SSL Certificate Errors

thank you so much can you check again to be sure.

I’m using OPNsense, which isn’t really a bad choice at all and pretty comparable with pfSense (given the fact that it’s actually a fork of pfSense).
My modem is completely in bridge mode, so it isn’t involved at all.
I already checked each aspect of my network and all components, but everything looks pretty healthy.

But if you have any insights to what exactly is causing the problems, I’m happy to be proven wrong. :wink:
Maybe my OPNsense is just badly configured (but then it’s the first time in years, I have problems with it).

@igorked

plex.home.lan has been deleted 2x from what I see here. I can clean that up for you if you wish. If I clean it up, you’ll need to do a Control-F5 in Plex/web to force a list reload.

I renamed to NJF few seconds ago, but still i can’t see NJF-1 in my Dashboard, thats weird.
btw. thx for resetting the Cert.

@TVJunkie

You’re good. Open/pfSense is good stuff. It never flinches here either. It’s been one of those mornings already. :slight_smile:

I was easily able to configure mine so only the FQDN (DDNS) addresses of those I want to stream to can actually come through the firewall and even know the server exists.

I also use the box for site-site to Plex HQ

1 Like

please do delete i renamed it the same again - or do i need to name it something else now

@igorked

Check your PM.

Thanks! Unfortunately, that didn’t solve the problem either. My old certificate was valid August 30th to November 28th, but the intermediate certificate already was ISRG Root X1. I now got a new one, also with ISRG Root X1. I also tried to use my own certificate with PKCS #12. All are the same: The server is marked as “Not available outside your network” and disappears after a while (due to Remote access somehow automatically beign disabled) unless I set “Secure Connections” to “Preferred” - which I’d really prefer not to :-).

The logs keep saying “CERT: incomplete TLS handshake from [::ffff:54.170.120.91]:35942: sslv3 alert certificate expired”. Is it possible the problem is really not on my system but on 54.170.120.9?

@vanElden

Then let’s let the team work on the Remote Access problem (which they’re doing right now as I said a few moments ago).

Re the cert?

If that cert were expired, ALL of the users on EU-West (which is my server as well) would be down.

You still have an issue there to resolve.

Thank you. To avoid issues like this in the future could a UI be built out for us to do it ourselves? Perhaps locking the option till the issue is detected to keep from people doing it for no reason.

@syco54645 Good idea! I’ll ask . I do know that if everyone hit the button at once there would be a :fire: LOL

@vanElden

I forwarded your info to the team. They are working on R.A. on the EU-West server right now since it’s the most problematic (and most heavily used)

Not able to access remote server… " Not available outside your network" help please. Is this a ssl certificate issue? can my be reset as well?? help!

[CERT] TLS connection from [::ffff:192.168.50.179]:49809 came in with unrecognized plex.direct SNI name ‘192-168-50-105.6e9f770e99f34db38221f8dd1ca6d86b.plex.direct’; using installed plex.direct cert

Thanks! I’ll wait and see then; sorry for missing the info that it’s being worked out. I’ll see what happens with the certificate log-lines once it’s back to green. Might turn out to be a connected mate’s server or something… :shrug:

My cert will only expire on 18th December, not sure why this problem is also affecting me…
Version: 1.24.5.5071 Synology DSM 7.0.1 RC | DS218+
Using a LE certificate that I generated through acme package in pfsense.
This cert is also being used in another locations, so why only plex being affected I don’t know…

Thank you. That seems to have resolved it after a restart. I still have issues with a user though who has an LG TV. I have instructed her to allow insecure connections and reboot her TV and she still seems to have issues.
In the absence of an update of her TV, does the certificate expiry imply that the TV plex client will no longer operational? Is the certificate embedded in the plex client (which obviously can be updated) or in the TV firmware (which may not be) ?

1 Like

@mcury

  1. Your cert for your FQDN, just like me, is supplemental to Plex’s cert.
  2. Plex’s cert is used for PMS - Plex.tv communication always.

Would you like me to reset your certificate or are you only having remote access problems ?

1 Like

Kindly do it ChuckPa, really thanks
The problem is only with remote access, I can access through other VLANs here in my network

@mcury

Certificate reset.

You may restart the server.

If still Remote Access flipflopping. we all need to wait on that

1 Like

Restarted the server but it stills flipflopping…
When I checked, it showed green (available), then 2 seconds later it becomes unavailable as per image below

image

I can confirm that it’s not being blocked by my firewall, so I’ll just wait, thanks a lot ChuckPa