Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    MD5 not matching File

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    24 Posts 7 Posters 4.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      This came up before with someone else saying the mirrors were all messed up.. All testing I did was fine then, you got something messing with your downloads.. You trying to use some sort of download accelerator?

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • T
        TIm the BIG Nooob
        last edited by

        I go here to DL the files

        https://pfsense.org/download/mirror.php?section=downloads

        Select 1386 memstick vga and get these mirrors

        Country Hosting by Location
        US ESF Austin, TX USA                                    …Untrusted
        NL Coltex Amsterdam, Netherlands            ...connection timed out
        IE Webcore Cloud Ireland                      ... unable to connect try again
        US BluegrassNet Louisville, KY USA                ... unable to connect try again
        US NYI New York City                                    ...Untrusted
        GB Peer Point Internet London, UK                ... unable to connect try again

        This is copy and paste of the message I get...

        This Connection is Untrusted

        You have asked Firefox to connect securely to files.nyi.pfsense.org, but we can't confirm that your connection is secure.

        Normally, when you try to connect securely, sites will present trusted identification to prove that you are going to the right place. However, this site's identity can't be verified.
        What Should I Do?

        If you usually connect to this site without problems, this error could mean that someone is trying to impersonate the site, and you shouldn't continue.

        This site uses HTTP Strict Transport Security (HSTS) to specify that Firefox only connect to it securely. As a result, it is not possible to add an exception for this certificate.

        I am not using any kind of Downloader I am on Comcast currently using a sbg6580 and my main reason for going down this road is I cannot use the firewall and portforward through it.

        I tried the link you put in your response and got the "Untrusted ....get me outa here" message.

        To note I CAN get the MD5 download instantly no problem.

        1 Reply Last reply Reply Quote 0
        • T
          TIm the BIG Nooob
          last edited by

          In addition I just downloaded Sandboxie and got a hash match so that all works at least for sandboxie.

          My thought is to try to DL from the untrusted site from within sandboxie to at least see if I can get a hash match file.

          1 Reply Last reply Reply Quote 0
          • T
            TIm the BIG Nooob
            last edited by

            Silly me I went to Dl from the Untrusted site through Sandboxie and realized there is NO option to Continue to the site its not just a warning its a roadblock.

            This process is really killing my enthusiasm for the whole deal.

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              I do not get https links on any of the mirrors. You have something like https everywhere forcing https when it shouldn't?

              I do agree it's bad form to have a site respond to https with a bad certificate, but it shouldn't stop you from downloading it.

              Copy the link for the mirror you want, paste it in the location bar, and remove the s from https.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • D
                doktornotor Banned
                last edited by

                Haaaaaaaaaaaaahahahahaha. Please, uninstall your browser "improvements". There's been a thread about this not even a month ago.

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  pretty sure even if you download via https still works..  But yeah with dok on this, those links are not https - so your running something that is switching it.

                  I show for example those links as http://files.atx.pfsense.org/mirror/updates/pfSense-Full-Update-2.2.4-RELEASE-i386.tgz

                  If you have tried to go there before with https then browser can remember that, etc.

                  You should not be getting pointed to https in those links, they are all http.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • BBcan177B
                    BBcan177 Moderator
                    last edited by

                    https://www.reddit.com/r/PFSENSE/comments/3notso/pfsenseorg_seems_down_docs_forums_any_alternates/

                    https://twitter.com/pfsense

                    "Experience is something you don't get until just after you need it."

                    Website: http://pfBlockerNG.com
                    Twitter: @BBcan177  #pfBlockerNG
                    Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      So I just got this to happen with firefox 41, it likes to use https if you have on https for that site before.  So I was getting links to https even though they don't work because I had been playing around with https on the previous threads about this.

                      i just cleared firefox cache, website prefs, etc.. And now it goes to http for all those mirrors like it suppose too.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • D
                        doktornotor Banned
                        last edited by

                        @BBcan177:

                        https://www.reddit.com/r/PFSENSE/comments/3notso/pfsenseorg_seems_down_docs_forums_any_alternates/

                        https://twitter.com/pfsense

                        Hmmm, so all those 3 DNS servers are behind a single switch? Sounds like that needs some redesign.

                        1 Reply Last reply Reply Quote 0
                        • T
                          TIm the BIG Nooob
                          last edited by

                          Ok heres one for all you beautifully smart people I do not have "https everywhere"  as an addon in Firefox Chrome or IE.

                          The only reference to it was in Eset NOD32 my AV but the selection was greyed out so I temp disabled Nod32 and still no DL

                          Since its effecting all 3 browsers Im thinking it must be Windows or perhaps a Arris router setting that forces Https.  ???? If possible ???

                          BUT I just tried DL from Firefox in NEW PRIVATE WINDOW  and VIOLA !!!!!!  It worked ! Hurray

                          now to see if hashes match….......

                          1 Reply Last reply Reply Quote 0
                          • D
                            doktornotor Banned
                            last edited by

                            Aaah, the famous ESET MITM thing… @TIm:

                            The only reference to it was in Eset NOD32

                            https://forum.pfsense.org/index.php?topic=93188.0

                            This "feature" is exactly as helpful in every AV out there.

                            1 Reply Last reply Reply Quote 0
                            • T
                              TIm the BIG Nooob
                              last edited by

                              OK I looked for an add-on for force HTTPS everywhere and found nothing.

                              There is a setting in Eset Nod32 for HTTP scanning but that's all greyed out so I didnt try to mess with it.

                              Disabled Nod32 and still didn't work.

                              Firefox, Chrome and IE would not go HTTP alone.

                              What finally did just work is 'New private window"

                              SO I just DL the first file and here are the hashes

                              pfSense-memstick-2.2.4-RELEASE-i386(1).img.gz              f45cd3be36e5c44704352caa9172b723

                              MD5      12e914c5fe740ee55c8ebfa958fe16c2

                              Back to the beginning…... no matching  hash

                              1 Reply Last reply Reply Quote 0
                              • D
                                doktornotor Banned
                                last edited by

                                Yeah, dude. Reinstall that superscrewed box. (And skip ESET.)

                                1 Reply Last reply Reply Quote 0
                                • T
                                  TIm the BIG Nooob
                                  last edited by

                                  @doktornotor:

                                  Yeah, dude. Reinstall that superscrewed box. (And skip ESET.)

                                  I can actually appreciate difficult issues like this because they are learning opportunities. I thank all of you for taking the time to help me out BUT when you just basically say F'  it just reinstall

                                  I'd at least like an explanation as to why you think that would be the best course. To me that sounds like 1st level tech support.  Are there certain circumstances that can effect the hash process

                                  to cause mismatch ?

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    Your internet is messing up your downloads.  Call your ISP.

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • KOMK
                                      KOM
                                      last edited by

                                      I thank all of you for taking the time to help me out BUT when you just basically say F'  it just reinstall

                                      A lot of us maintain these firewalls in corporate settings, and you often don't have the luxury of drilling down to the _n_th level to find out the source of a problem.  Oftentimes it's pragmatism that drives everything, and Get 'Er Done is more important than Who? How? Why?

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.