OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 21.7 Legacy Series »
  • ACME Client - Validation Failed
« previous next »
  • Print
Pages: [1]

Author Topic: ACME Client - Validation Failed  (Read 2905 times)

leacho73

  • Newbie
  • *
  • Posts: 33
  • Karma: 0
    • View Profile
ACME Client - Validation Failed
« on: December 05, 2021, 06:18:50 pm »
Hi All,

I've recently reinstalled my ACME client and removed the existing config - when I now try and request certificates, I am getting validation failed due to the HTTP-01 check using the custom port that I am using for the GUI as the lookup rather than the normal 443/SSL connection - I see the following in the logs:

Verify error:Fetching https://my.domain.com:12345/.well-known/...........

Normally I would expect the verify URL to just hit https://my.domain.com/.well-known/....

I have the HAProxy integration installed and working ok - no port forwards are set for the management port, so I'm at a loss to what is going on.

Thanks
Leacho

Logged

Fright

  • Hero Member
  • *****
  • Posts: 1777
  • Karma: 164
    • View Profile
Re: ACME Client - Validation Failed
« Reply #1 on: December 06, 2021, 08:01:32 pm »
Hi
can you share the config? I thought the http01 challenge type always uses port 80.
additionally, the plugin adds on the fly a redirecting rule to the loopback interface and the "Services: ACME Client: Settings:Local HTTP Port" port (to avoid port conflicts with other services)
Logged

5k7m4n

  • Newbie
  • *
  • Posts: 20
  • Karma: 0
    • View Profile
Re: ACME Client - Validation Failed
« Reply #2 on: January 02, 2022, 07:00:25 pm »
Having this issue and can't remember how to fix it. This post came up first in the search result.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 21.7 Legacy Series »
  • ACME Client - Validation Failed
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2