OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Auto-certificate and Chrome
« previous next »
  • Print
Pages: 1 [2] 3

Author Topic: Auto-certificate and Chrome  (Read 17274 times)

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: Auto-certificate and Chrome
« Reply #15 on: October 17, 2018, 06:33:45 pm »
You should not generate a certificate. A SSH key is generated on the command line using the following command:

ssh-keygen -t ed25519

If you use putty, you can use the puttygen tool to generate a new key pair.
Logged

balubeto

  • Jr. Member
  • **
  • Posts: 75
  • Karma: 0
    • View Profile
Re: Auto-certificate and Chrome
« Reply #16 on: October 17, 2018, 07:52:16 pm »
Quote from: fabian on October 17, 2018, 06:33:45 pm
You should not generate a certificate. A SSH key is generated on the command line using the following command:

ssh-keygen -t ed25519

If you use putty, you can use the puttygen tool to generate a new key pair.

With PuttyGen, I created a copy of keys and then tried to connect with the firewall but it displayed the "Server refused our key"message .  How come?

Thanks

Bye
Logged
balubeto

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: Auto-certificate and Chrome
« Reply #17 on: October 17, 2018, 09:04:27 pm »
then you have pasted the wrong format.. I don't have putty but I am pretty sure it supports the correct openssh format for public keys.
Logged

balubeto

  • Jr. Member
  • **
  • Posts: 75
  • Karma: 0
    • View Profile
Re: Auto-certificate and Chrome
« Reply #18 on: October 19, 2018, 05:29:30 pm »
Being able to act on the OPNsense VGA console, how do I disable the https protocol and enable the http protocol so that I can again access the GUI using the last protocol?

Thanks

Bye
Logged
balubeto

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: Auto-certificate and Chrome
« Reply #19 on: October 19, 2018, 06:46:08 pm »
It usually asks if you reconfigure an interface.
Logged

balubeto

  • Jr. Member
  • **
  • Posts: 75
  • Karma: 0
    • View Profile
Re: Auto-certificate and Chrome
« Reply #20 on: October 19, 2018, 07:15:36 pm »
Quote from: fabian on October 19, 2018, 06:46:08 pm
It usually asks if you reconfigure an interface.

I'm sorry, how do I reconfigure an interface?

Thanks

Bye
Logged
balubeto

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: Auto-certificate and Chrome
« Reply #21 on: October 19, 2018, 07:30:13 pm »
option 2 in the menu.
Logged

balubeto

  • Jr. Member
  • **
  • Posts: 75
  • Karma: 0
    • View Profile
Re: Auto-certificate and Chrome
« Reply #22 on: October 21, 2018, 10:08:25 am »

Thanks to you, I have been able to access the GUI via the http protocol.


I want, however, to use the https protocol, I created again the chain of self-certificates described by your guide.


Now, I attach the Certificates page because I would like you to tell me which button I should click to export this certificate to be able to import it and use it in Chrome.


Thanks


Bye
Logged
balubeto

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: Auto-certificate and Chrome
« Reply #23 on: October 21, 2018, 09:05:54 pm »
I don't know how it is called in your language but you should use the export certificate button which does NOT include the private key.
Logged

balubeto

  • Jr. Member
  • **
  • Posts: 75
  • Karma: 0
    • View Profile
Re: Auto-certificate and Chrome
« Reply #24 on: October 22, 2018, 08:59:57 am »
Quote from: fabian on October 21, 2018, 09:05:54 pm
I don't know how it is called in your language but you should use the export certificate button which does NOT include the private key.

In English, what is this button called and where is it?

Thanks

Bye
Logged
balubeto

qinohe

  • Full Member
  • ***
  • Posts: 160
  • Karma: 19
    • View Profile
Re: Auto-certificate and Chrome
« Reply #25 on: October 22, 2018, 02:10:20 pm »
Hey balubeto, you did not do what is on that wiki page, at least not exactly, I can tell from that picture^^

To prevent things going wrong, remove that chain create the chain(again) following that wiki page by the letter.

If you did that, export ca crt, button is the same name.

Greetings, mark
Logged

qinohe

  • Full Member
  • ***
  • Posts: 160
  • Karma: 19
    • View Profile
Re: Auto-certificate and Chrome
« Reply #26 on: October 22, 2018, 03:09:11 pm »
Also, the reason it's (probably) not working in Chrome/Chromium is because of 'SAN' - Subject Alternative Name'.

Now I would like to see the filled in 'CN -Common Name' to be translated to 'SAN' automatic, but that's not the case - devs?

So, you should translate that to the form exactly. If you did that there is no guaranty from me that it works the way you expect (in Crome).

Change to a different browser if you insist on using self-signed certs., would make it easier on you  :D

Greetings, mark
Logged

balubeto

  • Jr. Member
  • **
  • Posts: 75
  • Karma: 0
    • View Profile
Re: Auto-certificate and Chrome
« Reply #27 on: October 22, 2018, 06:40:45 pm »
As your guide has not been updated, in attachment, I have summarized the two tables of the Trust in English.

Now, I would like to know if you find something wrong and how I can export the certificate so that Chrome can use it without any problems.

Thanks

Bye
Logged
balubeto

qinohe

  • Full Member
  • ***
  • Posts: 160
  • Karma: 19
    • View Profile
Re: Auto-certificate and Chrome
« Reply #28 on: October 22, 2018, 06:54:11 pm »
I quote from the wiki
Quote
The thirth certificate will be a server certificate signed by the intermediate CA we just created. This will also be the last one we create for this chain.
The certificate you have generated is neither a server or a CA.

Greetings, mark
Logged

balubeto

  • Jr. Member
  • **
  • Posts: 75
  • Karma: 0
    • View Profile
Re: Auto-certificate and Chrome
« Reply #29 on: October 22, 2018, 07:36:49 pm »
Quote from: qinohe on October 22, 2018, 06:54:11 pm
I quote from the wiki
Quote
The thirth certificate will be a server certificate signed by the intermediate CA we just created. This will also be the last one we create for this chain.
The certificate you have generated is neither a server or a CA.

Greetings, mark

Sorry, but I only created a self-certificate.

Thanks

Bye
Logged
balubeto

  • Print
Pages: 1 [2] 3
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Auto-certificate and Chrome
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2