opnsense / opnsense/plugins

ACME Client: Automations - Sync SSL certificate changes into running HAProxy not doing anything?

Open
#5,445 9 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

support
Dominant language
PHP
Stars
1.2k
Forks
863
Avg merge
2d 6h
Merged PRs (30d)
10

Description

Important notices

Before you add a new report, we ask you kindly to acknowledge the following:

Describe the bug

I'm using ACME client automations and noticed that the Sync SSL certificate changes into running HAProxy automation does not seem to do anything.

Checking ACME Client: Certificates I can see that my LE certificates has been renewed, but viewing the certificate being served by HAProxy it's clear that it's from the previous iteration.

I have these automations configured:

Image

Manually clicking "Run automations" for the certificate in question does not solve anything, it's still the old certificate in HAProxy.

However if I stop HAProxy and start it again then the new cert is served.

Tip: to validate your setup was working with the previous version, use opnsense-revert (https://docs.opnsense.org/manual/opnsense_tools.html#opnsense-revert)

To Reproduce

Steps to reproduce the behavior:

  1. Go to '...'
  2. Click on '....'
  3. Scroll down to '....'
  4. See error

Expected behavior

New cert being served after running the automation.

Environment

Software version used and hardware type if relevant, e.g.:

OPNsense 26.1.8_5-amd64 (amd64).

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the ACME Client certificate automation entry point and trace the “Sync SSL certificate changes into running HAProxy” action, then compare it with the stop/start HAProxy path. Reproduce by renewing a certificate and using “Run automations”; done when the new certificate is served without manually restarting HAProxy.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
devops, networking, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.