Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to create internal certificate (CA not detected)

    Scheduled Pinned Locked Moved General pfSense Questions
    9 Posts 3 Posters 73 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • lindheL Offline
      lindhe
      last edited by

      I've been trying and failing to create a new certificate for my pfSense system. I'm running 25.07.1 on a Netgate SG-3100. Either I'm completely missing something obvious, or there's a bug at play here.

      First I've created a CA. I tried both with and without checking the box to add it to the system's trust store and also the box to use random numbers. I've also rebooted the machine after creating them, just to be extra sure. This is what they look like:

      Screenshot from 2025-10-17 08-00-06.png

      Yet, I'm unable to use them to create a new certificate. It just says "No internal Certificate Authorities have been defined. An internal CA must be defined in order to create an internal certificate. Create an internal CA." :

      Screenshot from 2025-10-17 08-00-25.png

      If anyone has any ideas on how to solve this, it would be much appreciated.

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        What pfSense version are you testing in?

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG Online
          Gertjan @stephenw10
          last edited by

          @stephenw10

          @lindhe said in Unable to create internal certificate (CA not detected):

          I'm running 25.07.1 on a Netgate SG-3100.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            Doh! ๐Ÿคฆ

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG Online
              Gertjan @stephenw10
              last edited by

              @stephenw10

              Double Doh...

              I'm using 25.07.1 as well (on a 4100) and I can create a CA by entering 'test' and hit the save button :

              71762f99-c4a5-4f36-a388-a77db8b213f4-image.png

              When creating a certificat, I can select/use it :

              9245afdc-e65f-4c8b-9ff5-e53682e490e4-image.png

              so not sure about what is going on.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • stephenw10S Offline
                stephenw10 Netgate Administrator
                last edited by

                Yup works for me too on a 3100. Must be something invalid about that CA. Dates out of range perhaps?

                lindheL 1 Reply Last reply Reply Quote 0
                • lindheL Offline
                  lindhe @stephenw10
                  last edited by

                  @stephenw10 said in Unable to create internal certificate (CA not detected):

                  Dates out of range perhaps?

                  Good suggestion. I tried 365 days instead of the default 3650 days for the CA, but same effect.

                  I love it when I find bugs that are unique to my setup. ๐Ÿ˜‚

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG Online
                    Gertjan @lindhe
                    last edited by Gertjan

                    @lindhe

                    Try this :
                    Make a backup of your config.
                    Delete all your CA. (edit : the ones you've added yourself. There may be other certs - see the image below, you've probably imported these don't delete these)
                    Then, as I've shown above : create a new CA. Name it like me : "test" do/add nothing else, and hit the Save button.
                    Now, create a certificat, and check if you can select the CA named "test".


                    edit :

                    b2002b48-7efb-4407-a9d2-eb9962119852-image.png

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S Offline
                      stephenw10 Netgate Administrator
                      last edited by

                      The valid from and to dates are correct though? A CA that was, for some reason, no longer valid would be hidden.

                      You might try exporting the CA and examining it in a cert viewer to check for anything obviously wrong.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.