<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CA cert renew]]></title><description><![CDATA[<p dir="auto">Hi.</p>
<p dir="auto">In GUI I have option to renew CA cert. But I can`t select for how long, it takes current valid period and just use that. <strong>How can I renew CA cert with same key and serial but for 20 years?</strong></p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/topic/198837/ca-cert-renew</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 19:05:48 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/198837.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 22 Sep 2025 06:12:33 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to CA cert renew on Mon, 22 Sep 2025 07:34:07 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/maverick_slo">@<bdi>maverick_slo</bdi></a></p>
<p dir="auto">Noop.<br />
I said : I can <em>image</em> and gave some examples. Only had a coffee or two this morning.<br />
Look at what has changed over the last 10 years.<br />
Chances are that things keep on changing. Our VPN needs will change also.</p>
<p dir="auto">Another example : 4096 bits deep CA/certs will do the job nicely today. It's secure enough. Then a major AI / quantum technology breakthrough will make this "4096" encryption way to dangerous.<br />
Like : "RSA" will fade away, it must be "ECDSA" or whatever will be invented in a near future.<br />
Your bet is : this won't happen in the next 10++ years.<br />
And I hope your right, but I won't place any bets on it though. The contrary will probably happen, as this is what the past told me.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/maverick_slo">@<bdi>maverick_slo</bdi></a> said in <a href="/post/1226253">CA cert renew</a>:</p>
<blockquote>
<p dir="auto">Openvpn is being ditched by Netgate?</p>
</blockquote>
<p dir="auto">Like this : OpenVPN is open source today. Like MySQL was in the past, and Javascript.<br />
Then it get sold to some company - and now it needs to get monetized = you have to pay for it.<br />
In that case "OpenVPN" will most probably lose it's place into a product like pfSense.</p>
<p dir="auto">Your 10+ scale is, for me, a huge time scale when you deal with security software.</p>
<p dir="auto">edit : but were getting off topic here.<br />
Your question isn't that special actually. I'm pretty sure it has been asked before.<br />
Dig (search) into this forum, and you will find equivalent question and more meaning full answers.</p>
]]></description><link>https://forum.netgate.com/post/1226254</link><guid isPermaLink="true">https://forum.netgate.com/post/1226254</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 22 Sep 2025 07:34:07 GMT</pubDate></item><item><title><![CDATA[Reply to CA cert renew on Mon, 22 Sep 2025 07:17:20 GMT]]></title><description><![CDATA[<p dir="auto">Umm, what?</p>
<p dir="auto">Openvpn is being diched by Netgate? OpenVPN is not opensource?<br />
Major bugs and security flaws?</p>
<p dir="auto">What? Are you high right now?</p>
]]></description><link>https://forum.netgate.com/post/1226253</link><guid isPermaLink="true">https://forum.netgate.com/post/1226253</guid><dc:creator><![CDATA[maverick_slo]]></dc:creator><pubDate>Mon, 22 Sep 2025 07:17:20 GMT</pubDate></item><item><title><![CDATA[Reply to CA cert renew on Mon, 22 Sep 2025 07:02:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/maverick_slo">@<bdi>maverick_slo</bdi></a></p>
<p dir="auto">I was hoping that you wouldn't add that detail : "a main OpenVPN certs and loads of users access certs based upon it" ^^</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/maverick_slo">@<bdi>maverick_slo</bdi></a> said in <a href="/post/1226250">CA cert renew</a>:</p>
<blockquote>
<p dir="auto">and I really don`t want to do this change every 10 years...</p>
</blockquote>
<p dir="auto">Euh lol, 4 times in your admin career is to much ?<br />
Don't worry, it guess that over that time span, "OpenVPN" is something of the past, and you already had to set up another type of VPN several times, for the 'known' (that I can image today) reasons : major bugs, security flaws, trends, Netgate ditching it because not opensource anymore, etc etc</p>
]]></description><link>https://forum.netgate.com/post/1226252</link><guid isPermaLink="true">https://forum.netgate.com/post/1226252</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 22 Sep 2025 07:02:02 GMT</pubDate></item><item><title><![CDATA[Reply to CA cert renew on Mon, 22 Sep 2025 06:43:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a><br />
This is for OpenVPN...</p>
<p dir="auto">We have like 400+ clients on PC, MAC, Android and Iphones and I really don`t want to do this change every 10 years...</p>
]]></description><link>https://forum.netgate.com/post/1226250</link><guid isPermaLink="true">https://forum.netgate.com/post/1226250</guid><dc:creator><![CDATA[maverick_slo]]></dc:creator><pubDate>Mon, 22 Sep 2025 06:43:46 GMT</pubDate></item><item><title><![CDATA[Reply to CA cert renew on Mon, 22 Sep 2025 06:26:15 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/maverick_slo">@<bdi>maverick_slo</bdi></a></p>
<p dir="auto">Can't tell why you can't change most of the CA  details when you renew.<br />
Maybe renewal renews with most or all of the details identical.</p>
<p dir="auto"><img src="/assets/uploads/files/1758522167697-8fc636fe-3d8d-4912-bb2f-9aa7b17bfb5d-image.png" alt="8fc636fe-3d8d-4912-bb2f-9aa7b17bfb5d-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">But what about creating a new one ?<br />
Afterwards, base of this CA a new cert, use it wherever you need it and call it a day ... no ... 7300 days.</p>
<p dir="auto">Btw : more thoughts : do browser accept certs that are valid that long ? It goes, imho, against security lines.</p>
]]></description><link>https://forum.netgate.com/post/1226249</link><guid isPermaLink="true">https://forum.netgate.com/post/1226249</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 22 Sep 2025 06:26:15 GMT</pubDate></item></channel></rss>