Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    25.11 Webconfiguator doesn't start with https after upgrade

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    8 Posts 2 Posters 213 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L Offline
      Liam
      last edited by

      Webconfiguator gives a failed message after upgrade to 25.11

      If I change protocol to http via viconfig then it starts and I get the gui back

      This is the working stanza from webconfig:

      <webgui>
                              <protocol>http</protocol>
                              <ssl-certref>54686b27c47e0</ssl-certref>
                              <port></port>
                              <max_procs>2</max_procs>
                              <dashboardcolumns>2</dashboardcolumns>
                              <webguicss>pfSense.css</webguicss>
                              <logincss>1e3f75;</logincss>
                              <roaming>enabled</roaming>
                              <dashboardavailablewidgetspanel></dashboardavailablewidgetspanel>
                              <systemlogsfilterpanel></systemlogsfilterpanel>
                              <systemlogsmanagelogpanel></systemlogsmanagelogpanel>
                              <statusmonitoringsettingspanel></statusmonitoringsettingspanel>
                      </webgui>
      
      

      The only change I made to the stanza was to remove the 's' from the 'https"

      Cheers, Liam

      1 Reply Last reply Reply Quote 0
      • L Offline
        Liam
        last edited by

        Host is a Netgate XG-1541

        S 1 Reply Last reply Reply Quote 0
        • S Offline
          SteveITS Rebel Alliance @Liam
          last edited by

          @Liam This is just a guess but is the certificate valid? Maybe regenerate that.

          Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
          Upvote ๐Ÿ‘ helpful posts!

          L 1 Reply Last reply Reply Quote 0
          • L Offline
            Liam @SteveITS
            last edited by

            @SteveITS

            Thanks Steve. I regenerated the cert, and it still won't start the webconfigurator with https configured.

            I don't know if I need to do any other steps other than hit the regenertate button for the cert though - so I might be missing something.

            S 1 Reply Last reply Reply Quote 0
            • S Offline
              SteveITS Rebel Alliance @Liam
              last edited by

              @Liam The certificate renewal page should show if anything is old/needs changing in the cert.

              Does the web server (GUI Service) log show anything useful when it won't start?

              Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
              Upvote ๐Ÿ‘ helpful posts!

              L 1 Reply Last reply Reply Quote 0
              • L Offline
                Liam @SteveITS
                last edited by

                @SteveITS

                Nothing under GUI Service, but there is this under General:

                rc.restart_webgui: The command '/usr/local/sbin/nginx -c /var/etc/nginx-webConfigurator.conf' returned exit code '1', the output was 'nginx: [emerg] SSL_CTX_use_certificate("/var/etc/cert.crt") failed (SSL: error:0A00018F:SSL routines::ee key too small)'

                S 1 Reply Last reply Reply Quote 0
                • S Offline
                  SteveITS Rebel Alliance @Liam
                  last edited by SteveITS

                  @Liam Sounds similar to the OpenVPN DH key issue:

                  https://docs.netgate.com/pfsense/en/latest/releases/25-11.html#openvpn
                  -> https://redmine.pfsense.org/issues/16421

                  Is your cert key 2048+ bits?

                  Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                  Upvote ๐Ÿ‘ helpful posts!

                  L 1 Reply Last reply Reply Quote 1
                  • L Offline
                    Liam @SteveITS
                    last edited by

                    @SteveITS

                    You nailed it. The cert I renewed had a 1024 key. Once I worked out how to update that setting on a key renewal turning on HTTPS from the gui worked. Going to check on reboot now, but I presume it will work.

                    ...and that's confirmed.

                    Thank you very much for your assistance, very much appreciated.

                    Cheers, Liam

                    1 Reply Last reply Reply Quote 2
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.