Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - ig-it1342

#1
Hello everyone,

I found the issue finally, it seems that the WebUI class is reported as up-to-date if the values only differ in the selected certificate ID.
Since the cert ID is different and it is not found on the target host, it is therefore not considered "different", so it shows up-to-date.

If the certificate exists but contains different values, it is considered to be different.

To fix it for my case, the solution was to set some unrelated value in the WebGUI configuration of the target to a different value, and then resynchronizing.

Maybe there is a bug in the logic of OPNCentral related to certificate comparison?

Anyways, thanks for the help
#2
Sorry for the late reply,

no matter which certificate is configured (even a new self-signed one), the push is not working at all, but the Provisioning still displays green.

#3
Hello,

okay, that is indeed strange. We double checked again all the values, and everything seems correct, however it simply does not want to push.

This is the case for all of our 8 firewalls, so the other sites also do not receive a valid certificate.

Is there maybe an internal log / view of the sync process, such that we could debug the issue further?

Thanks in advance
#4
Hi everyone,

recently, the update mechanism for pushing SSL certificates to OPNCentral-managed hosts from the main host seems to have stopped working.

Unfortunately, I don't precisely know which versions broke the functionality, however it is not working at least on the latest 26.4.1 patch.

The host is configured as following:

This is the certificate configured on the provisioning:

The provisioning for Web GUI is apparently complete (no new data):

However, the certificate is not set in the Web GUI config of the Host, and is nowhere to be found in the Certificate store:



Both firewalls were restarted and updated, and I manually tried to start the provisioning, but nothing happens.

No related log lines / errors are present in the system log of either firewalls.

Has anyone experienced the same issue recently?

---

Versions: Both firewalls are running


OPNsense 26.4.1-amd64
FreeBSD 14.3-RELEASE-p15
OpenSSL 3.0.21


with plugin versions

os-OPNBEcore    1.8_2
os-OPNcentral    1.12_2