PFSense - Certificates - Create a Server Certificate

A Server certificate (SSL certificates) is used to authenticate the identity of a server.


Create the Server Certificate

Navigate to System → Cert Manager.

In Add/Sign a New Certificate:

In Internal Certificate:

In Certificate Attributes:

NOTE: Lifetime.

  • New TLS certificates will be limited to 398 days, a little over a year (13 months).
  • In a move that is meant to boost security, Apple, Google, and Mozilla reject publicly rooted digital certificates in their respective web browsers that expire more than 13 months (or 398 days) from their creation date.
  • To avoid unintended consequences, it is recommended that certificates be issued with a maximum validity of 397 days.