Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - PotatoCarl

#1
Exactly my point. According to the log OPNsense tries to (re)import the certificates from a non-existing directory. There seems to be something wrong in the file handling.

Although I wonder where it gets to old certificates from that it sends to the client...
#2
Well, what works is (little suprisingly) to manually copy the certificates to your client computer and install there. That is what I made, but that is not a fix, but just a crude workaround.
#3
Also, when I "reimport" a the certificate a) the wrong one is tried to be imported (wrong directory) and b) it is not shown under "system/security/certificates"

Is there anything seriously wrong with the plugin?

As reminder, I did reset the acme plugin and try to get the certificates back in the system.
#4
More to that: During the renewalprocess it seems that OPNSense is crashing.

I get from the crash reporter those messages:

User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:153.0) Gecko/20100101 Firefox/153.0
FreeBSD 14.3-RELEASE-p16 stable/26.1-n272152-9b6eef552f24 SMP amd64
OPNsense 26.4.1p2 907221bb6
Plugins os-OPNBEcore-1.8_2 os-acme-client-4.16_1 os-c-icap-1.9 os-chrony-1.5_3 os-clamav-1.8.1 os-cpu-microcode-amd-1.1_1 os-dec-hw-1.1_3 os-dmidecode-1.2 os-freeradius-1.10.1 os-ftp-proxy-1.0_4 os-hw-probe-1.0_1 os-intrusion-detection-content-et-open-1.0.2_2 os-intrusion-detection-content-snort-vrt-1.2 os-iperf-1.0_2 os-isc-dhcp-1.0_5 os-maltrail-1.10_3 os-nextcloud-backup-1.2 os-openvpn-legacy-1.0_1 os-postfix-1.24.1 os-redis-1.1_4 os-rspamd-1.13_2 os-sftp-backup-1.1_2 os-siproxd-1.3_3 os-smart-2.4 os-squid-1.4_1
Time Mon, 03 Aug 2026 11:12:49 +0200
OpenSSL 3.0.21
Python 3.13.14
PHP 8.3.31

[03-Aug-2026 11:09:38 Europe/Berlin] PHP Fatal error:  Uncaught OPNsense\Base\ValidationException: [OPNsense\Trust\Ca:ca.1298b06f-bb98-43fc-b1c9-d4bdb29419eb.key_type] Option [] not in list.{9999}
 in /usr/local/opnsense/mvc/app/models/OPNsense/Base/BaseModel.php:822
Stack trace:
#0 /usr/local/opnsense/mvc/app/library/OPNsense/AcmeClient/LeCertificate.php(193): OPNsense\Base\BaseModel->serializeToConfig()
#1 /usr/local/opnsense/mvc/app/library/OPNsense/AcmeClient/LeCertificate.php(381): OPNsense\AcmeClient\LeCertificate->import(true)
#2 /usr/local/opnsense/scripts/OPNsense/AcmeClient/lecert.php(169): OPNsense\AcmeClient\LeCertificate->issue()
#3 /usr/local/opnsense/scripts/OPNsense/AcmeClient/lecert.php(198): main()
#4 {main}
  thrown in /usr/local/opnsense/mvc/app/models/OPNsense/Base/BaseModel.php on line 822
[03-Aug-2026 11:10:16 Europe/Berlin] PHP Fatal error:  Uncaught OPNsense\Base\ValidationException: [OPNsense\Trust\Ca:ca.1298b06f-bb98-43fc-b1c9-d4bdb29419eb.key_type] Option [] not in list.{9999}
 in /usr/local/opnsense/mvc/app/models/OPNsense/Base/BaseModel.php:822
Stack trace:
#0 /usr/local/opnsense/mvc/app/library/OPNsense/AcmeClient/LeCertificate.php(193): OPNsense\Base\BaseModel->serializeToConfig()
#1 /usr/local/opnsense/scripts/OPNsense/AcmeClient/lecert.php(175): OPNsense\AcmeClient\LeCertificate->import(true)
#2 /usr/local/opnsense/scripts/OPNsense/AcmeClient/lecert.php(198): main()
#3 {main}
  thrown in /usr/local/opnsense/mvc/app/models/OPNsense/Base/BaseModel.php on line 822
[03-Aug-2026 11:12:11 Europe/Berlin] PHP Fatal error:  Uncaught OPNsense\Base\ValidationException: [OPNsense\Trust\Ca:ca.1298b06f-bb98-43fc-b1c9-d4bdb29419eb.key_type] Option [] not in list.{9999}
 in /usr/local/opnsense/mvc/app/models/OPNsense/Base/BaseModel.php:822
Stack trace:
#0 /usr/local/opnsense/mvc/app/library/OPNsense/AcmeClient/LeCertificate.php(193): OPNsense\Base\BaseModel->serializeToConfig()
#1 /usr/local/opnsense/scripts/OPNsense/AcmeClient/lecert.php(175): OPNsense\AcmeClient\LeCertificate->import(true)
#2 /usr/local/opnsense/scripts/OPNsense/AcmeClient/lecert.php(198): main()
#3 {main}
  thrown in /usr/local/opnsense/mvc/app/models/OPNsense/Base/BaseModel.php on line 822


---<<BOOT>>---
Copyright (c) 1992-2023 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
   The Regents of the University of California. All rights reserved.
FreeBSD is a registered trademark of The FreeBSD Foundation.
FreeBSD 14.3-RELEASE-p16 stable/26.1-n272152-9b6eef552f24 SMP amd64
FreeBSD clang version 19.1.7 (https://github.com/llvm/llvm-project.git llvmorg-19.1.7-0-gcd708029e0b2)
[1] VT(vga): resolution 640x480
[1] CPU: AMD Ryzen Embedded V1500B                       (2196.03-MHz K8-class CPU)
[1]   Origin="AuthenticAMD"  Id=0x810f10  Family=0x17  Model=0x11  Stepping=0
[1]   Features=0x178bfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,MMX,FXSR,SSE,SSE2,HTT>
[1]   Features2=0x7ed8320b<SSE3,PCLMULQDQ,MON,SSSE3,FMA,CX16,SSE4.1,SSE4.2,MOVBE,POPCNT,AESNI,XSAVE,OSXSAVE,AVX,F16C,RDRAND>
[1]   AMD Features=0x2e500800<SYSCALL,NX,MMX+,FFXSR,Page1GB,RDTSCP,LM>
[1]   AMD Features2=0x35c233ff<LAHF,CMP,SVM,ExtAPIC,CR8,ABM,SSE4A,MAS,Prefetch,OSVW,SKINIT,WDT,TCE,Topology,PCXC,PNXC,DBE,PL2I,MWAITX>
[1]   Structured Extended Features=0x209c01a9<FSGSBASE,BMI1,AVX2,SMEP,BMI2,RDSEED,ADX,SMAP,CLFLUSHOPT,SHA>
[1]   XSAVE Features=0xf<XSAVEOPT,XSAVEC,XINUSE,XSAVES>
[1]   AMD Extended Feature Extensions ID EBX=0x1007<CLZERO,IRPerf,XSaveErPtr,IBPB>
[1]   SVM: (disabled in BIOS) NP,NRIP,VClean,AFlush,DAssist,NAsids=32768
[1]   TSC: P-state invariant, performance statistics
[1] real memory  = 8589934592 (8192 MB)
[1] avail memory = 8221208576 (7840 MB)
[1] Event timer "LAPIC" quality 600
[1] ACPI APIC Table: <INSYDE EDK2    >
[1] FreeBSD/SMP: Multiprocessor System Detected: 4 CPUs
[1] FreeBSD/SMP: 1 package(s) x 4 core(s)
[1] random: registering fast source Intel Secure Key RNG
[1] random: fast provider: "Intel Secure Key RNG"
[1] random: unblocking device.
[1] ioapic0: MADT APIC ID 33 != hw id 0
[1] ioapic1: MADT APIC ID 34 != hw id 0
[1] ioapic0 <Version 2.1> irqs 0-23
[1] ioapic1 <Version 2.1> irqs 24-55
[1] Launching APs: 2 3 1
[1] random: entropy device external interface
[1] wlan: mac acl policy registered
[1] kbd0 at kbdmux0
[1] WARNING: Device "spkr" is Giant locked and may be deleted before FreeBSD 15.0.
[1] efirtc0: <EFI Realtime Clock>
[1] efirtc0: registered as a time-of-day clock, resolution 1.000000s
[1] vtvga0: <VT VGA driver>
[1] smbios0: <System Management BIOS> at iomem 0xce152000-0xce152017
[1] smbios0: Entry point: v3 (64-bit), Version: 3.1
[1] aesni0: <AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS,SHA1,SHA256>
[1] acpi0: <INSYDE EDK2>
[1] acpi0: Power Button (fixed)
[1] cpu0: <ACPI CPU> on acpi0
[1] hpet0: <High Precision Event Timer> iomem 0xfed00000-0xfed003ff irq 0,8 on acpi0
[1] Timecounter "HPET" frequency 14318180 Hz quality 950
[1] Event timer "HPET" frequency 14318180 Hz quality 450
[1] Event timer "HPET1" frequency 14318180 Hz quality 450
[1] Event timer "HPET2" frequency 14318180 Hz quality 450
[1] atrtc0: <AT realtime clock> port 0x70-0x71 on acpi0
[1] atrtc0: registered as a time-of-day clock, resolution 1.000000s
[1] Event timer "RTC" frequency 32768 Hz quality 0
[1] attimer0: <AT timer> port 0x40-0x43 on acpi0
[1] Timecounter "i8254" frequency 1193182 Hz quality 0
[1] Event timer "i8254" frequency 1193182 Hz quality 100
[1] Timecounter "ACPI-fast" frequency 3579545 Hz quality 900
[1] acpi_timer0: <32-bit timer at 3.579545MHz> port 0x408-0x40b on acpi0
[1] acpi_button0: <Power Button> on acpi0
[1] pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
[1] pci0: <ACPI PCI bus> on pcib0
[1] pcib1: <ACPI PCI-PCI bridge> at device 1.1 on pci0
[1] pci1: <ACPI PCI bus> on pcib1
[1] nvme0: <Generic NVMe Device> mem 0xd1400000-0xd1403fff at device 0.0 on pci1
[1] pcib2: <ACPI PCI-PCI bridge> at device 1.2 on pci0
[1] pci2: <ACPI PCI bus> on pcib2
[1] igc0: <Intel(R) Ethernet Controller I226-V> mem 0xd1200000-0xd12fffff,0xd1300000-0xd1303fff at device 0.0 on pci2
[1] igc0: EEPROM V2.25-0 eTrack 0x800003b1
[1] igc0: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc0: Using 4 RX queues 4 TX queues
[1] igc0: Using MSI-X interrupts with 5 vectors
[1] igc0: Ethernet address: f4:90:ea:01:cf:f0
[1] igc0: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib3: <ACPI PCI-PCI bridge> at device 1.3 on pci0
[1] pci3: <ACPI PCI bus> on pcib3
[1] igc1: <Intel(R) Ethernet Controller I226-V> mem 0xd1000000-0xd10fffff,0xd1100000-0xd1103fff at device 0.0 on pci3
[1] igc1: EEPROM V2.25-0 eTrack 0x800003b1
[1] igc1: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc1: Using 4 RX queues 4 TX queues
[1] igc1: Using MSI-X interrupts with 5 vectors
[1] igc1: Ethernet address: f4:90:ea:01:cf:f1
[1] igc1: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib4: <ACPI PCI-PCI bridge> at device 1.4 on pci0
[1] pci4: <ACPI PCI bus> on pcib4
[1] igc2: <Intel(R) Ethernet Controller I226-V> mem 0xd0e00000-0xd0efffff,0xd0f00000-0xd0f03fff at device 0.0 on pci4
[1] igc2: EEPROM V2.25-0 eTrack 0x800003b1
[1] igc2: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc2: Using 4 RX queues 4 TX queues
[1] igc2: Using MSI-X interrupts with 5 vectors
[1] igc2: Ethernet address: f4:90:ea:01:cf:f2
[1] igc2: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib5: <ACPI PCI-PCI bridge> at device 1.5 on pci0
[1] pci5: <ACPI PCI bus> on pcib5
[1] pcib6: <PCI-PCI bridge> at device 0.0 on pci5
[1] pci6: <PCI bus> on pcib6
[1] pcib7: <PCI-PCI bridge> at device 1.0 on pci6
[1] pci7: <PCI bus> on pcib7
[1] igc3: <Intel(R) Ethernet Controller I226-V> mem 0xd0c00000-0xd0cfffff,0xd0d00000-0xd0d03fff at device 0.0 on pci7
[1] igc3: EEPROM V2.25-0 eTrack 0x800003b1
[1] igc3: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc3: Using 4 RX queues 4 TX queues
[1] igc3: Using MSI-X interrupts with 5 vectors
[1] igc3: Ethernet address: f4:90:ea:01:da:30
[1] igc3: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib8: <PCI-PCI bridge> at device 2.0 on pci6
[1] pci8: <PCI bus> on pcib8
[1] igc4: <Intel(R) Ethernet Controller I226-V> mem 0xd0a00000-0xd0afffff,0xd0b00000-0xd0b03fff at device 0.0 on pci8
[1] igc4: EEPROM V2.25-0 eTrack 0x800003b1
[1] igc4: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc4: Using 4 RX queues 4 TX queues
[1] igc4: Using MSI-X interrupts with 5 vectors
[1] igc4: Ethernet address: f4:90:ea:01:da:31
[1] igc4: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib9: <PCI-PCI bridge> at device 3.0 on pci6
[1] pci9: <PCI bus> on pcib9
[1] igc5: <Intel(R) Ethernet Controller I226-V> mem 0xd0800000-0xd08fffff,0xd0900000-0xd0903fff at device 0.0 on pci9
[1] igc5: EEPROM V2.25-0 eTrack 0x800003b1
[1] igc5: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc5: Using 4 RX queues 4 TX queues
[1] igc5: Using MSI-X interrupts with 5 vectors
[1] igc5: Ethernet address: f4:90:ea:01:da:32
[1] igc5: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib10: <PCI-PCI bridge> at device 4.0 on pci6
[1] pci10: <PCI bus> on pcib10
[1] igc6: <Intel(R) Ethernet Controller I226-V> mem 0xd0600000-0xd06fffff,0xd0700000-0xd0703fff at device 0.0 on pci10
[1] igc6: EEPROM V2.25-0 eTrack 0x800003b1
[1] igc6: Using 1024 TX descriptors and 1024 RX descriptors
[1] igc6: Using 4 RX queues 4 TX queues
[1] igc6: Using MSI-X interrupts with 5 vectors
[1] igc6: Ethernet address: f4:90:ea:01:da:33
[1] igc6: netmap queues/slots: TX 4/1024, RX 4/1024
[1] pcib11: <ACPI PCI-PCI bridge> at device 8.1 on pci0
[1] pci11: <ACPI PCI bus> on pcib11
[1] pci11: <encrypt/decrypt> at device 0.2 (no driver attached)
[1] xhci0: <AMD Raven USB 3.1 controller> mem 0xd0300000-0xd03fffff at device 0.3 on pci11
[1] xhci0: 64 bytes context size, 64-bit DMA
[1] usbus0: waiting for BIOS to give up control
[1] usbus0 on xhci0
[1] usbus0: 5.0Gbps Super Speed USB v3.0
[1] xhci1: <AMD Raven USB 3.1 controller> mem 0xd0200000-0xd02fffff at device 0.4 on pci11
[1] xhci1: 64 bytes context size, 64-bit DMA
[1] usbus1: waiting for BIOS to give up control
[1] usbus1 on xhci1
[1] usbus1: 5.0Gbps Super Speed USB v3.0
[1] pci11: <multimedia> at device 0.5 (no driver attached)
[1] hdac0: <AMD Raven HDA Controller> mem 0xd0540000-0xd0547fff at device 0.6 on pci11
[1] pci11: <old, non-VGA display device> at device 0.7 (no driver attached)
[1] pcib12: <ACPI PCI-PCI bridge> at device 8.2 on pci0
[1] pci12: <ACPI PCI bus> on pcib12
[1] ax0: <AMD 10 Gigabit Ethernet Driver> mem 0xd0060000-0xd007ffff,0xd0040000-0xd005ffff,0xd0082000-0xd0083fff at device 0.1 on pci12
[1] ax0: Using 512 TX descriptors and 512 RX descriptors
[1] ax0: Using 3 RX queues 3 TX queues
[1] ax0: Using MSI-X interrupts with 7 vectors
[1] ax0: Ethernet address: f4:90:ea:01:cf:f3
[1] ax0: xgbe_config_sph_mode: SPH disabled in channel 0
[1] ax0: xgbe_config_sph_mode: SPH disabled in channel 1
[1] ax0: xgbe_config_sph_mode: SPH disabled in channel 2
[1] ax0: RSS Enabled
[1] ax0: Receive checksum offload Enabled
[1] ax0: VLAN filtering Enabled
[1] ax0: VLAN Stripping Enabled
[1] ax0: Checking GPIO expander validity
[1] ax0: GPIO configuration valid
[1] ax0: xgbe_phy_sfp_signals: port_sfp_inputs: 0x2
[1] ax0: SFP detected:
[1] ax0:   vendor:    Uptimed         
[1] ax0:   part number:    UP-TR-10G-RJ45-C
[1] ax0:   revision level: 1   
[1] ax0:   serial number:  UPC5TX4604054   
[1] ax0: netmap queues/slots: TX 3/512, RX 3/512
[1] ax1: <AMD 10 Gigabit Ethernet Driver> mem 0xd0020000-0xd003ffff,0xd0000000-0xd001ffff,0xd0080000-0xd0081fff at device 0.2 on pci12
[1] ax1: Using 512 TX descriptors and 512 RX descriptors
[1] ax1: Using 3 RX queues 3 TX queues
[1] ax1: Using MSI-X interrupts with 7 vectors
[1] ax1: Ethernet address: f4:90:ea:01:cf:f4
[1] ax1: xgbe_config_sph_mode: SPH disabled in channel 0
[1] ax1: xgbe_config_sph_mode: SPH disabled in channel 1
[1] ax1: xgbe_config_sph_mode: SPH disabled in channel 2
[1] ax1: RSS Enabled
[1] ax1: Receive checksum offload Enabled
[1] ax1: VLAN filtering Enabled
[1] ax1: VLAN Stripping Enabled
[1] ax1: xgbe_phy_rx_reset: firmware mailbox reset performed
[1] ax1: Checking GPIO expander validity
[1] ax1: GPIO configuration valid
[1] ax1: xgbe_phy_sfp_signals: port_sfp_inputs: 0x2
[1] ax1: SFP detected:
[1] ax1:   vendor:    Uptimed         
[1] ax1:   part number:    UP-TR-10G-RJ45-C
[1] ax1:   revision level: 1   
[1] ax1:   serial number:  UPC5TX4604055   
[1] ax1: netmap queues/slots: TX 3/512, RX 3/512
[1] isab0: <PCI-ISA bridge> at device 20.3 on pci0
[1] isa0: <ISA bus> on isab0
[1] uart2: <16x50 with 256 byte FIFO> iomem 0xfedc9000-0xfedc9fff,0xfedc7000-0xfedc7fff irq 3 on acpi0
[1] ns8250: UART FCR is broken
[1] uart2: console (115384,n,8,1)
[1] hwpstate0: <Cool`n'Quiet 2.0> on cpu0
[1] cpufreq0: <CPU frequency control> on cpu0
[1] Timecounter "TSC-low" frequency 1097937895 Hz quality 1000
[1] Timecounters tick every 1.000 msec
[1] ugen0.1: <AMD XHCI root HUB> at usbus0
[1] ugen1.1: <AMD XHCI root HUB> at usbus1
[1] uhub0 on usbus0
[1] uhub1 on usbus1
[1] uhub0: <AMD XHCI root HUB, class 9/0, rev 3.00/1.00, addr 1> on usbus0
[1] uhub1: <AMD XHCI root HUB, class 9/0, rev 3.00/1.00, addr 1> on usbus1
[2] ax1: Link is DOWN
[2] ax0: Link is DOWN
[3] ZFS filesystem version: 5
[3] ZFS storage pool version: features support (5000)
[3] nda0 at nvme0 bus 0 scbus0 target 0 lun 1
nda0: <TS256GMTE712A 82B2W2AA J282220173>
nda0: Serial Number J282220173
nda0: nvme version 1.4
[3] nda0: 244198MB (500118192 512 byte sectors)
[3] Trying to mount root from zfs:zroot/ROOT/default []...
[3] uhub1: 3 ports with 3 removable, self powered
[3] uhub0: 8 ports with 8 removable, self powered
[3] pid 30 (zpool) is attempting to use unsafe AIO requests - not logging anymore
#5
Okay, it seems I am stuck(-> another post) at using the Wireguard inside (which does not work). From the outside it is working. Still not able to solve THAT problem, but this one here is solved, thanks.
#6
So step by step things go forward but not fully working.

I am really confused here a bit:

- ACME script says exit 0, certificate renewed.
- Automation (i.e. copy the certs to the client in question) says "yeah all is well"
- HOWEVER, the certificate has a current filedate on the client system, but contains the old, unchanged certificate
- If I select "reimport" in the "certificate" section of the acme client, obviously the old certificate (which is not valid anymore) is imported.

And now the biggie:

In /var/etc/acme-client/certs/xxxx/ *the new and refreqeshed client is present.

I also used the "reset" as recommended before for the settings. I was afraid it would delete my settings (which it did not), but it did no seem to have any effect.

On top of that, under "certificates" all certificates sho "unknown" or "not issued" ("Ausstehend", "unbekannt").

I am really out of ideas as the scrip and the log shows no error, it even seems to touch the right certificate, but it does not renew the certificate at the client.

TL;DR:
Logging says renewal and automation works fine. Locally in /var/etc/acme-client/ all the new certificates are installed, in the Webgui there is mentioning of any updates done and when copying the certificate to a client host, the "old" certificate is copied, that does not even exist on file anymore.

No clue what is happening and why not the new certificate is copied or imported in the webgui.
#7
Hi

I use in my setup a number of mobile devices running VPN clients in a local WIFI.

With OpenVPN it is no problem to stay connected with the VPN "inside" the local WIFI. With Wireguard I do not get any "Handshakes", i.e. it does not work. It works perfectly well from outside the "inside" network of the OPNSense router.

Is there any special setting in the firewall rules to use Wireguard from "inside"? The logging is unfortunately miserable so I have no idea why it does not work.
#8
This never get too boring here. So, after being blocked for 168hours, I was able to reissue the certifcate. BUT and this is the problem

- The webgui and log said "all is well"
- In the "certifiacte" section it is shown as "verfication failed"
- On the command line of the opnsense router I was able to run it, and install it manually on the host in question. So the certificate is fine
- "Reimport" of the certificate does not yield the refreshed one.
- The log file of the ACME client shows it is all well

2026-07-24T14:08:15
opnsense-business
AcmeClient: imported ACME CA: YR1 (6a6355af8c3b6)
2026-07-24T13:46:01
opnsense-business
AcmeClient: running automation (configd): Change_rights_Certificate
2026-07-24T13:46:01
opnsense-business
AcmeClient: running automation (configd): Change_Ownership_Certificate
2026-07-24T13:45:59
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-iKI0mG' to 'rocket.brace.de.key.pem'
2026-07-24T13:45:59
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.key.pem'
2026-07-24T13:45:58
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-6pka5k' to 'rocket.brace.de.fullchain.pem'
2026-07-24T13:45:58
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.fullchain.pem'
2026-07-24T13:45:57
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-94mTkH' to 'rocket.brace.de.cert.pem'
2026-07-24T13:45:57
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.cert.pem'
2026-07-24T13:45:56
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-oKGIEZ' to 'rocket.brace.de.ca.pem'
2026-07-24T13:45:56
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.ca.pem'
2026-07-24T13:45:51
opnsense-business
AcmeClient: running automation (configd): CopyCerts2Rocket
2026-07-24T13:45:51
opnsense-business
AcmeClient: running automations for certificate: rocket.brace.de
2026-07-24T13:45:47
opnsense-business
AcmeClient: imported ACME CA: YR1 (6a63506bbeb80)
2026-07-24T13:45:23
opnsense-business
AcmeClient: running automation (configd): Change_rights_Certificate
2026-07-24T13:45:22
opnsense-business
AcmeClient: running automation (configd): Change_Ownership_Certificate
2026-07-24T13:45:21
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-01Qt4t' to 'rocket.brace.de.key.pem'
2026-07-24T13:45:21
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.key.pem'
2026-07-24T13:45:20
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-nR04tT' to 'rocket.brace.de.fullchain.pem'
2026-07-24T13:45:20
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.fullchain.pem'
2026-07-24T13:45:19
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-0eqr8Z' to 'rocket.brace.de.cert.pem'
2026-07-24T13:45:19
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.cert.pem'
2026-07-24T13:45:17
opnsense-business
AcmeClient: Uploading file '/tmp/sftp-upload-o7Dai8' to 'rocket.brace.de.ca.pem'
2026-07-24T13:45:17
opnsense-business
AcmeClient: SFTP upload will not preserve file modification time for 'rocket.brace.de.ca.pem'
2026-07-24T13:45:13
opnsense-business
AcmeClient: running automation (configd): CopyCerts2Rocket
2026-07-24T13:45:13
opnsense-business
AcmeClient: running automations for certificate: rocket.brace.de
2026-07-24T13:43:20
opnsense-business
AcmeClient: imported ACME CA: YR1 (6a634fd8e17a9)
2026-07-24T13:43:20
opnsense-business
AcmeClient: successfully issued/renewed certificate: rocket.brace.de
2026-07-24T13:43:18
opnsense-business
AcmeClient: AcmeClient: The shell command returned exit code '0': '/usr/local/sbin/acme.sh --issue --syslog 6 --log-level 2 --server 'letsencrypt' --alpn --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/616731d690b683.11437695' --certpath '/var/etc/acme-client/certs/616731d690b683.11437695/cert.pem' --keypath '/var/etc/acme-client/keys/616731d690b683.11437695/private.key' --capath '/var/etc/acme-client/certs/616731d690b683.11437695/chain.pem' --fullchainpath '/var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem' --domain 'rocket.brace.de' --days '30' --force --keylength '4096' --tlsport '43581' --accountconf '/var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf''
2026-07-24T13:43:12
opnsense-business
AcmeClient: using challenge type: HTTP-Challenge_TLS
2026-07-24T13:43:12
opnsense-business
AcmeClient: using IPv4 address: 192.168.179.40
2026-07-24T13:43:12
opnsense-business
AcmeClient: using IPv4 address: 87.191.224.208
2026-07-24T13:43:12
opnsense-business
AcmeClient: using IPv4 address: 217.91.66.204
2026-07-24T13:43:12
opnsense-business
AcmeClient: account config is valid (CERT_HOME): BRACE_OPN
2026-07-24T13:43:12
opnsense-business
AcmeClient: account is registered: BRACE_OPN
2026-07-24T13:43:12
opnsense-business
AcmeClient: using CA: letsencrypt
2026-07-24T13:43:12
opnsense-business
AcmeClient: issue certificate: rocket.brace.de
2026-07-24T00:00:01
opnsense-business
AcmeClient: ignoring disabled certificate: directory1.brace.de
2026-07-24T00:00:00
opnsense-business
AcmeClient: ignoring disabled certificate: rocket.brace.de
2026-07-24T00:00:00
opnsense-business
AcmeClient: ignoring disabled certificate: rocket.brace.de
2026-07-24T00:00:00
opnsense-business
AcmeClient: ignoring disabled certificate: groupware.brace.de
2026-07-24T00:00:00
opnsense-business
AcmeClient: issue/renewal not required for certificate: rocket.brace.de

In the firewall log however I get those errormessages:

The DNS query name does not exist: acme-v01-2.api.letsencrypt.org. [for Letsencrypt_certbot]
I cannot access these sites via browser.

The ACME.log also seems to be doing well:
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Installing full chain to: /var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Installing key to: /var/etc/acme-client/keys/616731d690b683.11437695/private.key
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Installing CA to: /var/etc/acme-client/certs/616731d690b683.11437695/chain.pem
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Installing cert to: /var/etc/acme-client/certs/616731d690b683.11437695/cert.pem
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] And the full-chain cert is in: ␛[1;32m/var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/fullchain.cer␛[0m
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] The intermediate CA cert is in: ␛[1;32m/var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/ca.cer␛[0m
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Your cert key is in: ␛[1;32m/var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.key␛[0m
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Your cert is in: ␛[1;32m/var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.cer␛[0m
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] ␛[1;32mCert success.␛[0m
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/058280df044c612c1ee8ad643b58f2c49a06';
2026-07-24T13:45:29
acme.sh
[Fri Jul 24 13:45:29 CEST 2026] Downloading cert.
2026-07-24T13:45:26
acme.sh
[Fri Jul 24 13:45:26 CEST 2026] Le_OrderFinalize='https://acme-v02.api.letsencrypt.org/acme/finalize/237870340/536133903845';
2026-07-24T13:45:26
acme.sh
[Fri Jul 24 13:45:26 CEST 2026] Let's finalize the order.
2026-07-24T13:45:26
acme.sh
[Fri Jul 24 13:45:26 CEST 2026] Verification finished, beginning signing.
2026-07-24T13:45:26
acme.sh
[Fri Jul 24 13:45:26 CEST 2026] rocket.brace.de is already verified, skipping tls-alpn-01.
2026-07-24T13:45:26
acme.sh
[Fri Jul 24 13:45:26 CEST 2026] Getting webroot for domain='rocket.brace.de'
2026-07-24T13:45:24
acme.sh
[Fri Jul 24 13:45:24 CEST 2026] Single domain='rocket.brace.de'
2026-07-24T13:45:24
acme.sh
[Fri Jul 24 13:45:23 CEST 2026] Standalone alpn mode.
2026-07-24T13:45:23
acme.sh
[Fri Jul 24 13:45:23 CEST 2026] Using CA: https://acme-v02.api.letsencrypt.org/directory
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Installing full chain to: /var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Installing key to: /var/etc/acme-client/keys/616731d690b683.11437695/private.key
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Installing CA to: /var/etc/acme-client/certs/616731d690b683.11437695/chain.pem
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Installing cert to: /var/etc/acme-client/certs/616731d690b683.11437695/cert.pem
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] And the full-chain cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/fullchain.cer
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] The intermediate CA cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/ca.cer
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Your cert key is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.key
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Your cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.cer
2026-07-24T13:43:18
acme.sh
[Fri Jul 24 13:43:18 CEST 2026] Cert success.
2026-07-24T13:43:17
acme.sh
[Fri Jul 24 13:43:17 CEST 2026] Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/053ad6410a898d89bb5327782351246cd6e0';
2026-07-24T13:43:17
acme.sh
[Fri Jul 24 13:43:17 CEST 2026] Downloading cert.
2026-07-24T13:43:15
acme.sh
[Fri Jul 24 13:43:15 CEST 2026] Le_OrderFinalize='https://acme-v02.api.letsencrypt.org/acme/finalize/237870340/536133362855';
2026-07-24T13:43:15
acme.sh
[Fri Jul 24 13:43:15 CEST 2026] Let's finalize the order.
2026-07-24T13:43:15
acme.sh
[Fri Jul 24 13:43:15 CEST 2026] Verification finished, beginning signing.
2026-07-24T13:43:15
acme.sh
[Fri Jul 24 13:43:15 CEST 2026] rocket.brace.de is already verified, skipping tls-alpn-01.
2026-07-24T13:43:15
acme.sh
[Fri Jul 24 13:43:15 CEST 2026] Getting webroot for domain='rocket.brace.de'
2026-07-24T13:43:13
acme.sh
[Fri Jul 24 13:43:13 CEST 2026] Single domain='rocket.brace.de'
2026-07-24T13:43:13
acme.sh
[Fri Jul 24 13:43:13 CEST 2026] Standalone alpn mode.


I did not reset the ACME client after update - please correct me if I am wrong - as it does not seem to be necessary. In the file system the correct certificate is stored. So where might be the problem here? Any ideas?
#9
26.1, 26,4 Series / Re: Wireguard Stopped Working
July 28, 2026, 08:42:40 AM
It seems as after the last update (which did not restart the router) DHCP and some other services hang but not giving any message about (e.g. DHCP page was not accessible via webgui). After a restart the problem seems to be resolved.
#10
26.1, 26,4 Series / Wireguard Stopped Working
July 20, 2026, 09:41:43 AM
Hi, all of a sudden wireguard stopped working:

The protocol says:

/usr/local/opnsense/scripts/wireguard/wg-service-control.php: ROUTING: not a valid opt10 interface gateway address: 'missing'
Version:
26.4.1p1_3-amd64
(Business Edition)

The interface mentions "opt10" is connected to wg0.

I have not made any updates the last 9 days and it worked fine until yesterday.

What can be the problem here?
#11
Thank you dseven.

One more thing in case somebody else has those problems. The ssh keys change, too, so they are not imported in the backup. That means, if you transfer e.g. a cert with SFTP, you must also include the new .pub key on the target system.
#12
Quote from: dseven on July 16, 2026, 12:29:34 PMDid you do the "Reset ACME client" thing after moving to the new appliance?

BTW, thanks for the reminder - I just did a new installation of 26.7 and imported my config, but I hadn't remembered this ACME reset step ;)


I most definetly did not... and I am not sure how to do it? I will look for a suitable button but if you have a hint...

Current status (sorry for that but sometimes posting my problems here starts a new though process and I retry) is that it seems that the account have not been migrated. So no account information available.

I could just click at the "register account" button besides the accounts and they seem to have been recreated in the file system.

When running the command now at the command line there seem to be no error messages anymore. Unfortunately I cleverly used the "normal" account for the inital testing and Let's Encrypt is now pretty strict, locking me out for 7 days to renew the "real" certificate.

So @dseven I believe it would at this stage not a good anymore the reset. I have to recheck in 7 days if the certificate is really renewed, and then I might come back to that issue.

Thank you.
#13
Follow Up: I asked some AI and it mentioned to issue the "faulty" command directly on the firefwall, which i did.

Now, it throws a couple of errormessages

ouch: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
chmod: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot open /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot create /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
touch: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
chmod: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot open /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot create /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf: No such file or directory


It seems as the account directory is not existing at all.

If I switch the the "Testing" account at let's encrypt the acme.sh comand is successfully running (via TLS challenge even)

2026-07-16T12:32:29
opnsense-business
AcmeClient: AcmeClient: The shell command returned exit code '0': '/usr/local/sbin/acme.sh --issue --syslog 6 --log-level 2 --server 'letsencrypt_test' --alpn --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/616731d690b683.11437695' --certpath '/var/etc/acme-client/certs/616731d690b683.11437695/cert.pem' --keypath '/var/etc/acme-client/keys/616731d690b683.11437695/private.key' --capath '/var/etc/acme-client/certs/616731d690b683.11437695/chain.pem' --fullchainpath '/var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem' --domain 'rocket.brace.de' --days '30' --force --keylength '4096' --tlsport '43581' --accountconf '/var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf''

BUT if I start it on the command line, I get the same error messages about the missing account:

touch: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
chmod: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot open /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot create /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
touch: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
chmod: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot open /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
/usr/local/sbin/acme.sh: cannot create /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory
grep: /var/etc/acme-client/accounts/627608ae6954b6.64573180_stg/account.conf: No such file or directory

Just my thinking: is it possible that during migration from the community edition to the business edition everything BUT the accounts have been imported?

#14
Hi there.
I have installed and up and running the ACME plugin on the OPNSense community edition for some years. It refreshes a certificate for a webserver that has no external access (rocket chat) and copies it via SFTP to that system, then does a few file operations to get it installed. I used the HTTP Challenge.

Earlier this year I replaced the appliance with a new one, and wen to OPNSense business edition 25.10. That did not seem to be a problem at the time, basically everthing worked fine. Later then, it upgraded to 26.4..

*However* I noticed as of today, a couple of months later, that the certificates did not get renewed. Now, my memory is probably not the best, but I am kind of 80% sure that I checked after switching to the new appliance if the certificate was updated and believe to remember it did.

When I checked the firewall rules, I found that port 80 was not open (anymore?) at the external interfaces.

Long story short, I do not get the certificates refreshed.

I tried HTTP and TLS challenge and opening the ports, then the protocol say:

HTTP challenge:

2026-07-16T12:00:36 opnsense-business
AcmeClient: AcmeClient: The shell command returned exit code '1': '/usr/local/sbin/acme.sh --issue --syslog 6 --log-level 2 --server 'letsencrypt' --webroot /var/etc/acme-client/challenges --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/616731d690b683.11437695' --certpath '/var/etc/acme-client/certs/616731d690b683.11437695/cert.pem' --keypath '/var/etc/acme-client/keys/616731d690b683.11437695/private.key' --capath '/var/etc/acme-client/certs/616731d690b683.11437695/chain.pem' --fullchainpath '/var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem' --domain 'rocket.brace.de' --days '30' --force --keylength '4096' --accountconf '/var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf''

When using the TLS Challenge:

2026-07-16T12:01:06
opnsense-business
AcmeClient: AcmeClient: The shell command returned exit code '1': '/usr/local/sbin/acme.sh --issue --syslog 6 --log-level 2 --server 'letsencrypt' --alpn --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/616731d690b683.11437695' --certpath '/var/etc/acme-client/certs/616731d690b683.11437695/cert.pem' --keypath '/var/etc/acme-client/keys/616731d690b683.11437695/private.key' --capath '/var/etc/acme-client/certs/616731d690b683.11437695/chain.pem' --fullchainpath '/var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem' --domain 'rocket.brace.de' --days '30' --force --keylength '4096' --tlsport '43581' --accountconf '/var/etc/acme-client/accounts/5eda4b1803af18.28646449_prod/account.conf''


Under "Accounts" it claims the account is "OK" in the status.


I was not able to find a HOWTO for setting up the DNS-01 challenge (all of them omit how to create the nsupdate key and which exact format I need to put it into the DNS TXT records) so I gave up on that. If anybody has a howto for an idiot like me to get it created and installed I'll be greatful and will try.


In the ACME Log of OPNSense however, it seem to be working all well:

2026-07-16T12:00:35 acme.sh
[Thu Jul 16 12:00:35 CEST 2026] Single domain='rocket.brace.de'
2026-07-16T12:00:35 acme.sh
[Thu Jul 16 12:00:35 CEST 2026] Using CA: https://acme-v02.api.letsencrypt.org/directory
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Installing full chain to: /var/etc/acme-client/certs/616731d690b683.11437695/fullchain.pem
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Installing key to: /var/etc/acme-client/keys/616731d690b683.11437695/private.key
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Installing CA to: /var/etc/acme-client/certs/616731d690b683.11437695/chain.pem
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Installing cert to: /var/etc/acme-client/certs/616731d690b683.11437695/cert.pem
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] And the full-chain cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/fullchain.cer
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] The intermediate CA cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/ca.cer
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Your cert key is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.key
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Your cert is in: /var/etc/acme-client/cert-home/616731d690b683.11437695/rocket.brace.de/rocket.brace.de.cer
2026-07-16T11:50:30 acme.sh
[Thu Jul 16 11:50:30 CEST 2026] Cert success.
2026-07-16T11:50:29 acme.sh
[Thu Jul 16 11:50:29 CEST 2026] Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/0517aa711b64efc1671ef56cccab97cf1583';
2026-07-16T11:50:29 acme.sh
[Thu Jul 16 11:50:29 CEST 2026] Downloading cert.
2026-07-16T11:50:28 acme.sh
[Thu Jul 16 11:50:28 CEST 2026] Le_OrderFinalize='https://acme-v02.api.letsencrypt.org/acme/finalize/3539327496/532898622926';
2026-07-16T11:50:28 acme.sh
[Thu Jul 16 11:50:28 CEST 2026] Let's finalize the order.
2026-07-16T11:50:28 acme.sh
[Thu Jul 16 11:50:28 CEST 2026] Verification finished, beginning signing.
2026-07-16T11:50:28 acme.sh
[Thu Jul 16 11:50:28 CEST 2026] rocket.brace.de is already verified, skipping http-01.
2026-07-16T11:50:28 acme.sh
[Thu Jul 16 11:50:28 CEST 2026] Getting webroot for domain='rocket.brace.de'
2026-07-16T11:50:26 acme.sh
[Thu Jul 16 11:50:26 CEST 2026] Single domain='rocket.brace.de'


Shouldn't that say that the certificate was in fact renewed and should be on OPNSense? However, in the certificate section it is displayed as "überprüfung fehlgeschlagen" (renewal failed or to whatever this is translated)

Is there anything I can do to fix that?

Thanks.
#15
Hi nero355 thanks for not burning my post down.

I would not have posted it here if I would not think that it is some information missing or mislabeled to include it in (any) Linux setup.

The problem was (as usually) sitting in front of my monitor as I misread "public key" and "private key" and entered them vice-versa into the GUI. This lead to a connection, well not being able to be made. After switching both keys it suddenly worked to my utmost surprise pretty well.

Thanks for not giving up on me and my questions.

- Edited because problem was solved and the removed content would not have any value -