ACME pkg v1.1_1
-
ACME pkg v1.1 is out now for pfSense Plus software version 25.11.1 and CE 2.8.1
This version brings several significant changes, including:
-
Synchronized with upstream acme.sh version 3.1.3 (master branch)
-
Various upstream bug fixes
-
Added Certificate Profile option to choose alternate sets of certificate properties, if offered by the CA. #16604
-
Added External Account Binding options for Account Keys, which some CAs require for registration. #16623
-
Changed certificate renewal calculation to be based on certificate lifetime. #16603
-
Cleaned up and reformatted options and groupings of options in ACME settings. Some options have changed names and order, but should be more logical and user-friendly.
-
Cleaned up and reformatted Certificate and Account Key lists.
-
Fixed Certificate and Account Key configuration field encoding issues. #16650
-
Temporary compatibility code for logging changes from development snapshots to reduce differences with release versions.
-
Code whitespace cleanup.
-
Added new DNS validation providers from acme.sh:
- EfficientIP
- HostUp
- Infoblox UDDI
- mgw-media.de
- QUIC.cloud
- Sotoon.ir
- VirakCloud DNS API
EDIT: ACME pkg v1.1_1 is a small bug fix for an issue with account key names not being stored properly on certificates.
With the use of the
shortlivedprofile from Let's Encrypt, it is now possible to issue certificates with an IP address SAN. However, these certificates are only valid for 6 days, so the current release will always flag these certificates as expiring and issue warning notices. This is being addressed in the next pfSense software release, and can be patched with commit IDc27a5cc939445c03f0920d2934352bcd25da13a2via the System Patches package. See #16605 for details.Certificates issued using the
shortlivedandtlsserverprofiles will also lack a Common Name attribute and as a consequence have no certificate Subject, only SANs. This is valid, but the Certificate Manager does not display these properly since it always expects certificates to have a Subject/DN, so it prints "Unknown". This should not affect certificate functionality, and the SANs can be viewed as usual by clicking the "i" icon for a certificate to display its properties. This is being addressed in the next pfSense software release, and can be patched with commit ID445abad5522d04cc1414d9a11409504042941ebavia the System Patches package. See #16657 for details. -
-
J jimp pinned this topic on
-
J jimp referenced this topic on
-
G Gertjan referenced this topic on
-
Unable to upgrade to ACME 1.1 on pfSense 25.11.1
Error "WARNING: Current pkg repository has a new PHP major version. pfSense should be upgraded before installing any new package."Attempt to upgrade ACME be full delete & reinstall gives same error. So now I'm ACME-less.
-
@dstacey147 said in ACME pkg v1.1:
Unable to upgrade to ACME 1.1 on pfSense 25.11.1
Error "WARNING: Current pkg repository has a new PHP major version. pfSense should be upgraded before installing any new package."Attempt to upgrade ACME be full delete & reinstall gives same error. So now I'm ACME-less.
That isn't an ACME issue. See https://redmine.pfsense.org/issues/16669 for a workaround.
-
@jimp Back in business, thanks Jim
-
Hi there,
For the start much appreciate developer effort for that plugin.
Great addon to the pfSense./Unfortunately stoped working for me from last two recent updates.
I'm using OVH/europeThe error message showing wrong credentials but they are correct I'm sure. Also did't change them from last few years when using this plugin.
I also notice that when delating some domain and no longer under acme tab the cron is still trying update certs for deleted domains.
Hope this all will be sorted out soon.
-
@zimnysbrain said in ACME pkg v1.1_1:
Hi there,
For the start much appreciate developer effort for that plugin.
Great addon to the pfSense./Unfortunately stoped working for me from last two recent updates.
I'm using OVH/europeThe error message showing wrong credentials but they are correct I'm sure. Also did't change them from last few years when using this plugin.
Probably best to start your own thread for that. The OVH code in
acme.shhas not changed in any way that would impact that sort of operation in years.I also notice that when delating some domain and no longer under acme tab the cron is still trying update certs for deleted domains.
There must be some reference in the configuration still or it couldn't do that. It uses the same list for processing things via cron that it does for the certificates tab. Could be related to whatever is wrong with your other issue above, but both would be unrelated to these updates and should be in their own thread.
-
Hi, thank you for your answer
A bit disappointment with it
I'm reporting issues with your latest update in first so this thread should be ok
Your suggestions that I have other issues is not polite
Your explanation "There must be some reference in the configuration still or it couldn't do that" is it my problem or your script?Maybe is a good idea to stay on the line with api recent updates with providers you offer in your script.
The truth is that i din't change anything in my setup and your script stop working after your recent update
But ok.
Thanx anyway -
@zimnysbrain This thread is not for reporting issues, it's to announce the release and for awareness.
Every issue really belongs in its own thread so the discussions can be focused on single issues.
-
J jimp referenced this topic on
-
J jimp unpinned this topic on
Privacy Policy · Cookie Policy