Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Why do I get these Certificate entries are expiring notifications?

    Scheduled Pinned Locked Moved ACME
    6 Posts 2 Posters 735 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      Flemmingss
      last edited by

      I am running on 2.7.2-RELEASE, and I have for long, maybe years gotten these notifications, all the time ...
      But now I think it is time to get rid of them, maybe anyone here know what they mean?
      d0d9d23a-84a1-4e16-92c9-cb11734c4251-image.png
      Well, I understand it say something is expired, but I don't understand how, I have one cert with two renewal methods (manual and auto). None of them expired.
      c09a2981-a0f5-4df0-8fd5-82573aa88884-image.png

      So, I am not that good with certificates, but what do I do to make this right?
      But they work, no problem there.

      T 1 Reply Last reply Reply Quote 0
      • T
        Tom8 @Flemmingss
        last edited by

        @Flemmingss
        check: System - Certificates - Certificates

        F 1 Reply Last reply Reply Quote 0
        • F
          Flemmingss @Tom8
          last edited by Flemmingss

          @Tom8 Found this:
          137be4a5-6d9d-49b1-bdef-7f415bcaee56-image.png

          Serial: 0
          Signature Digest: RSA-SHA256
          KU: Digital Signature, Key Encipherment
          EKU: TLS Web Server Authentication, IP Security IKE Intermediate
          Key Type: RSA
          Key Size: 2048
          DN: /C=US/ST=State/L=Locality/O=pfSense webConfigurator Self-Signed Certificate/emailAddress=admin@pfSense.localdomain/CN=pfSense-xxx
          Hash: e5fee5e1
          Subject Key ID: xxx
          Authority Key ID: keyid:xxx
          DirName:/C=US/ST=State/L=Locality/O=pfSense webConfigurator Self-Signed Certificate/emailAddress=admin@pfSense.localdomain/CN=pfSense-xxx
          serial:00
          Total Lifetime: 2000 days
          Lifetime Remaining: Expired 286 days ago
          

          Is it safe to just remove the first one? Don't know what that is. Looks like some pfsense-autgenerated thing?

          T 1 Reply Last reply Reply Quote 0
          • T
            Tom8 @Flemmingss
            last edited by

            @Flemmingss
            Don´t remove, just renew it.

            https://forum.netgate.com/topic/171607/webconfigurator-certificate-expiring

            F 1 Reply Last reply Reply Quote 0
            • F
              Flemmingss @Tom8
              last edited by Flemmingss

              @Tom8
              Thanks, certificates looks good now.
              dd307dc4-eca5-4a71-8ac5-cdfba8308d7c-image.png
              But a one entry below authorities looks expired, do you know what that is?
              40629594-3272-4ada-9be9-dd8136a603ce-image.png

              Serial: xxx
              Signature Digest: RSA-SHA256
              KU: Digital Signature, Certificate Sign, CRL Sign
              DN: /C=US/O=Let's Encrypt/CN=Let's Encrypt Authority X3
              Hash: 4f06f81d
              Subject Key ID: xxx
              Authority Key ID: xxx
              Total Lifetime: 1826 days
              Lifetime Remaining: Expired 1101 days ago
              Trust Store: Excluded
              

              maybe I can just delete it as it has zero certs?

              T 1 Reply Last reply Reply Quote 0
              • T
                Tom8 @Flemmingss
                last edited by

                @Flemmingss
                https://forum.netgate.com/topic/161052/let-s-encrypt-certificate-authority-expiring-soon/7

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.