Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Virtual private networks
»
Install CA as standard user
« previous
next »
Print
Pages:
1
[
2
]
Author
Topic: Install CA as standard user (Read 4700 times)
robertkwild
Jr. Member
Posts: 87
Karma: 3
Re: Install CA as standard user
«
Reply #15 on:
February 03, 2022, 04:22:50 pm »
Will it work even tho I'm using the free no ip and only got one hostname
Edit - just went on no ip and have to pay extra to get a txt record for dns challenge
So I will need to open port 80 to fw
What do you suggest, get a txt record or open port 80?
«
Last Edit: February 03, 2022, 05:04:39 pm by robertkwild
»
Logged
atom
Full Member
Posts: 207
Karma: 4
Re: Install CA as standard user
«
Reply #16 on:
February 03, 2022, 05:33:35 pm »
I would prefer the 3rd variant and take my own CA.
Logged
robertkwild
Jr. Member
Posts: 87
Karma: 3
Re: Install CA as standard user
«
Reply #17 on:
February 03, 2022, 05:38:52 pm »
You mean just export the self signed CA?
Logged
atom
Full Member
Posts: 207
Karma: 4
Re: Install CA as standard user
«
Reply #18 on:
February 03, 2022, 06:21:32 pm »
Yes, but you had some restrictions to install certificates as admin.
Logged
robertkwild
Jr. Member
Posts: 87
Karma: 3
Re: Install CA as standard user
«
Reply #19 on:
February 03, 2022, 09:04:21 pm »
not admin, as a standard user, they just couldnt import the CA
i really dont want to expose my firewall to WAN on any ports
i do port forwards to other servers on port 80 443
thanks so much atom for your help in this!!!!!!!!!!!
Logged
atom
Full Member
Posts: 207
Karma: 4
Re: Install CA as standard user
«
Reply #20 on:
February 04, 2022, 09:56:59 am »
You have the choice: Either install the certificate in Windows once as an admin (the best method in my opinion) or regularly renew the certificate with ACME - then either via DNS (no port to open) or HTTP (port 80 / 443) must be open.
Logged
robertkwild
Jr. Member
Posts: 87
Karma: 3
Re: Install CA as standard user
«
Reply #21 on:
February 04, 2022, 03:23:49 pm »
yeah i agree its a lot safer to use self signed cert instead of acme especially on firewall
Logged
Patrick M. Hausen
Hero Member
Posts: 6826
Karma: 573
Re: Install CA as standard user
«
Reply #22 on:
February 04, 2022, 06:23:41 pm »
Why should using ACME on the firewall pose any risk? If you use DNS challenge, it's perfectly safe ...
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
robertkwild
Jr. Member
Posts: 87
Karma: 3
Re: Install CA as standard user
«
Reply #23 on:
February 08, 2022, 02:38:11 pm »
success!!!!!!!!!!
installed/configured the ACME client on my opnsense, it got the certs (using DNS challenge with dynu)
i then changed the cert on my ipsec server to the ACME client one instead of my self signed one
at a different location (at work) i did a test, i spinned up a vm, created a standard user, logged in as standard user
created the ikev2 vpn and i could connect straight away without installing any cert!!!!!
«
Last Edit: February 08, 2022, 02:51:39 pm by robertkwild
»
Logged
atom
Full Member
Posts: 207
Karma: 4
Re: Install CA as standard user
«
Reply #24 on:
February 08, 2022, 02:40:55 pm »
I'm glad to hear it.
Logged
Print
Pages:
1
[
2
]
« previous
next »
OPNsense Forum
»
English Forums
»
Virtual private networks
»
Install CA as standard user