Knowledge Base

How to install and bind an SSL certificate on pfSense

 
 

Overview 

By the end of this guide, you will have imported your Certificate Authority (CA) bundle into pfSense, installed your server SSL certificate, and bound it to the pfSense web interface (WebGUI) so administrators connect over HTTPS without warnings. It covers the prerequisites, importing the root and intermediate certificates, installing the server certificate (whether the Certificate Signing Request, or CSR, was generated in pfSense or elsewhere), assigning the certificate to the WebGUI, and verifying that the certificate matches the host or Fully Qualified Domain Name (FQDN). 

Prerequisites 

  • Administrator access to the pfSense web interface (WebGUI) 

  • The Certificate Authority (CA) bundle (root and intermediate certificates) from your certificate authority 

  • The server certificate and its private key (if the CSR was generated externally) 

  • A configured pfSense environment 

Step 1: Import the root and intermediate certificates 

If your CA sent you a CA bundle: 

  1. Go to System > Certificates > Authorities tab. 

 

Figure 1: pfSense Authorities tab showing the location to add a new Certificate Authority. 

  1. Click + Add and enter a descriptive name. 

  1. Set Method to "Import an existing Certificate Authority." 

  1. Paste the CA bundle (root and intermediate certificates) into Certificate Data. 

  1. Click Save. 

 

Figure 2: Certificate Authority import form with the descriptive name, import method, and certificate data fields completed. 

Step 2: Install the server certificate 

If you generated the CSR in pfSense 

An entry for the certificate already exists. 

  1. Go to System > Certificates > Certificates tab. 

 

Figure 3: pfSense Certificates tab showing the list of certificates available for editing. 

  1. Click Edit next to the certificate. 

  1. Paste the signed certificate you received from the CA, then click Update. 

 

Figure 4: Certificate edit screen where the signed certificate can be pasted and updated. 

 
Figure 5: Updated certificate entry in pfSense after the signed certificate has been saved. 

If you generated the CSR elsewhere (OpenSSL, Internet Information Services (IIS), and so on) 

  1. Go to System > Certificates > Certificates. 

  1. Click + Add/Sign and choose "Import an existing Certificate." 

  1. Paste the private key and the certificate, then click Save. 

 

Figure 6: Import existing certificate form showing the private key and certificate fields for externally generated CSRs. 

Step 3: Bind the certificate to the pfSense WebGUI (HTTPS) 

  1. Go to System > Advanced > Admin Access. 

  1. Under WebGUI, set Protocol to HTTPS and select your imported certificate as the SSL/TLS Certificate. 

  1. Click Save. 

 

Figure 7: Admin Access settings showing HTTPS selected and the imported certificate assigned to the pfSense WebGUI. 

Step 4: Verify SSL is working 

  1. Open the pfSense URL in your browser. 

  1. Confirm the browser shows no certificate warnings and the certificate matches the host, IP address, or Fully Qualified Domain Name (FQDN). 

 

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today