Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Update OpenSSL to 1.1.0 or 1.1.1pre

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    3 Posts 2 Posters 621 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • dragoangelD
      dragoangel
      last edited by dragoangel

      Did anyone tried to manually compile newer OpenSSL then installed by default? Maybe good idea create plugin with can be installed via plugin manager? This can be interesting/helpful for people that use squid slicing proxy and for haproxy.

      Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
      Unifi AP-AC-LR with EAP RADIUS, US-24

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan
        last edited by

        The "pfSense environment" (the OS, included drivers and programs, scripts) isn't meant to be a development platform.
        You be needing the header files, libraries and boatloads build dependencies, and of course the make tools. Install, them all and you'll break pfSense for sure.
        You'll be needing another device with a vanilla FreeBSD setup that respects as close as possible the FreeBSD version that pfSense is using, prepare it so it has all the tools, and make your "package". When done, you will have to copy "in place" all the related files (openssl is a big one, and not a simple one neither).

        If you need the "the latest and greatest" (features and bugs) I would use some server on LAN that uses 1.1.1pre and simply NATted the needed ports to this server.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • dragoangelD
          dragoangel
          last edited by dragoangel

          I'm understand complexity of task, and because of it I ask this at forum before destroy my pfSense ☺ . Obviously use pfSense for build bins is really not good idea. About simply use NAT: I really like how in pfSense work Squid (for proxy) and HAproxy (for reverse proxy) and how I can combine HAproxy with pfBlocker aliases and GeoIP, and it will be awesome if them will support at least mainline OpenSSL version like optional plugin, and LTS line 1.0.2 by default that goes in FreeBSD. Or maybe some paranoiac guys do this already and have how-to in home wiki 😃

          Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
          Unifi AP-AC-LR with EAP RADIUS, US-24

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.