Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    The following CA/Certificate entries are expiring: Certificate: GUI default ...

    Scheduled Pinned Locked Moved webGUI
    8 Posts 4 Posters 639 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      khb
      last edited by

      No doubt this is a terribly naive question, but should I expect the GUI certificate to be expiring, and if so, where ought I fetch an updated one?

      SteveITSS 1 Reply Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @khb
        last edited by

        @khb yes. You can just renew it. https://docs.netgate.com/pfsense/en/latest/certificates/index.html

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • K Offline
          khb
          last edited by

          @SteveITS said in The following CA/Certificate entries are expiring: Certificate: GUI default ...:

          https://docs.netgate.com/pfsense/en/latest/certificates/index.html

          Thank you. While I appreciate the security upside of having external “things” certificates expire, what’s the benefit of this for the appliance's local GUI, especially since its self signed?

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator @khb
            last edited by johnpoz

            @khb I concur that should prob be longer, but in a recent thread that some of these browser makers are getting a bit overly zealous if you will on even local type certs.

            safari seems to have a limit of 825 days for even a local CA.. What I do is create my own ca, sign my pfsense gui cert with that ca that my browser trusts (firefox, and others) I don't use safari.

            I set them for 10 years. I also put in the fqdn I am using, currently for my pfsense gui sg4860.home.arpa - yes I know its very creative and imaginative, hehehhe being currently its a netgate sg-4860 model..

            I also put in the IP of my lan as SAN, so I can access via name or IP and my browser is happy and doesn't complain. And more than likely will have newer machine well before that cert expires ;)

            cert.jpg

            This one is good from 2024, when I changed over from using local.lan as my local domain to the approved home.arpa domain.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 26.03 | Lab VMs 2.8.1, 26.03

            SteveITSS 1 Reply Last reply Reply Quote 0
            • SteveITSS Offline
              SteveITS Rebel Alliance @johnpoz
              last edited by

              In addition per https://forum.netgate.com/post/1236652 they plan to auto-renew it in future versions.

              To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
              Only install packages for your version of pfSense.
              Upvote 👍 helpful posts!

              1 Reply Last reply Reply Quote 0
              • JonathanLeeJ Offline
                JonathanLee
                last edited by

                Yeah renew!!! Like the movie Logan’s Run you know ?

                Make sure to upvote

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator @JonathanLee
                  last edited by

                  @JonathanLee said in The following CA/Certificate entries are expiring: Certificate: GUI default ...:

                  Like the movie Logan’s Run you know ?

                  haha - one of my favs..

                  Enter the Carousel. This is the time of renewal.

                  renewal.jpg

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 26.03 | Lab VMs 2.8.1, 26.03

                  JonathanLeeJ 1 Reply Last reply Reply Quote 1
                  • JonathanLeeJ Offline
                    JonathanLee @johnpoz
                    last edited by

                    @johnpoz with that music going haha

                    Make sure to upvote

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.