Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Wildcard domain renewal fails

    Scheduled Pinned Locked Moved ACME
    7 Posts 2 Posters 637 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BoabB
      Boab
      last edited by

      My problem is everyday pfsense 2.7.1 / acme 0.7.5 sends me a message like this:-

      Notifications in this message: 1

      03:01:00 The following CA/Certificate entries are expiring:
      Certificate: star.example.com (6571dca5067ae): Expiring soon, in 14 days

      I am trying to renew example.com and *.example.com with letsencrypt. When I press Issue/Renew I get a new certificate for the next 90 days which works, tested/examined on www.example.com.
      I am coming to the end of first 90 day certificate, so this is my first real renewal. I have also received expiry notices from letsencrypt but not all that frequent.

      I am configured with only one certificate with ‘Domain SAN list’ of example.com and *.example.com the DNS update mechanism works as lets encrypt issues new working certificates.

      No I'm not really trying to renew example.com, simply replaced the real domain. pfsense uses word star i use *.

      HELP!!!

      pfsense trace removed as submit refused as spam

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @Boab
        last edited by Gertjan

        @Boab said in Wildcard domain renewal fails:

        I am coming to the end of first 90 day certificate, so this is my first real renewal. I have also received expiry notices from letsencrypt but not all that frequent.

        That's why this default value exists :

        274f0f9f-6dcb-4b3d-b58a-0e6e0e23f11a-image.png

        If something fails, you have 30 days to find the solution.
        Didn't know that LE sends mails to warn you for a soon-to-expire certificate - that's a nice of them.

        I also have a domain name that I use to with acme, and I renew it as a wild card :
        This means I have to entries :
        "domain.tld" and *.domain.tld" :

        b67b3f66-97d0-4202-ae72-e4707ecf9c2d-image.png

        If the renewal goes wrong, do what the 'error' message said, somewhere at the bottom : look at the acme log file, it will contain the message that tells why it fails.
        Its shows you where you can find it :
        /tmp/acme/[your-domaine-here.tld]/ and in that folder you'll find the very detailed log file acme_issuecert.log

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        BoabB 1 Reply Last reply Reply Quote 0
        • BoabB
          Boab @Gertjan
          last edited by

          @Gertjan Thanks for the reply.
          I have renewal set for 60 days and have been getting the emails for the last two weeks.
          My table looks like yours but I don't have the Zone entry - will try that.
          I don't see any obvious error message all appears to complete as expected

          here are the last few line which I hope will get thru the spam filter:-
          -----END CERTIFICATE-----
          [Sat Feb 17 19:14:14 GMT 2024] Your cert is in: /tmp/acme/example.com/example.com/example.com.cer
          [Sat Feb 17 19:14:14 GMT 2024] Your cert key is in: /tmp/acme/example.com/example.com/example.com.key
          [Sat Feb 17 19:14:14 GMT 2024] The intermediate CA cert is in: /tmp/acme/example.com/example.com/ca.cer
          [Sat Feb 17 19:14:14 GMT 2024] And the full chain certs is there: /tmp/acme/example.com/example.com/fullchain.cer
          [Sat Feb 17 19:14:14 GMT 2024] Your pre-generated next key for future cert key change is in: /tmp/acme/example.com/example.com/example.com.key.next
          [Sat Feb 17 19:14:14 GMT 2024] Run reload cmd: /tmp/acme/example.com/reloadcmd.sh

          IMPORT CERT example.com, /tmp/acme/example.com/example.com/example.com.key, /tmp/acme/example.com/example.com/example.com.cer
          update cert![Sat Feb 17 19:14:14 GMT 2024] Reload success

          BoabB GertjanG 2 Replies Last reply Reply Quote 0
          • BoabB
            Boab @Boab
            last edited by

            @Boab first attempt at pastebin...
            https://pastebin.com/WgkpgNTR

            BoabB 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @Boab
              last edited by Gertjan

              @Boab said in Wildcard domain renewal fails:

              -----END CERTIFICATE-----
              [Sat Feb 17 19:14:14 GMT 2024] Your cert is in: /tmp/acme/example.com/example.com/example.com.cer
              [Sat Feb 17 19:14:14 GMT 2024] Your cert key is in: /tmp/acme/example.com/example.com/example.com.key
              [Sat Feb 17 19:14:14 GMT 2024] The intermediate CA cert is in: /tmp/acme/example.com/example.com/ca.cer
              [Sat Feb 17 19:14:14 GMT 2024] And the full chain certs is there: /tmp/acme/example.com/example.com/fullchain.cer
              [Sat Feb 17 19:14:14 GMT 2024] Your pre-generated next key for future cert key change is in: /tmp/acme/example.com/example.com/example.com.key.next
              [Sat Feb 17 19:14:14 GMT 2024] Run reload cmd: /tmp/acme/example.com/reloadcmd.sh

              IMPORT CERT example.com, /tmp/acme/example.com/example.com/example.com.key, /tmp/acme/example.com/example.com/example.com.cer
              update cert![Sat Feb 17 19:14:14 GMT 2024] Reload success

              Looks fine to me.

              You have this :

              fabbc4c1-9bf6-4959-a397-87a506db7a6f-image.png

              so the web server instances on pfSense restart with the new certificate ?

              Did you check the certificate under System > Certificates > Certificates ?
              It should have a Valid from date on last February 17.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 1
              • BoabB
                Boab @Boab
                last edited by Boab

                @Boab pfsense-acme.jpg

                I think i may have spotted it.
                The top entry, when you look at the info covers my domain and * my domain.
                The bottom entry looks a bit strange and probably should be deleted, it may have been hanging around since i was initially setting up acme!

                Sins coming back to bite you...

                Thank you Gertjan for guiding me to it - I spent many hours struggling with this before asking on the forum.

                GertjanG 1 Reply Last reply Reply Quote 1
                • GertjanG
                  Gertjan @Boab
                  last edited by

                  @Boab

                  You have a wild card, so you can probably delete de start dot domain.tld as it is going out of businesses anyway.

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  1 Reply Last reply Reply Quote 1
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.