Skip to content
Geek is the Way!
Menu
  • Forums
  • Sobre o blog
  • Contato
  • English
    • Português
Menu

How to fix the X3 CA/Certificate issue after upgrading to pfSense 2.5

Posted on February 26, 2021August 6, 2022 by Thiago Crepaldi

Last Updated on August 6, 2022 by Thiago Crepaldi

If you recently upgraded to pfSense 2.5, you may have received notifications about some CA/Certificate entries close to expiring. The exact message would be something like “The following CA/Certificate entries are expiring: Certificate Authority: Acmecert: O=Let’s Encrypt, CN=Let’s Encrypt Authority X3, C=US”

The fix is quite simple, just visit System >> Cert Manager >> CAs and find the entry “Acmecert: O=Let’s Encrypt, CN=Let’s Encrypt Authority X3, C=US”. You should see a “Valid until” in yellow, with a near by date (less than 30 days, usually). Note also there is a “X3” in the CA name. Just click on Delete (trash bin icon) and confirm clicking on Ok.

This is safe to do because you must have another CA for Let’sEncrypt which contains “R3” in the name. Something like “Acmecert: O=Let’s Encrypt, CN=R3, C=US”

That is it, have fun!

Share this:

  • Tweet

Related

7 thoughts on “How to fix the X3 CA/Certificate issue after upgrading to pfSense 2.5”

  1. Protocol73 says:
    March 9, 2021 at 6:09 AM

    Thanks for this!

    Reply
  2. Anders says:
    March 28, 2021 at 4:56 AM

    I just love your blog, thanks!

    Reply
  3. Thiago Crepaldi says:
    March 28, 2021 at 3:52 PM

    Thank you!

    Reply
  4. Thiago Crepaldi says:
    March 30, 2021 at 10:23 AM

    quick question. Do you think that having screenshots would improve your experience or a raw text as today is better? I have been considering updating all posts with screenshots, but not sure whether it would make it look too long to follow or something

    Reply
  5. walter says:
    September 21, 2021 at 9:52 AM

    In my case is “R3” CA that is going to expire. What can i do to update CA cert?

    Reply
  6. Thiago Crepaldi says:
    October 18, 2021 at 7:48 PM

    You probably figured by yourself, but the procedure is almost the same. Make sure you have a CA called “Acmecert: O=Internet Security Research Group, CN=ISRG Root X1, C=US” (highlight to ISRG Root X1) and another non expired R3 (aka Acmecert: O=Let’s Encrypt, CN=R3, C=US). If you do, just delete the expired one. Don’t forget to renew all your Let’s Encrypt certificates after that.

    Reply

Leave a ReplyCancel reply

LIKED? SUPPORT IT :)

Buy Me a Coffee


Search


Categories

  • Cooking (1)
  • Homelab (79)
    • APC UPS (6)
    • pfSense (40)
    • Proxmox (20)
    • Shopping (1)
    • Supermicro (2)
    • Synology NAS (8)
    • Ubiquiti (6)
    • UDM-Pro (4)
  • Random (3)
  • Wordpress (1)

Tags

Agentless monitoring (3) AP9631 (3) Apache2 (3) APC UPS (6) Bind9 (3) certificates (5) crontab (2) DDNS (5) debian (3) DNS (7) DSM (6) DuckDNS (2) Dynamic DNS (4) en_US (2) Firewall (9) gmail (3) LDAP (2) Let's Encrypt Certificates (7) monitoring (18) networking (21) PBS (3) pfsense (43) port forwarding (3) proxmox (17) proxmox backup server (3) proxmox virtual environment (16) pve (5) rev202207eng (76) security (28) SNMP (4) SNMPv1 (3) ssh (4) SSL (6) subnet (2) Synology (7) udm-pro (5) unifi (6) unifi controller (3) unifi switch (2) UPS (5) VLAN (4) vpn (9) wifi (4) Zabbix (18) Zabbix Agent2 (11)

See also

Privacy policy

Sitemap

©2025 Geek is the Way! | Design by Superb