We are getting notifications of two CA's expiring in pfSense - shown below in a yellow colour:
These are:
Acmecert: O=(STAGING) Internet Security Research Group, CN=(STAGING) Pretend Pear X1, C=US
Acmecert: O=Internet Security Research Group, CN=ISRG Root X1, C=US
I found a thread on Netgate's forum from extremely recently, which seems similar. It talks about X1
CA's, and the two that are expiring for us are also X1
's.
There is no Renew button for these CA's.
Is it safe to delete these two CAs?
Afterwards how can we test that it has not caused any issues?
We are getting daily notifications:
The renew button is only applicable for CA's generated by pfsense.
You'll have to review how you use certificates - and if you use certificates issued by those CA's for any purpose. If so it may lead to problems. The answer is that it'll probably be fine as the certs belongs to Let's Encrypt, which has moved on to new root CA's, and issue short lived certificates.
Review that all functionality that uses PKI works as normal. This may be a lot or nothing - depending on configuration.