Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FF33 and pfsense

    Scheduled Pinned Locked Moved General pfSense Questions
    9 Posts 6 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      Paladinemishakal
      last edited by

      Hi All,

      I have just updated my FF to 33.0.1 and I can't access my pfsense (2.1.5) GUI. I have previously set security.use_mozillapkix_verification to false in about:config and I have checked and the setting is still there. I tried with Chrome and IE and they both can access the pfsense GUI.

      Any one have any issue?

      Regards.

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        In theory what you did should be disabling the new certificate verification code that causes the slow (in your case very slow) access. You can also clean up the old cached certificates like this: https://forum.pfsense.org/index.php?topic=82828.msg458036#msg458036

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          You just updated to 33.0.1?  .2 has been out over a week - why would you be not using it?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            He doesn't say which OS. Perhaps his OS hasn't updated their repos yet. I'm still running 33.0 under Xubuntu. No issues there.

            What did you update from?

            Steve

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              FF took away the pkix toggle in FF 33, so it's a bigger issue now.

              Vote up and yell at Mozilla on this ticket: https://bugzilla.mozilla.org/show_bug.cgi?id=1056341

              But don't be that guy.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • P
                Paladinemishakal
                last edited by

                I am using Windows 7 Pro and now the auto-update on Firefox have updated the version to 33.0.3 and still I cannot open the pfSense web GUI.

                I have gone to the Buzilla and voted on this. Hope they can resolve this soon.

                1 Reply Last reply Reply Quote 0
                • P
                  phil.davis
                  last edited by

                  I am on Firefox 33.1 now. I have not seen any issue since I removed al the old "CompanyName" certificates. I have 6 of them again now, but it is not slow.
                  Maybe you have lots more of them?
                  The bug does describe an O(n!) algorithm that slows things down - so if you have 10, 15, 20 of those from connecting to lots of pfSense boxes then maybe it will slow down. How many do you have? Does cleaning them out and letting it start again help?

                  As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                  If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                  1 Reply Last reply Reply Quote 0
                  • L
                    LinuxTracker
                    last edited by

                    Here's how I handled it (before finding this thread).

                    While Firefox was hung loading an https page, I ran Process Monitor and found firefox.exe endlessly querying cert8.db. 
                    I closed Firefox and renamed cert8.db.  When I launched Firefox, it generated a new cert8.db and I can access the webUI again.

                    cert8.db located at

                    %APPDATA%\Mozilla\Firefox\Profiles\%FIREFOX_PROFILE_DIR%\cert8.db
                    
                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      That will only work to let you into a small number of pfSense devices until it trips the bug again. Also it would forget any other HTTPS certificates that were manually marked as trusted.

                      That db can be managed from inside the settings on Firefox, though it's still a poor workaround for most of us.

                      If you're on 2.1.5, apply this patch: http://files.pfsense.org/jimp/patches/cert-unique.patch
                      Afterward, from the shell, run:

                      pfSsh.php playback generateguicert
                      

                      Then the GUI will use a certificate that Firefox won't choke on.

                      If you're on 2.2 already, run the command above from the shell. It's already present. Certs on fresh 2.2 installs are fine.

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.