• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Cipher missing from server post Server Certificate renewal

Scheduled Pinned Locked Moved OpenVPN
28 Posts 4 Posters 2.3k Views 4 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P Offline
    prashant.joshi @NightlyShark
    last edited by Mar 18, 2024, 9:30 AM

    @NightlyShark in my case cert shows properly renewed.

    Another thing I tried to save server settings it's giving me the "One or more of the selected Data Encryption Algorithms is not valid." error

    N 2 Replies Last reply Mar 18, 2024, 9:35 AM Reply Quote 0
    • N Offline
      NightlyShark @prashant.joshi
      last edited by NightlyShark Mar 18, 2024, 9:40 AM Mar 18, 2024, 9:35 AM

      @prashant-joshi That means that when renewing the cert you changed ciphers and now it gets all confused. Just delete, both the cert and the server profile, and recreate. Unless there is a Gateway or a custom OpenVPN interface (for the fw rules) involved, then just try to delete the cert.

      P 1 Reply Last reply Mar 18, 2024, 10:05 AM Reply Quote 0
      • N Offline
        NightlyShark @prashant.joshi
        last edited by Mar 18, 2024, 9:41 AM

        @prashant-joshi Also, check out the logs for OpenVPN.

        1 Reply Last reply Reply Quote 0
        • P Offline
          prashant.joshi @NightlyShark
          last edited by Mar 18, 2024, 10:05 AM

          @NightlyShark when I am trying to add new server still the left side Cipher is blank.

          alt text

          N 1 Reply Last reply Mar 18, 2024, 10:06 AM Reply Quote 0
          • N Offline
            NightlyShark @prashant.joshi
            last edited by Mar 18, 2024, 10:06 AM

            @prashant-joshi You need to select a certificate, first :)

            P 1 Reply Last reply Mar 18, 2024, 10:10 AM Reply Quote 0
            • P Offline
              prashant.joshi @NightlyShark
              last edited by Mar 18, 2024, 10:10 AM

              @NightlyShark Even after selecting the server Cert nothing changed. Still the left side is missing and blank.

              N 2 Replies Last reply Mar 18, 2024, 10:16 AM Reply Quote 0
              • N Offline
                NightlyShark @prashant.joshi
                last edited by NightlyShark Mar 18, 2024, 10:16 AM Mar 18, 2024, 10:16 AM

                @prashant-joshi Friend, I am this close to asking a stranger(you) to let me AnyDesk this...

                1 Reply Last reply Reply Quote 0
                • N Offline
                  NightlyShark @prashant.joshi
                  last edited by Mar 18, 2024, 10:17 AM

                  @prashant-joshi At this point of the head-scratching process, I would reinstall (remove and install) the OpenVPN package manually via cli.

                  1 Reply Last reply Reply Quote 0
                  • J Offline
                    johnpoz LAYER 8 Global Moderator @Gertjan
                    last edited by Mar 18, 2024, 11:10 AM

                    @Gertjan are you really on 23.05.1 ? I would move to current supported version 23.09.1 - there has been multiple changes, big one is jump to open ssl3, and I know the openvpn version has also been updated.

                    23.05.1 is no longer on the supported list.

                    If it was me, I would upgrade to current, and if your certs are still not working... Create new..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07 | Lab VMs 2.8, 25.07

                    N G 2 Replies Last reply Mar 18, 2024, 1:20 PM Reply Quote 1
                    • N Offline
                      NightlyShark @johnpoz
                      last edited by NightlyShark Mar 18, 2024, 1:26 PM Mar 18, 2024, 1:20 PM

                      @johnpoz We tried TS via anydesk (as securely as possible...) and in the end, it was throwing the "libssl.so.30 not found" error. In about 3 hours (when their workplace will empty) they will attempt the update.

                      I wonder why I was spared from that when I updated, with my 2+ year old certs... Maybe because I have everything ECDSA.

                      J G 2 Replies Last reply Mar 18, 2024, 2:03 PM Reply Quote 0
                      • J Offline
                        johnpoz LAYER 8 Global Moderator @NightlyShark
                        last edited by Mar 18, 2024, 2:03 PM

                        @NightlyShark said in Cipher missing from server post Server Certificate renewal:

                        ECDSA

                        I am pretty much exclusively using those.. I just created a couple for my new cams I got.. I might have some older but have started using those for the last few years.. And using those for my openvpn stuff.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07 | Lab VMs 2.8, 25.07

                        N 2 Replies Last reply Mar 18, 2024, 2:55 PM Reply Quote 1
                        • N Offline
                          NightlyShark @johnpoz
                          last edited by NightlyShark Mar 19, 2024, 12:15 PM Mar 18, 2024, 2:55 PM

                          @johnpoz And... a little bird told me that the only secure curve that was not recommended by certain people that are known to be allergic to public encryption (caugh, PRISM!, caugh) was secp521r1...

                          1 Reply Last reply Reply Quote 0
                          • N Offline
                            NightlyShark @johnpoz
                            last edited by Mar 18, 2024, 2:56 PM

                            @johnpoz That little bird is google, ok? hahaha

                            1 Reply Last reply Reply Quote 0
                            • G Online
                              Gertjan @NightlyShark
                              last edited by Mar 18, 2024, 2:59 PM

                              @NightlyShark said in Cipher missing from server post Server Certificate renewal:

                              "libssl.so.30 not found"

                              That's your system telling you : don't stay on older versions of pfSense. Upgrade to the actual version (23.09.1) asap and you'll be fine.
                              And note somewhere for the future : "never ever upgrade / install / 'do things with' packages before you've upgrade pfSense to the latest available version first".

                              No "help me" PM's please. Use the forum, the community will thank you.
                              Edit : and where are the logs ??

                              N 1 Reply Last reply Mar 18, 2024, 3:02 PM Reply Quote 0
                              • N Offline
                                NightlyShark @Gertjan
                                last edited by NightlyShark Mar 18, 2024, 3:03 PM Mar 18, 2024, 3:02 PM

                                @Gertjan It's not my system... Not my thread, even. I just talk too much, hahaha.

                                1 Reply Last reply Reply Quote 0
                                • G Online
                                  Gertjan @johnpoz
                                  last edited by Mar 18, 2024, 3:06 PM

                                  @johnpoz said in Cipher missing from server post Server Certificate renewal:

                                  @Gertjan are you really on 23.05.1 ?

                                  Me ? Your kidding. 23.05.1 was ok, probably, I don't remember, 23.09.1 is pretty rock solid (for me). "VPN" (server) works well.
                                  My bird says : if update is available, let the dust settle for a couple of days, and then click : upgrade.

                                  Btw : I've still my 10 years certs in service :

                                  1b570479-9c60-47e0-a205-57acb81393fe-image.png

                                  Total Lifetime: 3650 days
                                  Lifetime Remaining: 1027 days until expiration

                                  These were the less secure days I guess ...

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  P 1 Reply Last reply Mar 19, 2024, 12:00 PM Reply Quote 0
                                  • P Offline
                                    prashant.joshi @Gertjan
                                    last edited by Mar 19, 2024, 12:00 PM

                                    @Gertjan @NightlyShark Thanks for your support and advice. Post version upgrade the issue was resolved.

                                    Things are in control now and working well...

                                    Once again thank you everyone.....

                                    1 Reply Last reply Reply Quote 1
                                    28 out of 28
                                    • First post
                                      28/28
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                      This community forum collects and processes your personal information.
                                      consent.not_received