Important notices
Before you add a new report, we ask you kindly to acknowledge the following:
Describe the bug
By configuring automatic certificate push in OPNcentral, like described in the OPNsense Wiki & Documentation: Business Edition / Central Management / Configuration Tutorials / Automatic WebGUI Login / 5. Provision Certificates and WebGUI to Firewall Nodes the provisioning process does not detect any changes. In this case, the certificate is neither pushed nor installed.
By changing any setting, for example the session timeout under System > Settings > Administration from the default value of 240 to 241 and saving the change causes the provisioning process to detect a difference. It then pushes the certificate and activates it as expected.
The issue was also discussed in the forum: https://forum.opnsense.org/index.php?topic=52176.msg273945#msg273945
To Reproduce
Follow the steps from the [OPNsense Wiki & Documentation: Business Edition / Central Management / Configuration Tutorials / Automatic WebGUI Login / 5. Provision Certificates and WebGUI to Firewall Nodes](https://docs.opnsense.org/vendor/deciso/opncentral.html#provision-certificates-and-webgui-to-firewall-nodes)
to reproduce the behavior:
- Go to Management ‣ Host ‣ Configuration.
- Select a Firewall Node, e.g.,
node-a1.opnsense.local and edit it.
- Make sure that Validate SSL is not selected right now.
- Select the correct certificate in Push WebUI certificate, in this case
node-a1.opnsense.local
- In Provision classes, select
Web GUI. Please be careful not to select Certificates, only Web GUI is needed as Provision classes.
- Press Save and repeat the same for all other Firewall Nodes.
- Go to Management ‣ Provisioning and select all Hosts, then press Reconfigure.
Expected behavior
After the provisioning has succeeded the target firewall should have set the new certificate active.
Describe alternatives you considered
The provisioning process does not detect any changes. In this case, the certificate is neither pushed nor installed.
For example, changing the session timeout under System > Settings > Administration from the default value of 240 to 241 and saving the change causes the provisioning process to detect a difference. It then pushes the certificate and activates it as expected.
Screenshots
Not applicable
Relevant log files
Not applicable
Additional context
The issue was also discussed in the forum: https://forum.opnsense.org/index.php?topic=52176.msg273945#msg273945
Environment
Software version used and hardware type if relevant, e.g.:
Software:
- OPNsense 26.4.1p2-amd64 (Business Edition) (all hosts have the same patchlevel)
Hardware:
- Deciso DEC2770
- Deciso & DECC4280
Important notices
Before you add a new report, we ask you kindly to acknowledge the following:
Describe the bug
By configuring automatic certificate push in OPNcentral, like described in the OPNsense Wiki & Documentation: Business Edition / Central Management / Configuration Tutorials / Automatic WebGUI Login / 5. Provision Certificates and WebGUI to Firewall Nodes the provisioning process does not detect any changes. In this case, the certificate is neither pushed nor installed.
By changing any setting, for example the session timeout under
System > Settings > Administrationfrom the default value of 240 to 241 and saving the change causes the provisioning process to detect a difference. It then pushes the certificate and activates it as expected.The issue was also discussed in the forum: https://forum.opnsense.org/index.php?topic=52176.msg273945#msg273945
To Reproduce
Follow the steps from the [OPNsense Wiki & Documentation: Business Edition / Central Management / Configuration Tutorials / Automatic WebGUI Login / 5. Provision Certificates and WebGUI to Firewall Nodes](https://docs.opnsense.org/vendor/deciso/opncentral.html#provision-certificates-and-webgui-to-firewall-nodes)
to reproduce the behavior:
node-a1.opnsense.localand edit it.node-a1.opnsense.localWeb GUI. Please be careful not to selectCertificates, onlyWeb GUIis needed as Provision classes.Expected behavior
After the provisioning has succeeded the target firewall should have set the new certificate active.
Describe alternatives you considered
The provisioning process does not detect any changes. In this case, the certificate is neither pushed nor installed.
For example, changing the session timeout under System > Settings > Administration from the default value of 240 to 241 and saving the change causes the provisioning process to detect a difference. It then pushes the certificate and activates it as expected.
Screenshots
Not applicable
Relevant log files
Not applicable
Additional context
The issue was also discussed in the forum: https://forum.opnsense.org/index.php?topic=52176.msg273945#msg273945
Environment
Software version used and hardware type if relevant, e.g.:
Software:
Hardware: