<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[HA sync overwrites certificates on backup router even if unchecked]]></title><description><![CDATA[<p dir="auto">I set up ACME/LE certs on our two data center routers yesterday.  Twice since then I have noticed the cert is missing on the backup router, even though I disabled sync of certificates:<br />
<img src="/assets/uploads/files/1772213518123-0be69b2e-b131-4495-8378-b1f885b8ec5e-image.png" alt="0be69b2e-b131-4495-8378-b1f885b8ec5e-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I'm assuming that is not expected?  The backup router web server is left running with a live cert, but the web server cert dropdown is set to "IKEv2 server," the first cert it has in its list.  So presumably would break upon restart.  The CAs are overwritten and the router1 cert is on router2 as well so they all sync'd.</p>
<p dir="auto">If expected, what is the solution, to use a wildcard cert?  That's what we previously had, so had been syncing certs on purpose.</p>
<p dir="auto">These routers are still on 25.07, though I don't see anything in later release notes about this.</p>
]]></description><link>https://forum.netgate.com/topic/200255/ha-sync-overwrites-certificates-on-backup-router-even-if-unchecked</link><generator>RSS for Node</generator><lastBuildDate>Sat, 13 Jun 2026 06:44:27 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/200255.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 27 Feb 2026 17:36:44 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to HA sync overwrites certificates on backup router even if unchecked on Fri, 05 Jun 2026 21:04:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/derelict">@<bdi>Derelict</bdi></a> I realized today that although the LE cert syncs to the secondary just fine, it doesn't restart nginx which continues using the expired cert.</p>
<p dir="auto">On the primary router the Post-Renew Actions is run to do that. That doesn't exist on the secondary because the cert doesn't exist on the secondary.</p>
<p dir="auto">Is there a proper solution other than restarting the secondary webGUI via cron or something?</p>
]]></description><link>https://forum.netgate.com/post/1243733</link><guid isPermaLink="true">https://forum.netgate.com/post/1243733</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Fri, 05 Jun 2026 21:04:37 GMT</pubDate></item><item><title><![CDATA[Reply to HA sync overwrites certificates on backup router even if unchecked on Sat, 28 Feb 2026 02:14:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/derelict">@<bdi>Derelict</bdi></a> Yeah, that’d be the other option and basically what we did with the wildcard cert. Might be cleaner to let the certs sync. It just surprised me to carefully test it all on r2, set up one cert on r1, and everything disappeared on r2.</p>
<p dir="auto">We were using the wildcard in a lot of places but are looking to avoid replacing that many cert locations every 47 days going forward… :(</p>
]]></description><link>https://forum.netgate.com/post/1238821</link><guid isPermaLink="true">https://forum.netgate.com/post/1238821</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Sat, 28 Feb 2026 02:14:06 GMT</pubDate></item><item><title><![CDATA[Reply to HA sync overwrites certificates on backup router even if unchecked on Fri, 27 Feb 2026 22:46:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>SteveITS</bdi></a> I use acme to obtain a certificate with three hostnames, fw-xyz.domain.com (CARP VIP), fw-a-xyz.domain.com (Primary), and fw-b-xyz.domain.com (Secondary). This runs on the primary and syncs to the secondary. Works great.</p>
]]></description><link>https://forum.netgate.com/post/1238810</link><guid isPermaLink="true">https://forum.netgate.com/post/1238810</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Fri, 27 Feb 2026 22:46:06 GMT</pubDate></item><item><title><![CDATA[Reply to HA sync overwrites certificates on backup router even if unchecked on Fri, 27 Feb 2026 19:26:43 GMT]]></title><description><![CDATA[<p dir="auto">If I read a bit further in the list I get to "OpenVPN configuration (Implies CA/Cert/CRL Sync)".  We don't use that anymore so I suppose can uncheck that. <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f915.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--face_with_head_bandage" style="height:23px;width:auto;vertical-align:middle" title=":face_with_head_bandage:" alt="🤕" /></p>
]]></description><link>https://forum.netgate.com/post/1238805</link><guid isPermaLink="true">https://forum.netgate.com/post/1238805</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Fri, 27 Feb 2026 19:26:43 GMT</pubDate></item></channel></rss>