Skip to content
Geek is the Way!
Menu
  • Forums
  • Sobre o blog
  • Contato
  • English
    • Português
Menu

Setting up Let’s Encrypt SSL certificates on your pfSense

Posted on June 27, 2020October 17, 2022 by Thiago Crepaldi

Last Updated on October 17, 2022 by Thiago Crepaldi

In a previous post, I have described how to issue Let’s Encrypt certificates for free. SSL certificates have many applications, including replacing self-signed certificates that are not recognized by browsers. That is the goal of this post. Replace pfSense’s self-signed certificate by the one we have created using Let’s Encrypt API.

Let’s Encrypt setup

If you don’t have a SSL certificate yet, just follow this post first. As an additional step, every time the certificate is renewed, we want to reload pfSense’s webConfigurator to start using the latest version of the new certificate. For such, go to Services >> Acme certificates and click on the edit icon (pencil). Next, scroll down to Actions list and click on Add:

  • Mode: Enabled
  • Command: /etc/rc.restart_webgui
  • Method: Shell command

Click on Save to complete the update. At this point, if you go to System >> Cert. Manager >> Certificates, you should see your Let’s Encrypt certificate.

pfSense setup

On your pfSense, go to System >> Advanced >> Admin Access page. There are many options, but the following are the most relevant:

  • Protocol: HTTPS
  • SSL/TLS Certificate: select the certificate created using Let’s Encrypt
  • HSTS: unchecked
  • DNS Rebind Check:
    • If you intend to use only internal IP to access your router, you can uncheck this.
    • However, if you want to use your DDNS URL (e.g. pfsense.mydomain.com), you have to check this box
  • Browser HTTP_REFERER enforcement: Same as DNS Rebind Check

Click Save and you should be redirected to the https version of your router portal. A manual refresh is faster, though!

DNS Resolver

Go to Services >> DNS Resolver >> General page and at the SSL/TLS Certificate field, select the certificate created using Let’s Encrypt service. Click Save and Apply changes to start using your new certificates for your DNS services.

Share this:

  • Tweet

Related

Leave a ReplyCancel reply

LIKED? SUPPORT IT :)

Buy Me a Coffee


Search


Categories

  • Cooking (1)
  • Homelab (79)
    • APC UPS (6)
    • pfSense (40)
    • Proxmox (20)
    • Shopping (1)
    • Supermicro (2)
    • Synology NAS (8)
    • Ubiquiti (6)
    • UDM-Pro (4)
  • Random (3)
  • Wordpress (1)

Tags

Agentless monitoring (3) AP9631 (3) Apache2 (3) APC UPS (6) Bind9 (3) certificates (5) cron (2) DDNS (5) debian (3) DNS (7) DSM (6) Dynamic DNS (4) Firewall (9) gmail (3) IPSEC (2) Let's Encrypt Certificates (7) monitoring (18) networking (21) PBS (3) pfBlockerNG (2) pfsense (43) port forwarding (3) proxmox (17) proxmox backup server (3) proxmox community (2) proxmox virtual environment (16) pve (5) rev202207eng (76) routing (2) security (28) SNMP (4) SNMPv1 (3) ssh (4) SSL (6) Synology (7) udm-pro (5) unifi (6) unifi controller (3) Unifi Dream Router (2) UPS (5) VLAN (4) vpn (9) wifi (4) Zabbix (18) Zabbix Agent2 (11)

See also

Privacy policy

Sitemap

©2025 Geek is the Way! | Design by Superb