OPNsense Forum

Archive => 21.7 Legacy Series => Topic started by: fields987 on July 30, 2021, 08:08:53 AM

Title: WebGUI Bug - Selecting Cert
Post by: fields987 on July 30, 2021, 08:08:53 AM
I did a fresh install of 21.7 and opted to restore my config by hand instead of xml.
I installed and enabled the acme plugin, registered an account, setup a basic http-01 challenge type, and requested my cert.

When I went to apply it to the webgui, i got an error saying the cert is not intended for server use. when I look at the cert, it shows server: No. How do I get this to issue a cert I can use for the web gui? PS - I'm on the staging environment as I think I've hit my quota against prod.

Thanks.
Title: Re: WebGUI Bug - Selecting Cert
Post by: fields987 on July 30, 2021, 11:15:55 PM
After digging in, its not related to the ACME plugin. I couldn't get external certs to apply either.
I was able to edit the config.xml file and put in the refid of the letsencrypt cert I generated and reloaded webgui. The cert is now in use, but any time I edit the webgui admin settings, I still get the error that the cert is not intended for server use.
Title: Re: WebGUI Bug - Selecting Cert
Post by: franco on July 31, 2021, 02:34:21 PM
Are you able to paste such a certificate here?

To my knowledge the server flag check has been working fine for a long time.


Cheers,
Franco
Title: Re: WebGUI Bug - Selecting Cert
Post by: fields987 on August 01, 2021, 05:08:03 AM
Franco, Here is one example.
Thanks!
Title: Re: WebGUI Bug - Selecting Cert
Post by: franco on August 01, 2021, 09:25:21 AM
Thanks, same issue on GitHub for activity:

https://github.com/opnsense/core/issues/5128


Cheers,
Franco