Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot renew or create new cert Godaddy API

    ACME
    2
    6
    306
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cougarmaster
      last edited by

      I am using pfSense 2.7.2 and ACME 0.9_1. My domain is on Godaddy and have no connection to cloudflare but it keeps going there to purge.

      Not valid yet, let's wait for 10 seconds then check the next one.
      [Wed Feb 5 13:44:31 HKT 2025] _p_txtdomain='_acme-challenge.oneiricts.com'
      [Wed Feb 5 13:44:31 HKT 2025] Purging Cloudflare TXT record for domain _acme-challenge.oneiricts.com
      [Wed Feb 5 13:44:31 HKT 2025] POST
      [Wed Feb 5 13:44:31 HKT 2025] _post_url='https://cloudflare-dns.com/api/v1/purge?domain=_acme-challenge.oneiricts.com&type=TXT'
      [Wed Feb 5 13:44:31 HKT 2025] body
      [Wed Feb 5 13:44:31 HKT 2025] _postContentType
      [Wed Feb 5 13:44:31 HKT 2025] Http already initialized.
      [Wed Feb 5 13:44:31 HKT 2025] _CURL='curl --silent --dump-header /tmp/acme/Blackwall/http.header -L -g '
      [Wed Feb 5 13:44:32 HKT 2025] _ret='0'
      [Wed Feb 5 13:44:32 HKT 2025] response='{"msg":"Purge request queued. Please wait a few seconds and verify the request was successful."}'
      [Wed Feb 5 13:44:40 HKT 2025] Let's wait for 10 seconds and check again.

      I could not renew so I deleted all CA for letencrypt it still could not renew. Then I deleted all certs and CA and tried to create new and now it would not. Do I have to reinstall the whole firewall?

      1 Reply Last reply Reply Quote 0
      • C
        cougarmaster
        last edited by

        I think its working now but it will not show starting and expire time nor any indications it is done. Also there are no CA used to make the cert and its private now. The cert works but visually no indication whatsoever.

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @cougarmaster
          last edited by

          @cougarmaster said in Cannot renew or create new cert Godaddy API:

          The cert works but visually no indication whatsoever.

          So you didn't see this ? :

          91393f64-9a93-494f-aa0b-d613a43e4f17-image.png

          @cougarmaster said in Cannot renew or create new cert Godaddy API:

          Do I have to reinstall the whole firewall?

          Never. Just check the settings you've entered. If it doesn't work, there is an error some where. Because you can't see it, this doesn't mean the error isn't there. It is.
          The acme package, or certificate renewal works fine.
          But, the info you've entered must be 100 % correct.
          Also, you have to give the other side (cloudflare, etc) some time so the DNS gets settled.

          Use, for example : 5 minutes :

          c691ea1d-a838-4d76-a006-a403c02c0371-image.png

          Here : a nice example of 'doesn't work' : Unable to delete TXT record - and read until the end ^^

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          C 1 Reply Last reply Reply Quote 0
          • C
            cougarmaster @Gertjan
            last edited by

            @Gertjan Thank you yes it shows now was used to being more immediate sorry for the trouble thanks again.

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @cougarmaster
              last edited by Gertjan

              @cougarmaster

              It is immediate.
              If you use the certificate for the pfSense GUI, and you have the default :

              47399d86-c22c-4208-824f-a81b8817f16e-image.png

              then, after a GUI page reload, you can see - by clicking on the pad lock that indicates a https connection, and you can look at the cert details - that the new certificate is now used.

              edit :

              Or go straight to System > Certificates > Certificates and you see it.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              C 1 Reply Last reply Reply Quote 0
              • C
                cougarmaster @Gertjan
                last edited by

                @Gertjan Yes it is but the GUI still laggs so at least now I know I can use the cert without waiting for GUI to update.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.