OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Let's Encrypt: Doesn't seem to know it's working?
« previous next »
  • Print
Pages: [1] 2

Author Topic: Let's Encrypt: Doesn't seem to know it's working?  (Read 9469 times)

lrosenman

  • Full Member
  • ***
  • Posts: 197
  • Karma: 8
    • View Profile
Let's Encrypt: Doesn't seem to know it's working?
« on: April 04, 2019, 03:35:59 pm »
I've got a valid LE cert on my FW, but the certifcates in the GUI show validation failed, and I can't seem to find the cronjob.

ideas?

(I force renewed from the GUI, hence the new issue date).
Logged

FingerlessGloves

  • Full Member
  • ***
  • Posts: 114
  • Karma: 11
    • View Profile
    • FingerlessGloves
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #1 on: April 04, 2019, 08:30:25 pm »
So chrome/firefox, shows a letsencrypt certificate?

I noticed your domain home-fw.lerctr.org points to a local network address 192.168.200.11
Logged
Adventuring through internet pipes
My Blog

lrosenman

  • Full Member
  • ***
  • Posts: 197
  • Karma: 8
    • View Profile
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #2 on: April 04, 2019, 08:35:31 pm »
yep.

https://www.lerctr.org/~ler/cert.png

(since the attachment limit is too small).

I'm *VERY* knowledgeable, and a FreeBSD ports committer FWIW.
Logged

FingerlessGloves

  • Full Member
  • ***
  • Posts: 114
  • Karma: 11
    • View Profile
    • FingerlessGloves
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #3 on: April 04, 2019, 08:48:01 pm »
What validation method you using?
Logged
Adventuring through internet pipes
My Blog

lrosenman

  • Full Member
  • ***
  • Posts: 197
  • Karma: 8
    • View Profile
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #4 on: April 04, 2019, 08:49:20 pm »
dns-01 / nsupdate to my nameserver.  NOTE: acme issues the cert, but the GUI doesn't seem to know that.
Logged

FingerlessGloves

  • Full Member
  • ***
  • Posts: 114
  • Karma: 11
    • View Profile
    • FingerlessGloves
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #5 on: April 04, 2019, 09:03:31 pm »
If you look in to the source code (https://github.com/opnsense/plugins/blob/a18c04031f682eb5bf77487bb4d5b897ec34ed88/security/acme-client/src/opnsense/scripts/OPNsense/AcmeClient/certhelper.php) line 226 is the part of the if statement I think your getting.

So if you follow the run_acme_validation() function it builds the command to check the status of the certificate, so the check must be failing due to some reason. The logs might help you there.

You haven't removed the TXT record have you?
Logged
Adventuring through internet pipes
My Blog

lrosenman

  • Full Member
  • ***
  • Posts: 197
  • Karma: 8
    • View Profile
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #6 on: April 04, 2019, 10:01:39 pm »
The DNS-01 challenge creates, then auths, then deletes the TXT record, so it will *NOT* exist, except during the renewal process.

I'll have to go look at the script later.

Logged

lrosenman

  • Full Member
  • ***
  • Posts: 197
  • Karma: 8
    • View Profile
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #7 on: April 04, 2019, 10:36:40 pm »
If it's looking for dns01, but the validation method is actually DNS-01, that's a problem.....

Logged

FingerlessGloves

  • Full Member
  • ***
  • Posts: 114
  • Karma: 11
    • View Profile
    • FingerlessGloves
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #8 on: April 06, 2019, 02:08:18 pm »
Quote from: lrosenman on April 04, 2019, 10:01:39 pm
The DNS-01 challenge creates, then auths, then deletes the TXT record, so it will *NOT* exist, except during the renewal process.

I'll have to go look at the script later.

I'm no expert but I thought the DNS record had to stay there?

Quote from: lrosenman on April 04, 2019, 10:36:40 pm
If it's looking for dns01, but the validation method is actually DNS-01, that's a problem.....

I think they just remove the - in the logic.
Logged
Adventuring through internet pipes
My Blog

lrosenman

  • Full Member
  • ***
  • Posts: 197
  • Karma: 8
    • View Profile
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #9 on: April 06, 2019, 06:09:27 pm »
 
Quote from: Jonny on April 06, 2019, 02:08:18 pm

I'm no expert but I thought the DNS record had to stay there?
Nope.  The record is created by the NSUPDATE helper, checked by acme during cert authorization, they removed
by the NSUPDATE helper.
Quote from: Jonny on April 06, 2019, 02:08:18 pm
Quote from: lrosenman on April 04, 2019, 10:36:40 pm
If it's looking for dns01, but the validation method is actually DNS-01, that's a problem.....

I think they just remove the - in the logic.
and what about cAsE-sEnSiTiViTy?
Logged

pingus

  • Newbie
  • *
  • Posts: 25
  • Karma: 2
    • View Profile
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #10 on: April 06, 2019, 07:40:07 pm »
Have the same problem: https://forum.opnsense.org/index.php?topic=11350.msg51317#msg51317
Logged

lrosenman

  • Full Member
  • ***
  • Posts: 197
  • Karma: 8
    • View Profile
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #11 on: April 06, 2019, 07:42:16 pm »
YAY!  it's not just me :)
Logged

bulmaro

  • Newbie
  • *
  • Posts: 49
  • Karma: 13
    • View Profile
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #12 on: April 09, 2019, 11:26:02 pm »
I have the same problem with my certificate, someone already solved the problem?
Logged

lrosenman

  • Full Member
  • ***
  • Posts: 197
  • Karma: 8
    • View Profile
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #13 on: April 09, 2019, 11:28:29 pm »
Not yet.  Waiting for someone with some clue to chime in.
Logged

bulmaro

  • Newbie
  • *
  • Posts: 49
  • Karma: 13
    • View Profile
Re: Let's Encrypt: Doesn't seem to know it's working?
« Reply #14 on: April 11, 2019, 06:59:37 pm »
I inform you, with the last update 19.1.6 the certificate no longer marks error
Logged

  • Print
Pages: [1] 2
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Let's Encrypt: Doesn't seem to know it's working?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2