Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Let's encrypt CA expired

    Scheduled Pinned Locked Moved ACME
    11 Posts 4 Posters 815 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      emc
      last edited by

      1. Can the "external" expired cert be deleted or will this break things?
      2. If I decide to import the new pem file from Let's encrypt, can you explain how to do it exactly and do all certs in this page need to be replaced or just this one?

      I had installed ACME package, I currently have two certificates and two private keys under the "ACME" section.

      Under System/Certificate Manager/CAs I have four certificates
      f112470c-53e6-45a2-8d77-923aaf8f13eb-image.png

      The second one has expired.
      I searched on other posts, and it seems like you cannot renew that CA from pfSense directly but instead you have to go to Let's encrypt and download the self signed PEM from this page (According to this post https://forum.netgate.com/topic/189937/how-do-i-renew-this-certificate-athority/16): https://letsencrypt.org/certificates/

      d0a48852-0448-4ce4-9c20-f63bea871c79-image.png

      On other posts I've read that it can simply be deleted as it's no longer needed.
      Either way, the expiration for the other CAs are coming eventually and importing files will need to happen.

      Thank you everyone for your help in advanced!

      johnpozJ J GertjanG 3 Replies Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @emc
        last edited by

        @emc My understanding is you could in theory just delete all of those, and next time you run acme if it needs a CA it would just install it.. Or maybe on a reinstall of the package..

        But I wouldn't worry too much, but yeah you can delete that expired CA, you can see on the right there you don't have any certs under that CA being used.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 1
        • J
          jrey @emc
          last edited by jrey

          @emc

          Wait aren't there 3 certs listed against that expired certificate.
          I thought it would auto renew as well, but never seemed to.

          Here is what I did,

          https://forum.netgate.com/topic/189674/certificate-updated-ca-r11-still-pointing-to-isrg-root-x1?_=1727886203715

          and the certificates that where under my expired one immediately move to the new certificate
          then I deleted the old one.

          johnpozJ E 2 Replies Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @jrey
            last edited by johnpoz

            @jrey said in Let's encrypt CA expired:

            Wait aren't there 3 certs listed against that expired certificate.

            where are you seeing that?

            certs.jpg

            I don't see anything.. I see HAProxy using one under that top R3 that expires in sept 2025

            edit.. Oh the 3 there, but they are currently not listed as IN USE.. Maybe he has some old certs too?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            J 1 Reply Last reply Reply Quote 0
            • E
              emc @jrey
              last edited by

              @jrey Is the PEM certificate that I highlighted in the first screenshot the correct one (Certificate details (self-signed))?

              J 1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @emc
                last edited by

                @emc

                Under CA, right ?

                6ed979ed-a992-48ec-b6b6-364e64286644-image.png

                You can ditch (expired Letsencrypt CA's) them.
                If you want the new ones, as these are from Letsecnrypt, do your shopping here :
                Chains of Trust

                Get the two CAs : ISRG Root X1 (if you are a RSA guy) and ISRG Root X2 if you want to go all ECDSA.

                Same thing for the Subordinate (Intermediate) CAs
                Get all the E5/E6 and R10/R11.

                said that : I really guess none of them are really needed to be loaded into the pfSense cert store.
                I'll have to test that : wipe them all, then renew a cert with acme.sh. I'm pretty sure everything keeps on working just fine.

                If things go wrong : yell at me, and get your config backup back in ;)
                I still have to do this test

                Right now, I see this :

                9b821555-7a9e-4401-8aea-328753c5f6b4-image.png

                as my current certs are based upon :

                bb7a6544-208c-4df0-94f2-eafd518336eb-image.png

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 0
                • J
                  jrey @johnpoz
                  last edited by

                  @johnpoz said in Let's encrypt CA expired:

                  Oh the 3 there, but they are currently not listed as IN USE..

                  The "3" would be number of "Certificates" that are chained up to that CA

                  So for example I have a 1 the In Use column is empty on the CA screen and then under Certificates there is 1 that references CA and on that screen the In Use column shows what is using it.

                  My self signed CA for VPN - the CA shows 2 and under the "Certificates" there are 2 certificates that reference it.

                  On my CA list the one with a 2 does not have anything in the "In Use" column either.
                  Screen Shot 2024-10-02 at 1.16.10 PM.png

                  But on the Certificates pages there are 2 "In use" that reference the above CA
                  they also both have values "In Use" on that screen

                  Screen Shot 2024-10-02 at 1.21.32 PM.png

                  So on the certificates screen he likely has 3 certificates referencing that CA.
                  We don't know if they are in use or not because we don't see that screen.

                  In fact I have 3 CA (none have an In Use Value) in the certificates column they total 4 and on the Certificates screen there are well 4 certificates - 1 is not in use (field empty) but it still chains up to a CA - the other 3 all have In use values. 2 of those are the VPN.

                  1 Reply Last reply Reply Quote 0
                  • J
                    jrey @emc
                    last edited by

                    @emc said in Let's encrypt CA expired:

                    Is the PEM certificate that I highlighted in the first screenshot the correct one (Certificate details (self-signed))?

                    Yes

                    make a backup of the config .. πŸ‘

                    https://letsencrypt.org/certificates/

                    just need the pem from that line

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @jrey
                      last edited by

                      @jrey little reason to back them up to be honest.. So I had 3 acme CAs, I deleted them all, and renewed couple of certs I had.. The CAs auto got added back

                      acme.jpg

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      J 1 Reply Last reply Reply Quote 0
                      • J
                        jrey @johnpoz
                        last edited by

                        @johnpoz

                        Interesting - I wonder if is has something to do with:

                        your first screen capture the CA's are E5 E6 R3

                        also notice that your R3 shown in the first CA screen capture isn't in the second screen capture - assume that is after you deleted and renewed and you are showing they came back. (the 2 highlighted)

                        but at the same time the ones that most people are inquiring about with the "problem" are those where on CA the CN = X1 on the authority.

                        now @Gertjan in his screen capture is showing both X1 X2 R10 and R11
                        and that X1 is current 2035 expiry
                        but only the X1 and R10 are chained on that screen. (count 1 each)

                        in my case it is the X1 and R11 the other 2 don't exist.

                        in the op's case he has an R3 not used, and R10 not used
                        and an expired X1 and valid R11.

                        So maybe the X1 renewal is the issue. I just did it manually and it's fine. I guess we could experiment more - but it works so ...

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @jrey
                          last edited by johnpoz

                          @jrey its doesn't need cas you don't have off of... My point was just delete them if they are expired.. And CAs that acme needs to renew your certs will just get added back anyway.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.