Note that if you are using a self-signed SSL certificate, you may need to add the certificate to your browser’s trusted root certificate store in order to access the NxFilter web interface without security warnings. You can verify this by accessing the NxFilter web interface using HTTPS and checking that the browser shows your custom SSL certificate as the site’s security certificate. There is a Github page for his install script: - Rob Asher's Github page for NxFilter install script on pfSense. You can easily install NxFilter on your pfSense or Netgate box. systemctl restart nxfilterĪfter following these steps, NxFilter should be using your custom SSL certificate for HTTPS connections. Rob Asher wrote a script installing NxFilter and its dependencies on pfSense. You can set your JSK file like below, keystore_file = conf/myown.jks One is ‘keystore_file’ and the other one is ‘keystore_pass’. And then you set two parameters in /nxfilter/conf/cfg.properties file. If you already have a CRT format certificate, you need to convert it to a JKS file by follow above instructions. Now to use your own SSL certificate, what you have to use Java KeyStore or JKS file which we have created above. keytool -importkeystore -srckeystore anyrandomname.jks -destkeystore anyrandomname.jks -deststoretype pkcs12 Kindly change the name Anynameyoucanuse.p12 and anyrandomname.jks with actual SSL names you want. These files should be in the PEM format and you have to convert the file in JKS (Java keystore) To convert normal CRT file into JKS run below commands on the same server. Then you can run above command to convert. To install a custom SSL certificate on NxFilter, you can follow the steps below: First, create or obtain your custom SSL certificate and key files. keytool -importkeystore -srckeystore Anynameyoucanuse.p12 \ Kindly make sure that SSLcertificatefilename is having all the certificate, key, CSR etc. In above command we are converting normal SSL certificate into. openssl pkcs12 -export -in SSLcertificatefilename -out Anynameyoucanuse.p12 To convert normal CRT file into JKS run below commands on the same server. These files should be in the PEM format and you have to convert the file in JKS (Java keystore) To install a custom SSL certificate on NxFilter, you can follow the steps below:įirst, create or obtain your custom SSL certificate and key files. Below are the steps to install custom SSL on nxfilter.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |