Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    RESOLVED----> 24.03.b.20240322.1708 Issues with SSL certificates will not allow reboot to install 24

    Scheduled Pinned Locked Moved Plus 24.03 Development Snapshots (Retired)
    20 Posts 3 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee
      last edited by JonathanLee

      Screenshot 2024-01-12 at 10.00.18 AM.jpg

      After reboot many errors for not found operation not supported

      This certctl error continued for a long time it would not stop, it just hung on this.

      After I could not use any of my BE to go back it really caused issues when I interrupted this, but it would never continue it was stuck.

      Make sure to upvote

      1 Reply Last reply Reply Quote 0
      • JonathanLeeJ
        JonathanLee
        last edited by

        After this wipped out my boot enviroments all of them

        Make sure to upvote

        1 Reply Last reply Reply Quote 0
        • JonathanLeeJ
          JonathanLee
          last edited by

          I am stuck at Ok thats it

          Make sure to upvote

          1 Reply Last reply Reply Quote 0
          • JonathanLeeJ
            JonathanLee
            last edited by

            This version from today did not work I am going to restore from USB Dang...

            I thought I could get it to boot from usb console I got just and OK screen and it had a major issue showing if you typed quit it would fail and start over.

            Make sure to upvote

            1 Reply Last reply Reply Quote 0
            • JonathanLeeJ
              JonathanLee
              last edited by JonathanLee

              You could not access the boot environments after power cycle only marvel. I did see at one point that I was attemping to do a PXE boot with an image and showed T T T T T T T for timeouts after I noticed 3100 I have a 2100

              Make sure to upvote

              1 Reply Last reply Reply Quote 0
              • JonathanLeeJ
                JonathanLee
                last edited by

                So when open SSL was removed the certificates I created and approved marked trusted are somehow mixed up with non approved list. How can we migrate them into the trust store

                Make sure to upvote

                1 Reply Last reply Reply Quote 0
                • JonathanLeeJ
                  JonathanLee
                  last edited by

                  I am a Squid/Squidguard/Squidlite user. Is it safe to say do not update to 24 at this time as it will break the system and boot environments?

                  Make sure to upvote

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    That is just the output of certctl rehash after pkg gets reinstalled/upgraded.

                    That is almost certainly completely unrelated to whatever your real issue is there.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    JonathanLeeJ 2 Replies Last reply Reply Quote 1
                    • JonathanLeeJ
                      JonathanLee @jimp
                      last edited by

                      @jimp it wouldn’t stop ever I had to reinstall after

                      Make sure to upvote

                      1 Reply Last reply Reply Quote 0
                      • JonathanLeeJ
                        JonathanLee @jimp
                        last edited by

                        @jimp Should I attempt this again? I am worried my Squid Package is going to be auto deleted. If I had it prior to install of 24 would it still keep that package?

                        Make sure to upvote

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Squid still exists in 24.03. And specifically in aarch64:

                          [24.03-BETA][admin@2100-2.stevew.lan]/root: pkg search squid
                          lightsquid-1.8_5               Light and fast web based squid proxy traffic analyser
                          pfSense-pkg-Lightsquid-3.0.7_4 pfSense package Lightsquid
                          pfSense-pkg-squid-0.4.47       pfSense package squid
                          pfSense-pkg-squidGuard-1.16.20 pfSense package squidGuard
                          squid-6.6                      HTTP Caching Proxy
                          squidGuard-1.4_15              Fast redirector for squid
                          squid_radius_auth-1.10         RADIUS authenticator for squid proxy 2.5 and later
                          squidclamav-7.3                Clamav c-icap service and redirector for Squid
                          [24.03-BETA][admin@2100-2.stevew.lan]/root: uname -a
                          FreeBSD 2100-2.stevew.lan 15.0-CURRENT FreeBSD 15.0-CURRENT #1 plus-devel-main-n256292-447d90db3c9: Mon Mar 11 06:39:35 UTC 2024     root@freebsd:/var/jenkins/workspace/pfSense-Plus-snapshots-master-main/obj/aarch64/FPS8k6SP/var/jenkins/workspace/pfSense-Plus-snapshots-master-main/sources/FreeBSD-src-plus-devel-main/arm64.aarch64/sys/pfSense arm64
                          
                          JonathanLeeJ 2 Replies Last reply Reply Quote 1
                          • JonathanLeeJ
                            JonathanLee @stephenw10
                            last edited by

                            @stephenw10 YEAH!!!!!!!! I am scared to test 24 again based on what occurred last time. But I should use my other SSD and do it because this SSD is working really well right now. It would not stop that photo you see above, I interrupted it and that is what killed my kernel file on the drive I bet, but it killed the Boot Environments too.

                            Make sure to upvote

                            1 Reply Last reply Reply Quote 0
                            • JonathanLeeJ
                              JonathanLee @stephenw10
                              last edited by

                              @stephenw10 Should I attempt it again but just let it run for a couple hours uninterrupted?

                              Make sure to upvote

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                I would expect to just be able to upgrade. I'm not aware of any particular issue there.

                                JonathanLeeJ 1 Reply Last reply Reply Quote 1
                                • JonathanLeeJ
                                  JonathanLee @stephenw10
                                  last edited by

                                  @stephenw10 I have the custom authenticated NTP code I wonder if that messed it up

                                  Make sure to upvote

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Possibly but I would have expected that to just be removed at upgrade. Unless perhaps it's completely outside the pkg system.

                                    JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                    • JonathanLeeJ
                                      JonathanLee @stephenw10
                                      last edited by

                                      @stephenw10 just to confirm Squid is still accessible in 24? I am so excited to update if it is this StoreID tool that comes with the package is amazing it increased my speed drastically with use of ssl certs.

                                      Make sure to upvote

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        Yes it's available in 24.03. I assume you are asking about aarch64 specifically:

                                        [24.03-BETA][admin@2100-2.stevew.lan]/root: uname -a
                                        FreeBSD 2100-2.stevew.lan 15.0-CURRENT FreeBSD 15.0-CURRENT #1 plus-devel-main-n256297-0a9899b0f3e: Thu Mar 21 06:37:50 UTC 2024     root@freebsd:/var/jenkins/workspace/pfSense-Plus-snapshots-master-main/obj/aarch64/WGrYl659/var/jenkins/workspace/pfSense-Plus-snapshots-master-main/sources/FreeBSD-src-plus-devel-main/arm64.aarch64/sys/pfSense arm64
                                        [24.03-BETA][admin@2100-2.stevew.lan]/root: pkg search squid
                                        lightsquid-1.8_5               Light and fast web based squid proxy traffic analyser
                                        pfSense-pkg-Lightsquid-3.0.7_4 pfSense package Lightsquid
                                        pfSense-pkg-squid-0.4.47       pfSense package squid
                                        pfSense-pkg-squidGuard-1.16.20 pfSense package squidGuard
                                        squid-6.6                      HTTP Caching Proxy
                                        squidGuard-1.4_15              Fast redirector for squid
                                        squid_radius_auth-1.10         RADIUS authenticator for squid proxy 2.5 and later
                                        squidclamav-7.3                Clamav c-icap service and redirector for Squid
                                        
                                        JonathanLeeJ 1 Reply Last reply Reply Quote 1
                                        • JonathanLeeJ
                                          JonathanLee @stephenw10
                                          last edited by JonathanLee

                                          @stephenw10 for arm 2100 thank you so much.

                                          Make sure to upvote

                                          1 Reply Last reply Reply Quote 0
                                          • JonathanLeeJ
                                            JonathanLee
                                            last edited by

                                            24.03.b.20240322.1708 resolved this

                                            1712246840439-screenshot-2024-04-04-090152.png

                                            System installs and boots and functions

                                            Make sure to upvote

                                            1 Reply Last reply Reply Quote 1
                                            • JonathanLeeJ JonathanLee referenced this topic on
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.