Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - arrowd

#1
I set up the ACME service on my OPNsense (v26.7.4_1 on a Protectli V1410) in the spring. The problem I describe happened at the first cert renewal, but I decided to wait for the next run to see if it repeated. The certificate was due for replacement yesterday but the cron job failed. I then ran it manually and it succeeded without my changing any setting. I have my domain DNS at Cloudflare. My TrueNAS is set up similarly and the ACME runs correctly there. This is apparently a commmon problem on OPNsense as I found at least two separate forum posts saying essentially the same thing. Neither had a solution with people just saying they would renew manually when needed. Do you think this is a permission problem? A Cloudflare problem? Thanks for reading.

Below is the log in debug format. I replaced my domain name with 'mydomainname' and my unique numbers with equal length strings of 'a','b','c','x', or 'y'. The two sets of long log lines between cron/manual runs are identical.

2026-09-24T00:00:00-04:00opnsenseAcmeClient: issue/renewal not required for certificate: opnsense.mydomainname.net

2026-09-23T13:44:08-04:00configAcmeClient: running automation (configd): Restart Web GUI
2026-09-23T13:44:08-04:00configAcmeClient: running automations for certificate: opnsense.mydomainname.net
2026-09-23T13:44:08-04:00configAcmeClient: updated ACME X.509 certificate: opnsense.mydomainname.net (ccccccccccccccc)
2026-09-23T13:44:08-04:00opnsenseAcmeClient: successfully issued/renewed certificate: opnsense.mydomainname.net
2026-09-23T13:44:08-04:00opnsenseAcmeClient: AcmeClient: The shell command returned exit code '0': '/usr/local/sbin/acme.sh --renew --syslog 7 --debug --server 'letsencrypt' --dns 'dns_cf' --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/xxxxxxxxxxxxxx.yyyyyyyy' --certpath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/cert.pem' --keypath '/var/etc/acme-client/keys/xxxxxxxxxxxxxx.yyyyyyyy/private.key' --capath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/chain.pem' --fullchainpath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/fullchain.pem' --domain 'opnsense.mydomainname.net' --days '60' --keylength '4096' --accountconf '/var/etc/acme-client/accounts/aaaaaaaaaaaaaa.bbbbbbbb_prod/account.conf''
2026-09-23T13:43:38-04:00opnsenseAcmeClient: running acme.sh command: /usr/local/sbin/acme.sh --renew --syslog 7 --debug --server 'letsencrypt' --dns 'dns_cf' --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/xxxxxxxxxxxxxx.yyyyyyyy' --certpath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/cert.pem' --keypath '/var/etc/acme-client/keys/xxxxxxxxxxxxxx.yyyyyyyy/private.key' --capath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/chain.pem' --fullchainpath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/fullchain.pem' --domain 'opnsense.mydomainname.net' --days '60' --keylength '4096' --accountconf '/var/etc/acme-client/accounts/aaaaaaaaaaaaaa.bbbbbbbb_prod/account.conf'
2026-09-23T13:43:38-04:00opnsenseAcmeClient: using challenge type: OPNsense GUI Certificate
2026-09-23T13:43:38-04:00opnsenseAcmeClient: account config is valid (CERT_HOME): OPNsense GUI Certificate
2026-09-23T13:43:38-04:00opnsenseAcmeClient: account is registered: OPNsense GUI Certificate
2026-09-23T13:43:38-04:00opnsenseAcmeClient: using CA: letsencrypt
2026-09-23T13:43:38-04:00opnsenseAcmeClient: renew certificate: opnsense.mydomainname.net
2026-09-23T13:43:38-04:00opnsenseAcmeClient: certificate must be issued/renewed: opnsense.mydomainname.net

2026-09-23T00:00:01-04:00opnsenseAcmeClient: validation for certificate failed: opnsense.mydomainname.net
2026-09-23T00:00:01-04:00opnsenseAcmeClient: domain validation failed (dns01)
2026-09-23T00:00:01-04:00opnsenseAcmeClient: AcmeClient: The shell command returned exit code '2': '/usr/local/sbin/acme.sh --renew --syslog 7 --debug --server 'letsencrypt' --dns 'dns_cf' --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/xxxxxxxxxxxxxx.yyyyyyyy' --certpath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/cert.pem' --keypath '/var/etc/acme-client/keys/xxxxxxxxxxxxxx.yyyyyyyy/private.key' --capath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/chain.pem' --fullchainpath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/fullchain.pem' --domain 'opnsense.mydomainname.net' --days '60' --keylength '4096' --accountconf '/var/etc/acme-client/accounts/aaaaaaaaaaaaaa.bbbbbbbb_prod/account.conf''
2026-09-23T00:00:00-04:00opnsenseAcmeClient: running acme.sh command: /usr/local/sbin/acme.sh --renew --syslog 7 --debug --server 'letsencrypt' --dns 'dns_cf' --home '/var/etc/acme-client/home' --cert-home '/var/etc/acme-client/cert-home/xxxxxxxxxxxxxx.yyyyyyyy' --certpath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/cert.pem' --keypath '/var/etc/acme-client/keys/xxxxxxxxxxxxxx.yyyyyyyy/private.key' --capath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/chain.pem' --fullchainpath '/var/etc/acme-client/certs/xxxxxxxxxxxxxx.yyyyyyyy/fullchain.pem' --domain 'opnsense.mydomainname.net' --days '60' --keylength '4096' --accountconf '/var/etc/acme-client/accounts/aaaaaaaaaaaaaa.bbbbbbbb_prod/account.conf'
2026-09-23T00:00:00-04:00opnsenseAcmeClient: using challenge type: OPNsense GUI Certificate
2026-09-23T00:00:00-04:00opnsenseAcmeClient: account config is valid (CERT_HOME): OPNsense GUI Certificate
2026-09-23T00:00:00-04:00opnsenseAcmeClient: account is registered: OPNsense GUI Certificate
2026-09-23T00:00:00-04:00opnsenseAcmeClient: using CA: letsencrypt
2026-09-23T00:00:00-04:00opnsenseAcmeClient: renew certificate: opnsense.mydomainname.net
2026-09-23T00:00:00-04:00opnsenseAcmeClient: certificate must be issued/renewed: opnsense.mydomainname.net

2026-09-22T00:00:00-04:00opnsenseAcmeClient: issue/renewal not required for certificate: opnsense.mydomainname.net
#2
Thanks. I hadn't seen System - Snapshots before.
#3
25.7, 25.10 Legacy Series / Purging old BE snapshots
October 25, 2025, 10:49:59 PM
I have a question about the snapshots to rollback an OPNsense version. Refer to "Safely upgrade to 22.1 beta and possibly roll back - boot environments FTW!" at https://forum.opnsense.org/index.php?topic=25540.15. I really appreciate Patrick's step by step of the process to be able to roll back if an update goes bad.

I have been using this to get to 25.7.6 and now have seven old snapshots going back to 24.7.12. I image that using 'bectl destroy' can eliminate the old ones but I would like to get a blessing from someone who knows more that I do.

So, can I enter 'bectl destroy 24.7.12' to eliminate the oldest one and not affect the later ones? Suppose for some reason I want to keep 25.1.10 but delete 25.1.12. Can I do that and then be able to return to any of the remaining ones without a problem? Thanks for any comments.
#4
I think I have the Nut service on OPNsense setup correctly now. In 'Services - Nut - Configuration - General Settings - General Nut Settings', I have 'Enabled'; 'Service Mode' = standalone, 'Name' = ups; 'Listen Address' = [localhost] & [192.168.15.1] (my OPNsense IP)'.

For 'Services - Nut - Configuration - General Settings - Nut Account Settings' and 'Services - Nut - Configuration - UPS Type', they're set as in my original post.

I now see the correct data in the Nut dashboard widget and can connect here from both my TrueNAS Core servers using 'upsc ups@192.168.15.1'. I can also use 'upsc' to see the info from those TN servers.

Next step is to set up my RPi and Win 11 PC as clients. And then do a shutdown test.
#5
I moved my OPNsense from one UPS to another. When on the first UPS, OPNsense was a NUT slave to a TrueNAS Core NUT master. Things worked well.

I need to set OPNsense as a NUT master on this UPS. (I will eventually add a RaspberryPi and a Windows 11 PC as slaves.) I am having a lot of trouble and can't find a solution after following many web leads.

If I enter "upsc ups" at a terminal prompt, I see all of the correct data for this UPS. I have the NUT widget on my dashboard but it is showing data from the old master! I tried deleting the NUT plugin and reinstalling it, but that didn't change the widget display. I feel there is some config file with the old data still in it that's being used and should be manually deleted.)

Under Services - NUT - Configuration - UPS Type, I have only USBHID-Driver enabled; all others are disabled. And in the extra arguments field I have port, vendorid, productid, serial and desc filled in.

For Services - NUT - General Settings, I have 'Enabled'; 'Service Mode' = standalone (netclient didn't work either); 'Name' = ups; 'Listen Address' = 127.0.0.1 (OPNsense address doesn't work either)

For Services - NUT - Nut Account Settings, I have 'Admin Password' = Password; 'Monitor Password' = same as former password.

Thanks for any suggestions!