Hi, new to this VPN server OPNsense 23.1.11
I know it's an old version; it is just used for VPN.
The server Cert is due to expire.
I created a new self-signed certificate Authority
Confirming steps;
1. Do I need to revoke the current one for the new one to take over, or is it fine with the new dates? If so how? In the certificate section?
2 Do I need to issue new certificates for the users since they were issued under the current expiring Server cert, or just make sure they do not have expiring certs?
3 Anything else required? And do I need to reboot it for any changes or adds? I see there are 149 certificates under the current cert...
Thank you in advance for any help!
Quote from: zuma48 on July 28, 2026, 11:35:07 PMI created a new self-signed certificate Authority
Was the existing one expired?
Generally a CA should have a long life time, e.g. 20+ y and there should rarely be a need to renew it.
You use the CA to issue both, the server certificate and the client certificates.
If you have replaced the CA, you have to reassign all again and assign the new CA and server cert to the OpenVPN server and give the client certs to the clients.
If just the server or client certificate expired, you only need to edit the cert, select "reissue and replace" and set new key values if you want. In case of server cert, you have to restart the VPN server after.
Here is the auth, the 2024- with an end date is first then the one i JUST CREATED.
opnsense-internal-ca-2024 YES self-signed 129 emailAddress=p@X.com, ST=Florida, O=X, L=X, CN=internal-ca-2024, C=US
Valid From: Sun, 05 May 2024 21:36:22 +0000
Valid Until: Sat, 08 Aug 2026 21:36:22 +0000
Opensense-Certificate-2026-2029 YES self-signed 0 emailAddress=d@oX.com, ST=Florida, O=X, L=X, CN=internal-ca-2026-2029, C=US
Valid From: Tue, 28 Jul 2026 13:35:38 +0000
Valid Until: Mon, 30 Oct 2028 13:35:38 +0000
Did I not need to create this?
Under Certificates;
2025 Cert
CA: No, Server: Yes opnsense-internal-ca-2024 emailAddress=plove@omniadvertising.com, ST=Florida, O=Omni Advertising, L=Boca Raton, CN=server-cert-2024, C=US
Valid From: Tue, 18 Mar 2025 15:12:54 +0000
Valid Until: Fri, 16 Mar 2035 15:12:54 +0000
This was created...
So your CA will expire soon.
You have to create a new one and then sign new server and client certificates with it and deploy them as mentioned above.
The insecure and not recommended workaround is to disable certificate verification on both, server and client.
I created this one. Is this correct for the server? What else do I need to do for the server? I do ot know...
And then re-issue all the clients with the new certs?
Thank you very much for your help.
Opensense-Certificate-2026-2029 YES self-signed 0 emailAddress=d@oX.com, ST=Florida, O=X, L=X, CN=internal-ca-2026-2029, C=US
Valid From: Tue, 28 Jul 2026 13:35:38 +0000
Valid Until: Mon, 30 Oct 2028 13:35:38 +0000
You need to create a new internal CA and then issue new certificates with that one.
The CA lifetime can be something like 10 or 20 years.
The maximum lifetime for a certificate from a private CA that works cross-platform is 825 days.
Thank you, Patrick.
Patrick, it is not working, can you help me please
What exactly did you do? What exactly is not working?
1 Added selfsigned Trust/auth cert with new date
2 added server server certificate
Err: Peer certificate verification failure
2026-08-10T14:11:37 Error openvpn_server1 68.2.107.249:62058 TLS Error: TLS handshake failed
2026-08-10T14:11:37 Error openvpn_server1 68.2.107.249:62058 TLS Error: TLS object -> incoming plaintext read error
2026-08-10T14:11:37 Error openvpn_server1 68.2.107.249:62058 TLS_ERROR: BIO read tls_read_plaintext error
2026-08-10T14:11:37 Error openvpn_server1 68.2.107.249:62058 OpenSSL: error:14094415:SSL routines:ssl3_read_bytes:sslv3 alert certificate expired
Did you create a certification authority as I advised?
Did you use that CA to sign the new certificate?
yes,
new CA
new cert
Server selected new ones saved
Any way you can do a share screen with me and I will pay you for your time?
Why don't you share screen shots. You can attach them to your postings directly in the forum.
patrick, I got it working, re did the certs... whew. Thank you!! Next will be updating it. Next week...lol