Hello,
OK. I got the issues solved. To put it simply after updating /etc/uhttpd.crt file with a new certificate and then using “uci set certificates.@certificate[8].datetime=’new-end-date’ where that new-end-date is either value from epoch or rfc3999 timestamp like what other certificates uses what is needed is to issue “uci commit certificates”.
And that’s it, after both me and WebGUI are happy ![]()
Now if someone else is device gets this issue and it’s root cause is not yet fixed with new firmware releases. I wrote a simple helper script to assist doing what I described above. Running that will what commands needs to be issued. It will dig from uci registry correct commands once provided the updated certificate file name with the path of course.
Here were the commands I used updating /etc/uhttpd.crt certificate which a new one generated with existing key /etc/uhttpd.key copying all data from old certificate but the dates of course.
root@rutx50:~# openssl x509 -x509toreq -copy_extensions copyall -in /etc/uhttpd.crt -signkey /etc/uhttpd.key -out uhttpd-new.csr
root@rutx50:~# openssl req -in uhttpd-new.csr -noout -text
root@rutx50:~# openssl x509 -in uhttpd-new.csr -out uhttpd-new.crt -req -signkey /etc/uhttpd.key -days 730
root@rutx50:~# openssl x509 -in uhttpd-new.crt -noout -text
root@rutx50:~# cp -av /etc/uhttpd.crt /etc/uhttpd-old.crt
root@rutx50:~# cp uhttpd-new.crt /etc/uhttpd.crt
root@rutx50:~# openssl x509 -in /etc/uhttpd.crt -noout -text
This was run from root home directory shell. Now after that, the script (attached in zip file) copied to router root home directory I ran it and this is what it happened.
root@rutx50:~# ./uhttpd-crt-update.sh /etc/uhttpd.crt
Registered uhttpd ertificate end_date at the moment is:
uci get certificates.@certificate[8].datetime
==> 1753271990
The certificate end_date at filesystem is:
/etc/uhttpd.crt
==> 2027-10-15T06:46:25Z
# If you want to register /etc/uhttpd.crt cerificate end_date to
uhttpd registry, you can accomplish that by issuing
the following commands usin root user privileges.
# Make backup of certificate settings
uci export certificates > uhttpd-certificates.bak
# Update end_date
uci set certificates.@certificate[8].datetime=‘2027-10-15T06:46:25Z’
# Verify change and commit chante
uci get certificates.@certificate[8].datetime
uci commit certificates
# Verify using WebGUI the Certificate date is correct,
# if not, then you can roll back using commands
uci import certificates < uttpd-certificates.bak
uci commit certificates
# If it was, you may now or later remove the backup file
rm uhttpd-certificates.bak
=====================================================================
root@rutx50:~#
root@rutx50:~# uci export certificates > uhttpd-certificates.bak
root@rutx50:~# uci set certificates.@certificate[8].datetime=‘2027-10-15T06:46:25Z’
root@rutx50:~# uci get certificates.@certificate[8].datetime
2027-10-15T06:46:25Z
root@rutx50:~# uci commit certificates
root@rutx50:~#
And that’s it. Now WebGUI shows at System->Administration→Certificates uhttpd.crt is valid for 1 year and 11 months <Yay!>
Now, if there isn’t anything else someone else would like to add. This issue would be ready to made resolved.
riku
uhttpd-crt-update.zip (1.3 KB)