Project

General

Profile

Actions

Bug #16652

closed

Certificate configured in DNS Resolver not shown as "In Use" if resolver doesn't have SSL/TLS enabled

Added by cemysce . 21 days ago. Updated 20 days ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
Certificates
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
2.8.1
Affected Architecture:

Description

I have a certificate (being maintained by acme 1.0.5 plugin, in case that matters). I use this certificate in the following 3 places within the pfSense config:

  1. System / Advanced / Admin Access: used as "SSL/TLS Certificate" under "webConfigurator"
  2. Services / DNS Resolver / General Settings: used as "SSL/TLS Certificate" under "General DNS Resolver Options" (note that "Enable SSL/TLS Service" is unchecked)
  3. Services / Acme Certificates / Certificates: it's one of the certificates ACME is maintaining

However under System / Certificates / Certificates, the "In Use" column only shows:

webConfigurator
Acme (1)

In other words, it is not showing that DNS Resolver uses the certificate if the DNS Resolver setting "Enable SSL/TLS Service" is unchecked. It does show it if it is checked. However, regardless of whether SSL/TLS is enabled, I think it is useful to list all the places the configuration references a given certificate. I suppose it depends on your definition of "in use" — the certificate is technically not being used by Unbound in my case, but it is still being used in the sense that it is being referenced by Unbound's configuration. I think it is more valuable to show all the places the certificate is referenced, because it's much more tedious and mistake-prone to download the config.xml file and figure this out manually.

Actions

Also available in: Atom PDF