Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Upgrade to 23.05 Failed

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    8 Posts 5 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      KStarRunner
      last edited by KStarRunner

      This is a Netgate SG-3100 running 23.01-RELEASE. I tried the upgrade both via GUI and SSH, same error.

      I can't post the full error log, as your spam filter keeps blocking my post. But the below line keeps repeating and seems to be the genesis of the problem.

      Certificate verification failed for /C=US/ST=Texas/L=Austin/O=Rubicon Communications, LLC (Netgate)/OU=pfSense Plus/CN=pfsense-plus-pkg00.atx.netgate.com
      

      Of note, the server: pfsense-plus-pkg00[.]atx[.]netgate[.]com (208[.]123[.]73[.]207) seems to be configured with an untrusted certificate. Or at the very least, the full certificate chain is not being sent to clients. I'm leaning on this being an internally-issued cert (or a test cert), as it doesn't meet current CA/B requirements.

      1 Reply Last reply Reply Quote 0
      • K
        kirrn6100
        last edited by kirrn6100

        Certificate verification failed for /C=US/ST=Texas/L=Austin/O=Rubicon Communications, LLC (Netgate)/OU=pfSense Plus/CN=pfsense-plus-pkg01.atx.netgate.com
        2023-05-26.png

        1 Reply Last reply Reply Quote 0
        • Dobby_D
          Dobby_
          last edited by

          You may be try out two ways to get rid of that problem;
          First

          • system > update > update settings
            check "create boot environment" and click "save"
          • Wait a moment now, ca. ~5 minutes
          • Got to the console choose there option (13)

          Second

          • Console option (8)
            and then set up the following command
          pkg-static clean -ay; pkg-static install -fy pkg pfSense-repo pfSense-upgrade
          

          #~. @Dobby

          Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
          PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
          PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

          K 1 Reply Last reply Reply Quote 1
          • K
            KStarRunner @Dobby_
            last edited by

            @Dobby_ The device is remote, so can't do option #1. As for #2, here's what I get:

            pkg-static: Repository pfSense-core missing. 'pkg update' required
            pkg-static: No package database installed.  Nothing to do!
            Updating pfSense-core repository catalogue...
            Certificate verification failed for /C=US/ST=Texas/L=Austin/O=Rubicon Communications, LLC (Netgate)/OU=pfSense Plus/CN=pfsense-plus-pkg01.atx.netgate.com
            544518144:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-23_05-main/sources/FreeBSD-src-plus-RELENG_23_05/crypto/openssl/ssl/statem/statem_clnt.c:1921:
            

            Then the cert errors repeat.

            K 1 Reply Last reply Reply Quote 0
            • K
              KStarRunner @KStarRunner
              last edited by

              The trick for moving from the current branch to the previous branch and then back, did the trick.

              S 1 Reply Last reply Reply Quote 1
              • S
                sgw @KStarRunner
                last edited by sgw

                I see the same "Certificate verification failed" on a Netgate 7100.
                Switched the branch from 23.05 to 23.01 and back a few times, also did the forced reinstallation of pkg etc / so far no success.

                S 1 Reply Last reply Reply Quote 0
                • S
                  sgw @sgw
                  last edited by

                  Did

                   pkg-static clean -ay ; pkg-static install -fy pkg pfSense-repo pfSense-upgrade
                  

                  then switched to 23.05, now this:

                  # pfSense-upgrade
                  Your Netgate device has pfSense+ as part of your device purchase.
                  >>> Updating repositories metadata... 
                  Updating pfSense-core repository catalogue...
                  Fetching meta.conf: . done
                  Fetching packagesite.pkg: . done
                  Processing entries: .. done
                  pfSense-core repository update completed. 15 packages processed.
                  Updating pfSense repository catalogue...
                  Fetching meta.conf: . done
                  Fetching packagesite.pkg: .......... done
                  Processing entries: 
                  Processing entries............. done
                  pfSense repository update completed. 549 packages processed.
                  All repositories are up to date.
                  >>> Upgrading pfSense-upgrade... done.
                  pfSense-repoc-static: failed to fetch the repo data
                  failed to read the repo data.
                  failed to update the repository settings!!!
                  failed to update the repository settings!!!
                  
                  # pkg-static update
                  Updating pfSense-core repository catalogue...
                  pfSense-core repository is up to date.
                  Updating pfSense repository catalogue...
                  pfSense repository is up to date.
                  All repositories are up to date.
                  
                  # pfSense-upgrade
                  pfSense-repoc-static: failed to fetch the repo data
                  failed to read the repo data.
                  failed to update the repository settings!!!
                  failed to update the repository settings!!!
                  
                  J 1 Reply Last reply Reply Quote 1
                  • J
                    jsonger @sgw
                    last edited by

                    @sgw This is the exact thing I'm seeing. Something isn't right with pfSense-upgrade 1.0.66. As soon as I roll back to 1.0.61, everything works right again with package management.

                    1 Reply Last reply Reply Quote 1
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.