PBS and Let's Encrypt

degan

Active Member
Sep 25, 2019
22
0
41
Wuerzburg/Germany
Hello,

i noticed that the command "proxmox-backup-manager cert info | grep Fingerprint" and "openssl x509 -noout -in /etc/proxmox-backup/proxy.pem -fingerprint -sha256" gives me the same fingerprint.

If i now update this certificate and key with one from Let's Encrypt i get certificate warnings in Proxmox VE, i am right?
Also on any renewal of the certificate!?

I dont want to edit the fingerprint in my PVE hosts all the time i renew the LE Certificate.
Any solutions?
I think the best solution ist to buy truted certificate, isnt it?
 
the fingerprint is optional on the client-side (which includes PVE storage setup), in case you use a certificate signed by a CA trusted by the client system, simply leave it out.
 
  • Like
Reactions: degan