<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Expired Authorities update]]></title><description><![CDATA[<p dir="auto">Hello</p>
<p dir="auto">It might be a simple question, but I don't know how to answer it, so help is appreciated.</p>
<p dir="auto">I have the expired authority</p>
<p dir="auto"><img src="/assets/uploads/files/1728316376321-c5ef2966-d248-4622-8d90-c9e0b4b4380f-image.png" alt="c5ef2966-d248-4622-8d90-c9e0b4b4380f-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">How do I find what 3 certs are using it?</p>
<p dir="auto">And how do I update it?</p>
<p dir="auto">PS:  I don't see much difference in my pfS behavior</p>
<p dir="auto">TIA</p>
]]></description><link>https://forum.netgate.com/topic/190428/expired-authorities-update</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 03:52:08 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/190428.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 07 Oct 2024 15:53:58 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Expired Authorities update on Tue, 08 Oct 2024 06:29:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/chudak">@<bdi>chudak</bdi></a> said in <a href="/post/1187355">Expired Authorities update</a>:</p>
<blockquote>
<p dir="auto">But how do you what certificates it's associated with?</p>
</blockquote>
<p dir="auto">Keep in mind that the pfSense cert store isn't the only one that exists <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title=":blush:" alt="😊" /><br />
Every Pad, Phone, PC, etc every device that makes TLS connections uses a system wide certificate file, here  /usr/local/share/certs/ca-root-nss.crt - see also here /etc/ssl/certs/*</p>
<p dir="auto">You've noticed that the pfSense Certificate store doesn't list all the certs found in /usr/local/share/certs/ca-root-nss.crt and that's good. If people start to mess with that list, thing will go downhill fast.</p>
<p dir="auto">These are all 'auto signed' and are all the CAs that are 'trusted' out of the box. These lists are updated often as new trust chaines are signed (agreed upon) among the wold's ruling CA authorities.<br />
These two folders are used when pfSense <em>connects</em> (as a client) to the (example) upgrade.netgate.com update/upgrade package server.</p>
<p dir="auto">The pfSense Certificate store is a convenient place were the admin can keep the system's local certificates and intermediate certificates for the local <em>server</em> processes.</p>
]]></description><link>https://forum.netgate.com/post/1187395</link><guid isPermaLink="true">https://forum.netgate.com/post/1187395</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Tue, 08 Oct 2024 06:29:56 GMT</pubDate></item><item><title><![CDATA[Reply to Expired Authorities update on Mon, 07 Oct 2024 21:23:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/chudak">@<bdi>chudak</bdi></a> doesn't matter its the CA not the cert.. There is one of the threads <a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> mentioned where I deleted all of my acme CAs - then renewed my certs and it just put back the CAs it needed/wanted.</p>
]]></description><link>https://forum.netgate.com/post/1187383</link><guid isPermaLink="true">https://forum.netgate.com/post/1187383</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 07 Oct 2024 21:23:47 GMT</pubDate></item><item><title><![CDATA[Reply to Expired Authorities update on Mon, 07 Oct 2024 18:04:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1187340">Expired Authorities update</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/chudak">@<bdi>chudak</bdi></a></p>
<p dir="auto">Hey, your late to the party <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title=":blush:" alt="😊" /><br />
Several others threads discuss the 'issue' already.<br />
The solution is simple : delete it.</p>
<p dir="auto">Btw : don't take "delete it" literal.<br />
Of course I also wanted to say : get a pfSense config copy 'in case off'. And then delete it.</p>
</blockquote>
<p dir="auto">OK copy that</p>
<p dir="auto">But how do you what certificates it's associated with?</p>
]]></description><link>https://forum.netgate.com/post/1187355</link><guid isPermaLink="true">https://forum.netgate.com/post/1187355</guid><dc:creator><![CDATA[chudak]]></dc:creator><pubDate>Mon, 07 Oct 2024 18:04:49 GMT</pubDate></item><item><title><![CDATA[Reply to Expired Authorities update on Mon, 07 Oct 2024 16:10:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/chudak">@<bdi>chudak</bdi></a></p>
<p dir="auto">Hey, your late to the party <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title=":blush:" alt="😊" /><br />
Several others threads discuss the 'issue' already.<br />
The solution is simple : delete it.</p>
<p dir="auto">Btw : don't take "delete it" literal.<br />
Of course I also wanted to say : get a pfSense config copy 'in case off'. And then delete it.</p>
]]></description><link>https://forum.netgate.com/post/1187340</link><guid isPermaLink="true">https://forum.netgate.com/post/1187340</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 07 Oct 2024 16:10:19 GMT</pubDate></item></channel></rss>