Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    I can not upgrade or install any pckage due to Certificate verification failed for /CN=*.netgate.com

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    10 Posts 3 Posters 359 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      zara
      last edited by zara

      Hello,
      I'm not able to install any package anymore due to error of 'Certificate verification failed for /CN=*.netgate.com'

      from GUI :
      22f17c67-f52d-49ae-ae9c-f606c7eb5574-image.png

      or from console :

      1. Logout (SSH only) 9) pfTop
      2. Assign Interfaces 10) Filter Logs
      3. Set interface(s) IP address 11) Restart webConfigurator
      4. Reset webConfigurator password 12) PHP shell + pfSense tools
      5. Reset to factory defaults 13) Update from console
      6. Reboot system 14) Disable Secure Shell (sshd)
      7. Halt system 15) Restore recent configuration
      8. Ping host 16) Restart PHP-FPM
      9. Shell

      Enter an option: 13

      Certificate verification failed for /CN=*.netgate.com
      0080C1EC331C0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-CE-snapshots-2_7_2-main/sources/FreeBSD-src-RELENG_2_7_2/crypto/openssl/ssl/statem/statem_clnt.c:1890:
      pfSense-repoc-static: failed to fetch the repo data
      failed to read the repo data.
      failed to update the repository settings!!!
      failed to update the repository settings!!!

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @zara
        last edited by Gertjan

        @zara

        Your pfSense version is 2.7.2, right ?
        System time is ok ?

        See here for a check list : Troubleshooting Upgrades.

        edit : Wait ... ...snapshots... ? 2.7.2 is the "released and stable" version. Not sure if the snapshot version is the right one here. (I'm using 24.11 myself, so can't check / test )
        You've set this : System > Update > System Update to what ?

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        Z 1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          It's trying to get updates from 2.7.2 but could be running a previous version. If that version is 2.7.0 then first run certctl rehash then retry.

          If that allows you see updates then upgrade to 2.7.2 before trying to install pkgs

          1 Reply Last reply Reply Quote 0
          • Z
            zara @Gertjan
            last edited by zara

            @Gertjan

            I'm using 2.7.2, my time is not correcte it's trange 8b38f50f-97c4-4989-b734-37c4307ee938-image.png

            but I can not fixe it
            a64d3b18-f736-4ea2-80c1-b3cafa93f86c-image.png

            25f27977-83fe-4622-bb30-ddf2dddcae14-image.png
            thanks for you help!

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Try just setting the time at the CLI directly. You're probably in a chicken/egg scenario where it cant resolve the time servers because DNSSec is enabled.

              [25.03-RC][admin@8200-2.stevew.lan]/root: date 2502211741
              Fri Feb 21 17:41:00 GMT 2025
              
              Z 1 Reply Last reply Reply Quote 0
              • Z
                zara @stephenw10
                last edited by

                @stephenw10

                after change it manually, the problem of CA is gone but I can not install any package. the list is empty

                5801a520-172c-4923-96f4-a8bc6ffe926e-image.png

                from cli:

                Enter an option: 13

                pfSense-repoc-static: failed to fetch the repo data
                failed to read the repo data.
                failed to update the repository settings!!!
                failed to update the repository settings!!!

                when reboot the pfsense my time is set again to ... 2030 it's strange

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Do you see the branches in the upgrade settings? If so try re-saving that.

                  What hardware is that?

                  Z 1 Reply Last reply Reply Quote 0
                  • Z
                    zara @stephenw10
                    last edited by

                    @stephenw10
                    esxi , It was working fine, the boot was crashed after a cut power so I reinstall it and import the config again. so since this wont be work.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      So all good now?

                      Z 1 Reply Last reply Reply Quote 0
                      • Z
                        zara @stephenw10
                        last edited by zara

                        @stephenw10

                        thanks for your support.

                        I install it from scratch and import the config and it is working fine know.
                        I don't know what was wrong.

                        my advice to everyone is that to make daily or weekly backup at least if you don't change the config a lot to save your life .

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.