Skip to content

Allow WebUI to use self-signed certs generated by external CA #8484

@Fmstrat

Description

@Fmstrat

Important notices

Before you add a new report, we ask you kindly to acknowledge the following:

Is your feature request related to a problem? Please describe.

I have an enterprise CA set up that is not managed within OpnSense. From that CA, I generated a cert to be used for the web portal within OpnSense. When importing the cert, there is no way to set it to a "server" certificate unless the CA cert and private key have previously been imported.

This is a security issue in a least-privileged access infrastructure, as OpnSense, as an ingress, has no need to be given access to the CA private key.

Describe the solution you like

I should be able to import a certificate, and set it to "server", without requiring a CA to exist in OpnSense.

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedContributor missing / timeoutsupportCommunity support or awaiting triage

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions