Self signed Certificate renewal Legacy version OPNSENSE VPN

Started by zuma48, July 28, 2026, 11:35:07 PM

Previous topic - Next topic
Hi, new to this VPN server OPNsense 23.1.11
I know it's an old version; it is just used for VPN.
The server Cert is due to expire.
I created a new self-signed certificate Authority
Confirming steps;
1. Do I need to revoke the current one for the new one to take over, or is it fine with the new dates? If so how? In the certificate section?
2 Do I need to issue new certificates for the users since they were issued under the current expiring Server cert, or just make sure they do not have expiring certs?
3 Anything else required? And do I need to reboot it for any changes or adds? I see there are 149 certificates under the current cert...

Thank you in advance for any help!

Quote from: zuma48 on July 28, 2026, 11:35:07 PMI created a new self-signed certificate Authority
Was the existing one expired?

Generally a CA should have a long life time, e.g. 20+ y and there should rarely be a need to renew it.

You use the CA to issue both, the server certificate and the client certificates.
If you have replaced the CA, you have to reassign all again and assign the new CA and server cert to the OpenVPN server and give the client certs to the clients.

If just the server or client certificate expired, you only need to edit the cert, select "reissue and replace" and set new key values if you want. In case of server cert, you have to restart the VPN server after.

Here is the auth, the 2024- with an end date is first then the one i JUST CREATED.

opnsense-internal-ca-2024   YES    self-signed    129    emailAddress=p@X.com, ST=Florida, O=X, L=X, CN=internal-ca-2024, C=US
    Valid From:   Sun, 05 May 2024 21:36:22 +0000
    Valid Until:   Sat, 08 Aug 2026 21:36:22 +0000

Opensense-Certificate-2026-2029   YES    self-signed    0    emailAddress=d@oX.com, ST=Florida, O=X, L=X, CN=internal-ca-2026-2029, C=US
    Valid From:   Tue, 28 Jul 2026 13:35:38 +0000
    Valid Until:   Mon, 30 Oct 2028 13:35:38 +0000

Did I not need to create this?

Under Certificates;
 2025 Cert

CA: No, Server: Yes   opnsense-internal-ca-2024    emailAddress=plove@omniadvertising.com, ST=Florida, O=Omni Advertising, L=Boca Raton, CN=server-cert-2024, C=US
    Valid From:   Tue, 18 Mar 2025 15:12:54 +0000
    Valid Until:   Fri, 16 Mar 2035 15:12:54 +0000

This was created...