Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snapshot on 11th Jan 2011 GUI not work

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    35 Posts 7 Posters 7.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      iFloris
      last edited by

      Accessing the gui over https is working again for me using 2.0-BETA5 (i386) built on Thu Jan 13 19:33:19 EST 2011.
      Thanks jimp!

      one layer of information
      removed

      1 Reply Last reply Reply Quote 0
      • S
        siey2005
        last edited by

        I just tried the build now.. still failed.
        Thanks.

        1 Reply Last reply Reply Quote 0
        • L
          LostInIgnorance
          last edited by

          Doesn't work for me either?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            What errors are showing up in the system log now? What about /var/log/lighttpd.error.log?

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • L
              LostInIgnorance
              last edited by

              System Log

              Jan 14 10:23:53 	php: /system_advanced_admin.php: webConfigurator configuration has changed. Restarting webConfigurator.
              Jan 14 10:23:53 	check_reload_status: webConfigurator restart in progress
              Jan 14 10:23:55 	php: : The command '/usr/local/sbin/lighttpd -f /var/etc/lighty-webConfigurator.conf' returned exit code '255', the output was '2011-01-14 10:23:55: (network.c.565) SSL: error:00000000:lib(0):func(0):reason(0) /var/etc/ca.pem'
              Jan 14 10:23:55 	php: : Creating rrd update script
              Jan 14 10:25:14 	check_reload_status: syncing firewall
              

              /var/log/lighttpd.error.log

              2011-01-14 10:17:40: (log.c.166) server started 
              2011-01-14 10:17:46: (log.c.166) server started 
              2011-01-14 10:23:55: (log.c.166) server started 
              2011-01-14 10:25:18: (log.c.166) server started 
              2011-01-14 10:25:20: (log.c.166) server started 
              
              
              1 Reply Last reply Reply Quote 0
              • U
                uncon
                last edited by

                I've been able to work around this by commenting out the following line from /var/etc/lighty-webConfigurator.conf:

                ssl.ca-file = "/var/etc/ca.pem"
                

                Then, restarting lighttpd:

                lighttpd -f /var/etc/lighty-webConfigurator.conf
                

                It appears that the CA cert / key pair do not survive.

                uncon

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  That's the thing, with the default webgui cert there is no ca, so that line isn't there. I have no such line on mine.

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    Does /var/etc/ca.pem exist? If it does, is it empty? Or does it actually have the ca certificate in it?

                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • U
                      uncon
                      last edited by

                      When this issue occurs, the file ("/var/etc/ca.pem") exists and is empty.ย  I think this is only an issue if you create your own CA and subsequently a certificate for use with the webgui.

                      uncon

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        When you do "ls -l /var/etc/ca.pem" does it show as 0 bytes, or does it actually have some (blank) content in it like spaces or blank lines?

                        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • jimpJ
                          jimp Rebel Alliance Developer Netgate
                          last edited by

                          I've made a cert from an existing CA and used it and it was OK, and I made a fresh CA and cert and used it and it was still OKโ€ฆ so if there is something happening it's likely related to your config in some way.

                          I can add some extra safety belts around writing out the CA. It already checks if it's empty (as in empty string, "") but it should probably actually be using php's empty() call instead.

                          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                          Need help fast? Netgate Global Support!

                          Do not Chat/PM for help!

                          1 Reply Last reply Reply Quote 0
                          • U
                            uncon
                            last edited by

                            I can't seem to reproduce this now, but IIRC, the file was 0 bytes.

                            uncon

                            1 Reply Last reply Reply Quote 0
                            • L
                              LostInIgnorance
                              last edited by

                              @jimp:

                              That's the thing, with the default webgui cert there is no ca, so that line isn't there. I have no such line on mine.

                              JimP, like you, I have no such line in my /var/etc/lighty-webConfigurator.conf

                              1 Reply Last reply Reply Quote 0
                              • jimpJ
                                jimp Rebel Alliance Developer Netgate
                                last edited by

                                @LostInIgnorance:

                                JimP, like you, I have no such line in my /var/etc/lighty-webConfigurator.conf

                                To get the error you posted earlier, you have to have the ca line in the lighty config. If it wasn't there, you wouldn't get the error about ca.pem.

                                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                                Need help fast? Netgate Global Support!

                                Do not Chat/PM for help!

                                1 Reply Last reply Reply Quote 0
                                • L
                                  LostInIgnorance
                                  last edited by

                                  If I understand correctly, I should have that line in my file?

                                  EDIT: I can't verify if it is in there because when I change the login to HTTPS I get a timeout on my browser and have to reset it using the "Set interface(s) IP address" on the console to revert back to HTTP.

                                  1 Reply Last reply Reply Quote 0
                                  • jimpJ
                                    jimp Rebel Alliance Developer Netgate
                                    last edited by

                                    You posted that you had an error referencing ca.pem, in order for that error to happen, you have to have a line in the lighty config file that references ca.pem.

                                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                                    Need help fast? Netgate Global Support!

                                    Do not Chat/PM for help!

                                    1 Reply Last reply Reply Quote 0
                                    • L
                                      LostInIgnorance
                                      last edited by

                                      It is due to a CA getting deleted. ย My main CA that was created to access the webgui was deleted, but I am questioning why it has been deleted on two different machines with different configurations. ย Wondering if it happened with one of the upgrades because it has been in there since I initially configured the firewall.

                                      EDIT: All is working now that I recreated the CA.ย  Thanks JimP!!

                                      1 Reply Last reply Reply Quote 0
                                      • jimpJ
                                        jimp Rebel Alliance Developer Netgate
                                        last edited by

                                        I've never had a CA go missing, and I have VMs with up to 10 CAs on them that I use when testing the cert managerโ€ฆ

                                        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                                        Need help fast? Netgate Global Support!

                                        Do not Chat/PM for help!

                                        1 Reply Last reply Reply Quote 0
                                        • L
                                          LostInIgnorance
                                          last edited by

                                          The CA still shows up in my backup (from Nov. 1st) but doesn't show on the firewall itself config when I backed it up now.ย  It shows the newly generated one in it, but not the old one from the Nov. 1st backup.

                                          1 Reply Last reply Reply Quote 0
                                          • jimpJ
                                            jimp Rebel Alliance Developer Netgate
                                            last edited by

                                            Make sure you are looking in the right spot. The CA's should be near the bottom and not under <system>- they used to be there before in really old configs but were moved quite some time ago (and the upgrade code relocated them)

                                            They should be under their own <ca>tag, <cert>tag, and <crl>tag toward the end of the config.

                                            I just checked in a better test to make sure an empty CA isn't written out or used. Next snapshot should have it โ€“ one was not building but the commit should make the builders start a new run.</crl></cert></ca></system>

                                            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                                            Need help fast? Netgate Global Support!

                                            Do not Chat/PM for help!

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.