum.netgate.com/post/1123378</guid><dc:creator><![CDATA[Josho_SAI]]></dc:creator><pubDate>Thu, 31 Aug 2023 12:01:22 GMT</pubDate></item><item><title><![CDATA[Reply to ACME 60 day renewal schedule and scheduled Firewall Rule for HTTP &amp; HTTPS allow on Thu, 31 Aug 2023 05:58:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/josho_sai">@<bdi>Josho_SAI</bdi></a> Does ACME cert renewal require inbound HTTP/HTTPS sessions??? I can’t believe that is needed as it would be impossible to handle/allow in bigger organisations.</p>
]]></description><link>https://forum.netgate.com/post/1123337</link><guid isPermaLink="true">https://forum.netgate.com/post/1123337</guid><dc:creator><![CDATA[keyser]]></dc:creator><pubDate>Thu, 31 Aug 2023 05:58:29 GMT</pubDate></item></channel></rss>