Skip to content

OPNCentral: Automatic Certificate Push for WebUI not working #10842

Description

@Bluemeus

Important notices

Before you add a new report, we ask you kindly to acknowledge the following:

Describe the bug

By configuring automatic certificate push in OPNcentral, like described in the OPNsense Wiki & Documentation: Business Edition / Central Management / Configuration Tutorials / Automatic WebGUI Login / 5. Provision Certificates and WebGUI to Firewall Nodes the provisioning process does not detect any changes. In this case, the certificate is neither pushed nor installed.

By changing any setting, for example the session timeout under System > Settings > Administration from the default value of 240 to 241 and saving the change causes the provisioning process to detect a difference. It then pushes the certificate and activates it as expected.

The issue was also discussed in the forum: https://forum.opnsense.org/index.php?topic=52176.msg273945#msg273945

To Reproduce

Follow the steps from the [OPNsense Wiki & Documentation: Business Edition / Central Management / Configuration Tutorials / Automatic WebGUI Login / 5. Provision Certificates and WebGUI to Firewall Nodes](https://docs.opnsense.org/vendor/deciso/opncentral.html#provision-certificates-and-webgui-to-firewall-nodes)

to reproduce the behavior:

  1. Go to Management ‣ Host ‣ Configuration.
  2. Select a Firewall Node, e.g., node-a1.opnsense.local and edit it.
  3. Make sure that Validate SSL is not selected right now.
  4. Select the correct certificate in Push WebUI certificate, in this case node-a1.opnsense.local
  5. In Provision classes, select Web GUI. Please be careful not to select Certificates, only Web GUI is needed as Provision classes.
  6. Press Save and repeat the same for all other Firewall Nodes.
  7. Go to Management ‣ Provisioning and select all Hosts, then press Reconfigure.

Expected behavior

After the provisioning has succeeded the target firewall should have set the new certificate active.

Describe alternatives you considered

The provisioning process does not detect any changes. In this case, the certificate is neither pushed nor installed.

For example, changing the session timeout under System > Settings > Administration from the default value of 240 to 241 and saving the change causes the provisioning process to detect a difference. It then pushes the certificate and activates it as expected.

Screenshots

Not applicable

Relevant log files

Not applicable

Additional context

The issue was also discussed in the forum: https://forum.opnsense.org/index.php?topic=52176.msg273945#msg273945

Environment

Software version used and hardware type if relevant, e.g.:

Software:

  • OPNsense 26.4.1p2-amd64 (Business Edition) (all hosts have the same patchlevel)

Hardware:

  • Deciso DEC2770
  • Deciso & DECC4280

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    supportCommunity support or awaiting triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions