-
Notifications
You must be signed in to change notification settings - Fork 909
Closed as not planned
Labels
help wantedContributor missing / timeoutContributor missing / timeoutsupportCommunity support or awaiting triageCommunity support or awaiting triage
Description
Important notices
Before you add a new report, we ask you kindly to acknowledge the following:
- I have read the contributing guide lines at https://github.com/opnsense/core/blob/master/CONTRIBUTING.md
- I am convinced that my issue is new after having checked both open and closed issues at https://github.com/opnsense/core/issues?q=is%3Aissue
Is your feature request related to a problem? Please describe.
I have an enterprise CA set up that is not managed within OpnSense. From that CA, I generated a cert to be used for the web portal within OpnSense. When importing the cert, there is no way to set it to a "server" certificate unless the CA cert and private key have previously been imported.
This is a security issue in a least-privileged access infrastructure, as OpnSense, as an ingress, has no need to be given access to the CA private key.
Describe the solution you like
I should be able to import a certificate, and set it to "server", without requiring a CA to exist in OpnSense.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
help wantedContributor missing / timeoutContributor missing / timeoutsupportCommunity support or awaiting triageCommunity support or awaiting triage