Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    25.11 Webconfiguator doesn't start with https after upgrade

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    8 Posts 2 Posters 591 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L Offline
      Liam
      last edited by

      Webconfiguator gives a failed message after upgrade to 25.11

      If I change protocol to http via viconfig then it starts and I get the gui back

      This is the working stanza from webconfig:

      <webgui>
                              <protocol>http</protocol>
                              <ssl-certref>54686b27c47e0</ssl-certref>
                              <port></port>
                              <max_procs>2</max_procs>
                              <dashboardcolumns>2</dashboardcolumns>
                              <webguicss>pfSense.css</webguicss>
                              <logincss>1e3f75;</logincss>
                              <roaming>enabled</roaming>
                              <dashboardavailablewidgetspanel></dashboardavailablewidgetspanel>
                              <systemlogsfilterpanel></systemlogsfilterpanel>
                              <systemlogsmanagelogpanel></systemlogsmanagelogpanel>
                              <statusmonitoringsettingspanel></statusmonitoringsettingspanel>
                      </webgui>
      
      

      The only change I made to the stanza was to remove the 's' from the 'https"

      Cheers, Liam

      1 Reply Last reply Reply Quote 0
      • L Offline
        Liam
        last edited by

        Host is a Netgate XG-1541

        SteveITSS 1 Reply Last reply Reply Quote 0
        • SteveITSS Offline
          SteveITS Rebel Alliance @Liam
          last edited by

          @Liam This is just a guess but is the certificate valid? Maybe regenerate that.

          To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
          Only install packages for your version of pfSense.
          Upvote ๐Ÿ‘ helpful posts!

          L 1 Reply Last reply Reply Quote 0
          • L Offline
            Liam @SteveITS
            last edited by

            @SteveITS

            Thanks Steve. I regenerated the cert, and it still won't start the webconfigurator with https configured.

            I don't know if I need to do any other steps other than hit the regenertate button for the cert though - so I might be missing something.

            SteveITSS 1 Reply Last reply Reply Quote 0
            • SteveITSS Offline
              SteveITS Rebel Alliance @Liam
              last edited by

              @Liam The certificate renewal page should show if anything is old/needs changing in the cert.

              Does the web server (GUI Service) log show anything useful when it won't start?

              To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
              Only install packages for your version of pfSense.
              Upvote ๐Ÿ‘ helpful posts!

              L 1 Reply Last reply Reply Quote 0
              • L Offline
                Liam @SteveITS
                last edited by

                @SteveITS

                Nothing under GUI Service, but there is this under General:

                rc.restart_webgui: The command '/usr/local/sbin/nginx -c /var/etc/nginx-webConfigurator.conf' returned exit code '1', the output was 'nginx: [emerg] SSL_CTX_use_certificate("/var/etc/cert.crt") failed (SSL: error:0A00018F:SSL routines::ee key too small)'

                SteveITSS 1 Reply Last reply Reply Quote 0
                • SteveITSS Offline
                  SteveITS Rebel Alliance @Liam
                  last edited by SteveITS

                  @Liam Sounds similar to the OpenVPN DH key issue:

                  https://docs.netgate.com/pfsense/en/latest/releases/25-11.html#openvpn
                  -> https://redmine.pfsense.org/issues/16421

                  Is your cert key 2048+ bits?

                  To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                  Only install packages for your version of pfSense.
                  Upvote ๐Ÿ‘ helpful posts!

                  L 1 Reply Last reply Reply Quote 1
                  • L Offline
                    Liam @SteveITS
                    last edited by

                    @SteveITS

                    You nailed it. The cert I renewed had a 1024 key. Once I worked out how to update that setting on a key renewal turning on HTTPS from the gui worked. Going to check on reboot now, but I presume it will work.

                    ...and that's confirmed.

                    Thank you very much for your assistance, very much appreciated.

                    Cheers, Liam

                    1 Reply Last reply Reply Quote 2
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                    Privacy Policy · Cookie Policy