Self signed Certificate renewal Legacy version OPNSENSE VPN

Started by zuma48, July 28, 2026, 11:35:07 PM

Previous topic - Next topic
Hi, new to this VPN server OPNsense 23.1.11
I know it's an old version; it is just used for VPN.
The server Cert is due to expire.
I created a new self-signed certificate Authority
Confirming steps;
1. Do I need to revoke the current one for the new one to take over, or is it fine with the new dates? If so how? In the certificate section?
2 Do I need to issue new certificates for the users since they were issued under the current expiring Server cert, or just make sure they do not have expiring certs?
3 Anything else required? And do I need to reboot it for any changes or adds? I see there are 149 certificates under the current cert...

Thank you in advance for any help!

Quote from: zuma48 on July 28, 2026, 11:35:07 PMI created a new self-signed certificate Authority
Was the existing one expired?

Generally a CA should have a long life time, e.g. 20+ y and there should rarely be a need to renew it.

You use the CA to issue both, the server certificate and the client certificates.
If you have replaced the CA, you have to reassign all again and assign the new CA and server cert to the OpenVPN server and give the client certs to the clients.

If just the server or client certificate expired, you only need to edit the cert, select "reissue and replace" and set new key values if you want. In case of server cert, you have to restart the VPN server after.