Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    ACME pkg v1.1_1

    Scheduled Pinned Locked Moved ACME
    8 Posts 3 Posters 2.8k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ Offline
      jimp Rebel Alliance Developer Netgate
      last edited by jimp

      ACME pkg v1.1 is out now for pfSense Plus software version 25.11.1 and CE 2.8.1

      This version brings several significant changes, including:

      • Synchronized with upstream acme.sh version 3.1.3 (master branch)

      • Various upstream bug fixes

      • Added Certificate Profile option to choose alternate sets of certificate properties, if offered by the CA. #16604

      • Added External Account Binding options for Account Keys, which some CAs require for registration. #16623

      • Changed certificate renewal calculation to be based on certificate lifetime. #16603

      • Cleaned up and reformatted options and groupings of options in ACME settings. Some options have changed names and order, but should be more logical and user-friendly.

      • Cleaned up and reformatted Certificate and Account Key lists.

      • Fixed Certificate and Account Key configuration field encoding issues. #16650

      • Temporary compatibility code for logging changes from development snapshots to reduce differences with release versions.

      • Code whitespace cleanup.

      • Added new DNS validation providers from acme.sh:

        • EfficientIP
        • HostUp
        • Infoblox UDDI
        • mgw-media.de
        • QUIC.cloud
        • Sotoon.ir
        • VirakCloud DNS API

      EDIT: ACME pkg v1.1_1 is a small bug fix for an issue with account key names not being stored properly on certificates.


      With the use of the shortlived profile from Let's Encrypt, it is now possible to issue certificates with an IP address SAN. However, these certificates are only valid for 6 days, so the current release will always flag these certificates as expiring and issue warning notices. This is being addressed in the next pfSense software release, and can be patched with commit ID c27a5cc939445c03f0920d2934352bcd25da13a2 via the System Patches package. See #16605 for details.

      Certificates issued using the shortlived and tlsserver profiles will also lack a Common Name attribute and as a consequence have no certificate Subject, only SANs. This is valid, but the Certificate Manager does not display these properly since it always expects certificates to have a Subject/DN, so it prints "Unknown". This should not affect certificate functionality, and the SANs can be viewed as usual by clicking the "i" icon for a certificate to display its properties. This is being addressed in the next pfSense software release, and can be patched with commit ID 445abad5522d04cc1414d9a11409504042941eba via the System Patches package. See #16657 for details.

      Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 6
      • jimpJ jimp pinned this topic on
      • jimpJ jimp referenced this topic on
      • GertjanG Gertjan referenced this topic on
      • D Offline
        dstacey147
        last edited by

        Unable to upgrade to ACME 1.1 on pfSense 25.11.1
        Error "WARNING: Current pkg repository has a new PHP major version. pfSense should be upgraded before installing any new package."

        Attempt to upgrade ACME be full delete & reinstall gives same error. So now I'm ACME-less.

        jimpJ 1 Reply Last reply Reply Quote 0
        • jimpJ Offline
          jimp Rebel Alliance Developer Netgate @dstacey147
          last edited by

          @dstacey147 said in ACME pkg v1.1:

          Unable to upgrade to ACME 1.1 on pfSense 25.11.1
          Error "WARNING: Current pkg repository has a new PHP major version. pfSense should be upgraded before installing any new package."

          Attempt to upgrade ACME be full delete & reinstall gives same error. So now I'm ACME-less.

          That isn't an ACME issue. See https://redmine.pfsense.org/issues/16669 for a workaround.

          Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          D 1 Reply Last reply Reply Quote 1
          • D Offline
            dstacey147 @jimp
            last edited by

            @jimp Back in business, thanks Jim

            1 Reply Last reply Reply Quote 0
            • Z Offline
              zimnysbrain
              last edited by

              Hi there,
              For the start much appreciate developer effort for that plugin.
              Great addon to the pfSense./

              Unfortunately stoped working for me from last two recent updates.
              I'm using OVH/europe

              The error message showing wrong credentials but they are correct I'm sure. Also did't change them from last few years when using this plugin.

              I also notice that when delating some domain and no longer under acme tab the cron is still trying update certs for deleted domains.

              Hope this all will be sorted out soon.

              jimpJ 1 Reply Last reply Reply Quote 0
              • jimpJ Offline
                jimp Rebel Alliance Developer Netgate @zimnysbrain
                last edited by

                @zimnysbrain said in ACME pkg v1.1_1:

                Hi there,
                For the start much appreciate developer effort for that plugin.
                Great addon to the pfSense./

                Unfortunately stoped working for me from last two recent updates.
                I'm using OVH/europe

                The error message showing wrong credentials but they are correct I'm sure. Also did't change them from last few years when using this plugin.

                Probably best to start your own thread for that. The OVH code in acme.sh has not changed in any way that would impact that sort of operation in years.

                I also notice that when delating some domain and no longer under acme tab the cron is still trying update certs for deleted domains.

                There must be some reference in the configuration still or it couldn't do that. It uses the same list for processing things via cron that it does for the certificates tab. Could be related to whatever is wrong with your other issue above, but both would be unrelated to these updates and should be in their own thread.

                Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                Z 1 Reply Last reply Reply Quote 0
                • Z Offline
                  zimnysbrain @jimp
                  last edited by zimnysbrain

                  @jimp

                  Hi, thank you for your answer

                  A bit disappointment with it

                  I'm reporting issues with your latest update in first so this thread should be ok
                  Your suggestions that I have other issues is not polite
                  Your explanation "There must be some reference in the configuration still or it couldn't do that" is it my problem or your script?

                  Maybe is a good idea to stay on the line with api recent updates with providers you offer in your script.

                  The truth is that i din't change anything in my setup and your script stop working after your recent update

                  But ok.
                  Thanx anyway

                  jimpJ 1 Reply Last reply Reply Quote 0
                  • jimpJ Offline
                    jimp Rebel Alliance Developer Netgate @zimnysbrain
                    last edited by

                    @zimnysbrain This thread is not for reporting issues, it's to announce the release and for awareness.

                    Every issue really belongs in its own thread so the discussions can be focused on single issues.

                    Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 2
                    • jimpJ jimp referenced this topic on
                    • jimpJ jimp unpinned this topic on
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                    Privacy Policy · Cookie Policy