Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    certificate error while running pkg update

    Scheduled Pinned Locked Moved General pfSense Questions
    27 Posts 19 Posters 9.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      AB5G
      last edited by AB5G

      Same for me

      Updating repositories metadata...
      pkg-static: Warning: Major OS version upgrade detected. Running "pkg bootstrap -f" recommended
      Updating pfSense-core repository catalogue...
      Certificate verification failed for /C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root

      1 Reply Last reply Reply Quote 1
      • A
        Apsis-IM
        last edited by

        I'm pretty new to pfsense and BSD in general. I went wild with fixes all over this board, Reddit, and random google search results. It appears this has happened before (May 2020). The netgate team had to update certs on the webserver.

        Y 1 Reply Last reply Reply Quote 1
        • Y
          Yamabushi @Apsis-IM
          last edited by

          @apsis-im
          Yep, I think you are correct.

          1 Reply Last reply Reply Quote 0
          • JRubenCJ
            JRubenC
            last edited by

            +1

            Not working either on a new install I was performing this Saturday.

            Interestingly, both https://files00.netgate.com/ and https://files01.netgate.com/ have a valid certificate:

            *  subject: OU=Domain Control Validated; OU=PositiveSSL Wildcard; CN=*.netgate.com
            *  start date: Mar 13 00:00:00 2019 GMT
            *  expire date: Apr 11 23:59:59 2021 GMT
            

            so clearly is something deeper in their setup... I guess we have to wait.

            1 Reply Last reply Reply Quote 1
            • C
              castigo86
              last edited by

              Yeah, same for me on pgk upgrade && pkg update.

              Certificate verification failed for /C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root

              Let's wait and see

              1 Reply Last reply Reply Quote 0
              • M
                monofox
                last edited by

                +1

                Can confirm this on latest stable pfSense factory. This does still happen after removing AddTrust CA from /usr/local/share/certs/ca-root-nss.crt (may we need to reboot?)

                curl, openssl, etc. is choosing the correct certification path. fetch / pkg on freebsd seems to choose a different way for certification verification? Normally it should automatically ignore the AddTrust also its send from server and divert to system path and to go one of those two ways:
                712dd960-4ee4-4734-a64b-e31e79fc7664-image.png

                If i see it correctly, #1 must be possible for pfSense, as USERTrust RSA Certification Authority seems in system store.

                Temporarily for urgent matter, it is strongly not recommended, but possible by disabling certification peer check via env SSL_NO_VERIFY_PEER=1 pkg update

                1 Reply Last reply Reply Quote 0
                • A
                  Alex89
                  last edited by

                  Same here.. Thought it was an error on my side until i found this thread.. ๐Ÿ˜†
                  I guess we have to wait for the Team to fix that..?

                  1 Reply Last reply Reply Quote 3
                  • C
                    castigo86
                    last edited by

                    Did anyone post a bug report?

                    provelsP 1 Reply Last reply Reply Quote 0
                    • provelsP
                      provels @castigo86
                      last edited by

                      @castigo86
                      I wouldn't worry too much. Mods will see in forum.

                      Peder

                      MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                      BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                      JRubenCJ 1 Reply Last reply Reply Quote 1
                      • JRubenCJ
                        JRubenC @provels
                        last edited by

                        @provels said in certificate error while running pkg update:

                        @castigo86
                        I wouldn't worry too much. Mods will see in forum.

                        Yeah. But it's a bit embarrasing that for everybody out there running pfsense systems, we're now stuck without being able to install new packages just because someone somewhere hasn't a proper monitoring of something and someone somewhere has to wake up on this Saturday, check the forums, see the 2 threads about it, think "shit!" and fix it.

                        ๐Ÿ˜Š

                        1 Reply Last reply Reply Quote 0
                        • D
                          ddave
                          last edited by

                          any options to install from command line? Trying to setup the OpenVPN Export wizard.

                          1 Reply Last reply Reply Quote 0
                          • R
                            revengineer
                            last edited by

                            Same issue here.

                            1 Reply Last reply Reply Quote 1
                            • Z
                              Zak 0
                              last edited by

                              Same, joined to post a question to get help, will get fixed when it's fixed.

                              1 Reply Last reply Reply Quote 1
                              • N
                                nolaquen
                                last edited by

                                Had the issue all morning, but it's back up and working for me now.

                                1 Reply Last reply Reply Quote 1
                                • C
                                  castigo86
                                  last edited by

                                  Yap, I can confirm it's working for me too now.

                                  1 Reply Last reply Reply Quote 1
                                  • viktor_gV
                                    viktor_g Netgate
                                    last edited by

                                    Fixed! ๐Ÿ‘

                                    1 Reply Last reply Reply Quote 1
                                    • fjsantosF
                                      fjsantos
                                      last edited by

                                      @viktor_g said in certificate error while running pkg update:

                                      Fixed!

                                      Fixed!

                                      1 Reply Last reply Reply Quote 1
                                      • elite_kzmE
                                        elite_kzm
                                        last edited by

                                        Working for me now as well, but I had to manually force an update via the cmd line: /usr/local/sbin/pkg-static update -f

                                        1 Reply Last reply Reply Quote 0
                                        • Z
                                          zitstif
                                          last edited by

                                          I'm now having this issue, I was able to update the day before.

                                          pkg update
                                          pkg: Warning: Major OS version upgrade detected. Running "pkg bootstrap -f" recommended
                                          Updating pfSense-core repository catalogue...
                                          Certificate verification failed for /C=US/ST=Texas/L=Austin/O=Rubicon Communications, LLC (Netgate)/CN=repo01.netgate.com
                                          1086972976:error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed:/build/factory-crossbuild-245-aarch64/sources/FreeBSD-src/crypto/openssl/ssl/s3_clnt.c:1269:

                                          [truncated]

                                          Unable to update repository pfSense
                                          Error updating repositories!

                                          A 1 Reply Last reply Reply Quote 0
                                          • A
                                            Apsis-IM @zitstif
                                            last edited by Apsis-IM

                                            @zitstif looks like a very different issue.

                                            Certificate verification failed for /C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root

                                            Is what we were experiencing before.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.