Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to pull in package repo: "pfSense-repoc: invalid signature"

    Problems Installing or Upgrading pfSense Software
    11
    22
    2.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • debouncedD
      debounced
      last edited by debounced

      Hi,

      I was going to install a new package today for my homelab, but noticed I am unable to install any new packages on my virtualized whitebox install of pfSense+ 23.09, the "Available Packages" page shows no available packages and the update page shows the message "pfSense-repoc: invalid signature":

      b3267310-75a6-4264-9623-7d8fdff22fd1-image.png

      737dfd11-4988-4337-b896-ac7c92706685-image.png

      Running the following command (pkg-static upgrade -fy pfSense-repoc) in the shell also results in an error:

      pfSense-repoc
      Updating pfSense-core repository catalogue...
      pkg-static: An error occured while fetching package
      pkg-static: An error occured while fetching package
      repository pfSense-core has no meta file, using default settings
      pkg-static: An error occured while fetching package
      pkg-static: An error occured while fetching package
      Unable to update repository pfSense-core
      Updating pfSense repository catalogue...
      pkg-static: An error occured while fetching package
      pkg-static: An error occured while fetching package
      repository pfSense has no meta file, using default settings
      pkg-static: An error occured while fetching package
      pkg-static: An error occured while fetching package
      Unable to update repository pfSense
      Error updating repositories!
      

      All attempts to run pkg-static -d update result in

      < HTTP/1.1 400 Bad Request
      < Server: nginx
      < Date: Mon, 04 Dec 2023 22:43:12 GMT
      < Content-Type: text/html
      < Content-Length: 208
      < Connection: close
      

      Also, a reboot did not clear the error. I also verified proper DNS operation on the pfSense host.

      Any help would be much appreciated,

      Thank you!

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        The 'Bad rquest' error indicates the system is sending an invalid client cert.

        The 'invalid signature' error from repoc indicates it's not able to pull a new cert.

        Send me your NDI in chat and I'll check it.

        Steve

        debouncedD 1 Reply Last reply Reply Quote 1
        • debouncedD
          debounced @stephenw10
          last edited by

          @stephenw10 NDI sent!

          Thank you for investigating!

          1 Reply Last reply Reply Quote 0
          • debouncedD
            debounced
            last edited by debounced

            This ended up being my fault by adding a new NIC to the VM in Proxmox and therefore invalidating/changing the NDI. I was able to reactivate with a new pfSense+ token and now everything works again.

            1 Reply Last reply Reply Quote 1
            • G
              gsr23000
              last edited by

              Hello! I'm having the same problem. What is the proper way to handle / avoid this ?

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Send me the NDI in chat and I'll check it.

                1 Reply Last reply Reply Quote 0
                • M
                  milindhvijay
                  last edited by

                  Hi, I too am facing this issue. What should I do?

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Also send me the NDI in chat so I can check it.

                    1 Reply Last reply Reply Quote 0
                    • J
                      jpmchia
                      last edited by

                      Mind if I send you my NDI - am also experiencing the same issue.

                      1 Reply Last reply Reply Quote 0
                      • L
                        LARunnerJ
                        last edited by

                        I now have the same issue, after replacing a NIC with a faulty port. How does one invalidate the prior license key so that it can register again on the same device (albeit with a different network card)?

                        Thanks!

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Send me your NDI in chat and I'll check it

                          1 Reply Last reply Reply Quote 0
                          • J
                            jlw52761
                            last edited by jlw52761

                            Having this issue on CE 2.7.0, won't register 2.7.2.

                            • Couldn't find host pkg00-atx.netgate.com in the .netrc file; using defaults
                            • Hostname pkg00-atx.netgate.com was found in DNS cache
                            • Trying 208.123.73.207:443...
                            • Connected to pkg00-atx.netgate.com (208.123.73.207) port 443
                            • ALPN: curl offers http/1.1
                            • CAfile: none
                            • CApath: /etc/ssl/certs/
                            • SSL certificate problem: self-signed certificate in certificate chain
                            • Closing connection
                              pkg-static: An error occured while fetching package
                              Unable to update repository pfSense
                            stephenw10S 1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator @jlw52761
                              last edited by

                              @jlw52761 said in Unable to pull in package repo: "pfSense-repoc: invalid signature":

                              SSL certificate problem: self-signed certificate in certificate chain

                              Run: certctl rehash

                              Then recheck.

                              J 1 Reply Last reply Reply Quote 3
                              • J
                                jlw52761 @stephenw10
                                last edited by

                                @stephenw10 what a simple fix. Strange on a fresh install that’s a problem but seems to have resolved. Will need to retry the upgrade in the daytime me.

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  That's fixed in 2.7.2.

                                  1 Reply Last reply Reply Quote 0
                                  • L
                                    l.pachalski
                                    last edited by

                                    Hi @stephenw10 pfSense-repoc: invalid signature here.
                                    Thanks

                                    1 Reply Last reply Reply Quote 0
                                    • podlakP
                                      podlak
                                      last edited by

                                      After system failure and disk replacement I'm facing same issue and unfortunetely running certctl rehash gives no effect.
                                      Do I have to regenerate my token for my pfSense+ license? If yes, how to do that?

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        Send me your NDI in chat and I'll check it. That would only be an issue in Plus though.

                                        1 Reply Last reply Reply Quote 1
                                        • S
                                          simplyarne
                                          last edited by simplyarne

                                          Happy New Year,

                                          after connecting two pfSense instances via WireGuard VPN (home and cloud) I have the same problem.
                                          On both instances I have the "pfSense-repoc: invalid signature" message on the System - Update page.

                                          @stephenw10 May I send you the two NDIs via PM?

                                          Best regards
                                          Arne

                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            Sure send me them in chat and I can check them.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.