Tired of the "Your connection is not private" warning every time you log into pfSense? In this video I'll show you how to fix the pfSense SSL/TLS certificate error the RIGHT way — not by clicking "Proceed Anyway," but by building your own internal Certificate Authority (CA), issuing pfSense a proper certificate with a valid SAN, and trusting it on your machine. The result: a clean, trusted, green-padlock connection — exactly how it's done in enterprise networks.
This is the same PKI concept used in real network security and SOC roles, done in a home lab.
⏱️ CHAPTERS
0:00 – The error (and why "Proceed Anyway" isn't the fix)
0:40 – Why this actually happens (self-signed vs CA-signed)
2:00 – Step 1: Create your internal Certificate Authority
4:30 – Step 2: Issue the server certificate (⚠️ don't skip the SAN!)
7:30 – Step 3: Assign the cert to the Web UI
9:00 – Step 4: Export & trust the CA (Firefox + Linux)
12:30 – The payoff: green padlock 🟢
14:00 – Recap + what this means for real network security
🔑 THE #1 MISTAKE
Modern browsers ignore the Common Name field and validate ONLY the Subject Alternative Name (SAN). If you skip the SAN, your cert is trusted but STILL throws an error. Add both the FQDN and the IP address as SAN entries.
🔐 SECURITY NOTE
When exporting your CA, export the CERTIFICATE only — never the private key. That key is the master key to your entire CA.
🧪 FULL pfSENSE HOME LAB SERIES
▶️ Part 1 — pfSense Setup: • Build a Home Lab for FREE — pfSense Setup ...
▶️ Part 2 — Accessing pfSense: • Build a Home Lab for FREE — Accessing pfSe...
💬 Hit a snag? Drop a comment — I answer them.
👍 If this saved you a headache, like & subscribe for more hands-on cybersecurity labs.
— Netsectap | Practical Cybersecurity Training, Built for the Real World
#pfsense #homelab #cybersecurity #networking #ssl #certificates