SG-1100 Unable to check for updates (Certificate verification failed)
-
When attempting via the console I get:
>>> Updating repositories metadata... Updating pfSense-core repository catalogue... 1082884096:error:141F0006:SSL routines:tls_construct_cert_verify:EVP lib:/usr/local/poudriere/jails/pfSense_plus-v21_02_2_aarch64/usr/src/crypto/openssl/ssl/statem/statem_lib.c:283: Certificate verification failed for /C=US/ST=Texas/L=Austin/O=Rubicon Communications, LLC (Netgate)/CN=repo00.netgate.com 1082884096:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/usr/local/poudriere/jails/pfSense_plus-v21_02_2_aarch64/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1915: Child process pid=22555 terminated abnormally: Segmentation fault ERROR: Unable to compare version of pfSense-repo
Any suggestions?
-
@harrdou
I had a similar issue on a 2100; an answer may be to actually power cycle the device, not just a reboot.
Do a Halt system, wait for it stop (the ARM based systems do not power off), then physically pull power for at least 30 secs, then plug power back in and retry.Why?
It seems some of the crypto stuff can wedge that part of the hardware, resetting does not clear it, a power cycle does. -
@mer said in SG-1100 Unable to check for updates (Certificate verification failed):
physically pull power
For @harrdou , there's a doc page on this. I believe I read that was fixed in 21.02 or maybe .05 but the point is if you pull power once, then update, it shouldn't happen again.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.