Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Could not load client certificate /etc/ssl/pfSense-repo-custom.cert

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    12 Posts 5 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      snapper
      last edited by

      Hi,

      I had a pfSense Plus install that I had issues with, so have reinstalled from scratch. Now I'm unable to convert from CE to Plus anymore.
      This is on a Protectli VP2410 mini PC.

      I have downloaded and reinstalled CE 2.6. All works fine.
      When I check the System / Register menu, I get the following:

      Your device does not require registration, we recognize it already. You may have already registered, or it may be a pre-registered Netgate appliance.

      Moving then to System / Update, changing the dropdown to pfSense Plus Upgrade branch, the message is Unable to check for updates.
      Looking at Latest Stable, it says it's up to date, so don't think outbound comms is an issue.

      Following the Troubleshooting page, I have run this command pfSense-upgrade -d -c
      and the output is:

      >>> Updating repositories metadata...
      Updating pfSense-core repository catalogue...
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      pkg-static: https://pfsense-plus-pkg01.netgate.com/pfSense_plus-v22_01_amd64-core/meta.txz: Authentication error
      repository pfSense-core has no meta file, using default settings
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      pkg-static: https://pfsense-plus-pkg01.netgate.com/pfSense_plus-v22_01_amd64-core/packagesite.pkg: Authentication error
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      pkg-static: https://pfsense-plus-pkg01.netgate.com/pfSense_plus-v22_01_amd64-core/packagesite.txz: Authentication error
      Unable to update repository pfSense-core
      Updating pfSense repository catalogue...
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      pkg-static: https://pfsense-plus-pkg01.netgate.com/pfSense_plus-v22_01_amd64-pfSense_plus_v22_01//meta.txz: Authentication error
      repository pfSense has no meta file, using default settings
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      pkg-static: https://pfsense-plus-pkg01.netgate.com/pfSense_plus-v22_01_amd64-pfSense_plus_v22_01//packagesite.pkg: Authentication error
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
      pkg-static: https://pfsense-plus-pkg01.netgate.com/pfSense_plus-v22_01_amd64-pfSense_plus_v22_01//packagesite.txz: Authentication error
      Unable to update repository pfSense
      Error updating repositories!
      ERROR: Unable to compare version of pfSense-repo
      

      Looking in this forum, I can see someone else had this issue a few weeks back, but it was supposedly fixed...
      I have tried the IPv4 prefer trick but that doesn't work.

      So I don't know if the original issue that was fixed a few weeks back has reoccured, if there is an issue with my new install being detected as already registered, or something else...

      Anyone got any other ideas I can try?

      Many thanks

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Are you still seeing that problem? I know there was an issue over the weekend but it should be resolved now.

        Steve

        S 1 Reply Last reply Reply Quote 0
        • S
          snapper @stephenw10
          last edited by

          @stephenw10 Hi, yes seemed to be a weekend issue, upgraded fine now thanks…

          1 Reply Last reply Reply Quote 1
          • Y
            yasahiro_x
            last edited by

            @snapper said in Could not load client certificate /etc/ssl/pfSense-repo-custom.cert:

            pfSense-upgrade -d -c

            Hi @stephenw10
            I'm encountering the same problem as the thread starter when trying to upgrade.

            Updating repositories metadata...
            Updating pfSense-core repository catalogue...
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            pkg-static: https://pfsense-plus-pkg01.atx.netgate.com/pfSense_plus-v22_01_amd64-core/meta.txz: Authentication error
            repository pfSense-core has no meta file, using default settings
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            pkg-static: https://pfsense-plus-pkg01.atx.netgate.com/pfSense_plus-v22_01_amd64-core/packagesite.pkg: Authentication error
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            pkg-static: https://pfsense-plus-pkg01.atx.netgate.com/pfSense_plus-v22_01_amd64-core/packagesite.txz: Authentication error
            Unable to update repository pfSense-core
            Updating pfSense repository catalogue...
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            pkg-static: https://pfsense-plus-pkg01.atx.netgate.com/pfSense_plus-v22_01_amd64-pfSense_plus_v22_01//meta.txz: Authentication error
            repository pfSense has no meta file, using default settings
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            pkg-static: https://pfsense-plus-pkg01.atx.netgate.com/pfSense_plus-v22_01_amd64-pfSense_plus_v22_01//packagesite.pkg: Authentication error
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            Could not load client certificate /etc/ssl/pfSense-repo-custom.cert
            pkg-static: https://pfsense-plus-pkg01.atx.netgate.com/pfSense_plus-v22_01_amd64-pfSense_plus_v22_01//packagesite.txz: Authentication error
            Unable to update repository pfSense
            Error updating repositories!
            ERROR: Unable to compare version of pfSense-repo

            Any word on the cause of the problem?

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              That backend issue was resolved. Please open a ticket with us to investigate:
              https://www.netgate.com/tac-support-request

              Steve

              Y 1 Reply Last reply Reply Quote 0
              • Y
                yasahiro_x @stephenw10
                last edited by

                @stephenw10

                Hi, thanks for the update. I've checked again and the upgrade went though without a hitch.

                1 Reply Last reply Reply Quote 1
                • M
                  MindlessMavis
                  last edited by

                  im receiving this issue now

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @MindlessMavis
                    last edited by

                    @mindlessmavis said in Could not load client certificate /etc/ssl/pfSense-repo-custom.cert:

                    im receiving this issue now

                    Check your clocks. Last april, that was 4 months ago.

                    This (thread) concerns a cert issue on the Netgate side.
                    It was resolved last April.

                    If the server side doesn't work, no one, that is : all the pfSense users, couldn't (look for) update any more.
                    That's not the case.

                    Enter an option: 13
                    
                    >>> Updating repositories metadata...
                    Updating pfSense-core repository catalogue...
                    Fetching meta.conf: . done
                    Fetching packagesite.pkg: . done
                    Processing entries: .. done
                    pfSense-core repository update completed. 14 packages processed.
                    Updating pfSense repository catalogue...
                    Fetching meta.conf: . done
                    Fetching packagesite.pkg: .......... done
                    Processing entries: .......... done
                    pfSense repository update completed. 542 packages processed.
                    All repositories are up to date.
                    Your packages are up to date
                    

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      MindlessMavis @Gertjan
                      last edited by

                      @gertjan

                      alt text

                      not sure where to go from here then.

                      GertjanG 1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @MindlessMavis
                        last edited by

                        @mindlessmavis

                        Nice, a scrolling gif 👍
                        But instead of uploading a million size gif image file, what about the old fashioned text copy and paste ?
                        I can't follow the scrolled lines as it is to fast - no pause button.
                        Also, a text copy paste is waaaay more space economic (CO2 friendly 😊 )

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          You are trying to upgrade from CE to Plus here?

                          Did you also just reinstall?

                          You might need to open a ticket and ask to have your NDI bumped. Or just wait 24hrs. There's a limit to the number of times the server will hand out certificates, you may have exhausted it.

                          Steve

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            MindlessMavis @stephenw10
                            last edited by

                            yup from CE to plus and I also did a reinstall recently. After about 8 hours it allowed me to upgrade. likely what happened is as you described.

                            1 Reply Last reply Reply Quote 1
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.