<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[upgrade woes - openssl SSL alert]]></title><description><![CDATA[<p dir="auto">Hey there,</p>
<p dir="auto">I've gone through old posts and other websites to try and find the answer but nothing seems to work. I am unable to access 'available packages' or even attempt to update via CLI.</p>
<p dir="auto">Unable to update repository pfSense-core<br />
Updating pfSense repository catalogue...<br />
1082822656:error:1409441B:SSL routines:ssl3_read_bytes:tlsv1 alert decrypt error:/usr/src/crypto/openssl/ssl/record/rec_layer_s3.c:1544:SSL alert number 51<br />
1082822656:error:1409441B:SSL routines:ssl3_read_bytes:tlsv1 alert decrypt error:/usr/src/crypto/openssl/ssl/record/rec_layer_s3.c:1544:SSL alert number 51<br />
1082822656:error:1409441B:SSL routines:ssl3_read_bytes:tlsv1 alert decrypt error:/usr/src/crypto/openssl/ssl/record/rec_layer_s3.c:1544:SSL alert number 51<br />
1082822656:error:1409441B:SSL routines:ssl3_read_bytes:tlsv1 alert decrypt error:/usr/src/crypto/openssl/ssl/record/rec_layer_s3.c:1544:SSL alert number 51<br />
pkg-static: https://repo01.atx.netgate.com/pkg/pfSense_plus-v22_05_aarch64-pfSense_plus_v22_05/meta.txz: Authentication error<br />
repository pfSense has no meta file, using default settings<br />
1082822656:error:1409441B:SSL routines:ssl3_read_bytes:tlsv1 alert decrypt error:/usr/src/crypto/openssl/ssl/record/rec_layer_s3.c:1544:SSL alert number 51<br />
1082822656:error:1409441B:SSL routines:ssl3_read_bytes:tlsv1 alert decrypt error:/usr/src/crypto/openssl/ssl/record/rec_layer_s3.c:1544:SSL alert number 51<br />
pkg-static: https://repo01.atx.netgate.com/pkg/pfSense_plus-v22_05_aarch64-pfSense_plus_v22_05/packagesite.pkg: Authentication error<br />
1082822656:error:1409441B:SSL routines:ssl3_read_bytes:tlsv1 alert decrypt error:/usr/src/crypto/openssl/ssl/record/rec_layer_s3.c:1544:SSL alert number 51<br />
1082822656:error:1409441B:SSL routines:ssl3_read_bytes:tlsv1 alert decrypt error:/usr/src/crypto/openssl/ssl/record/rec_layer_s3.c:1544:SSL alert number 51<br />
pkg-static: https://repo01.atx.netgate.com/pkg/pfSense_plus-v22_05_aarch64-pfSense_plus_v22_05/packagesite.txz: Authentication error</p>
<p dir="auto">I am running a Netgate 1100 and haven't had an issue before. Anybody hit this issue before?</p>
<p dir="auto">And yes, I have power cycled the box (unplugged, waited a minute, plugged back in [thus, I have tried turning if off and on again])</p>
<p dir="auto"><img src="/assets/uploads/files/1667425171375-389dbd7a-728b-4ed9-a7aa-91572a7d536b-image.png" alt="389dbd7a-728b-4ed9-a7aa-91572a7d536b-image.png" class=" img-fluid img-markdown" /><br />
Thanks</p>
]]></description><link>https://forum.netgate.com/topic/175652/upgrade-woes-openssl-ssl-alert</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Apr 2026 06:33:49 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/175652.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 02 Nov 2022 21:39:38 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to upgrade woes - openssl SSL alert on Thu, 03 Nov 2022 13:09:08 GMT]]></title><description><![CDATA[<p dir="auto">For those who are still watching...the HOW of the issue is unclear but regardless, i'm just resetting the box to move on with life...</p>
<p dir="auto">thanks <a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a>  for the help</p>
<p dir="auto">thread closed</p>
]]></description><link>https://forum.netgate.com/post/1069202</link><guid isPermaLink="true">https://forum.netgate.com/post/1069202</guid><dc:creator><![CDATA[j3hst3r]]></dc:creator><pubDate>Thu, 03 Nov 2022 13:09:08 GMT</pubDate></item><item><title><![CDATA[Reply to upgrade woes - openssl SSL alert on Wed, 02 Nov 2022 22:30:02 GMT]]></title><description><![CDATA[<p dir="auto">Hmm, no that's actually newer than the 22.05 repo version:</p>
<pre><code>Command history storage is enabled. Clear history with: history -c; history -S.
[22.05-RELEASE][admin@2100-3.stevew.lan]/root: pkg -v
1.17.5
[22.05-RELEASE][admin@2100-3.stevew.lan]/root: pkg-static -v
1.17.5
</code></pre>
<p dir="auto">Checking....</p>
]]></description><link>https://forum.netgate.com/post/1069118</link><guid isPermaLink="true">https://forum.netgate.com/post/1069118</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 02 Nov 2022 22:30:02 GMT</pubDate></item><item><title><![CDATA[Reply to upgrade woes - openssl SSL alert on Wed, 02 Nov 2022 22:25:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a><br />
pkg -v is 1.18.3 -- is this accurate?</p>
]]></description><link>https://forum.netgate.com/post/1069117</link><guid isPermaLink="true">https://forum.netgate.com/post/1069117</guid><dc:creator><![CDATA[j3hst3r]]></dc:creator><pubDate>Wed, 02 Nov 2022 22:25:58 GMT</pubDate></item><item><title><![CDATA[Reply to upgrade woes - openssl SSL alert on Wed, 02 Nov 2022 22:24:47 GMT]]></title><description><![CDATA[<p dir="auto">Well I can try to fix your reputation....</p>
]]></description><link>https://forum.netgate.com/post/1069116</link><guid isPermaLink="true">https://forum.netgate.com/post/1069116</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 02 Nov 2022 22:24:47 GMT</pubDate></item><item><title><![CDATA[Reply to upgrade woes - openssl SSL alert on Wed, 02 Nov 2022 22:23:54 GMT]]></title><description><![CDATA[<p dir="auto">So fails with both pkg and pkg-static?</p>
<p dir="auto">Last time I saw this is was due to an older version of pkg-static being incorrectly installed by a package.</p>
]]></description><link>https://forum.netgate.com/post/1069115</link><guid isPermaLink="true">https://forum.netgate.com/post/1069115</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 02 Nov 2022 22:23:54 GMT</pubDate></item><item><title><![CDATA[Reply to upgrade woes - openssl SSL alert on Wed, 02 Nov 2022 22:22:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a></p>
<p dir="auto">pkg -d update:</p>
<p dir="auto">DBG(1)[5558]&gt; PkgRepo: extracting packagesite.yaml of repo pfSense<br />
DBG(1)[18095]&gt; PkgRepo: extracting signature of repo in a sandbox<br />
pkg: No trusted public keys found<br />
Unable to update repository pfSense<br />
Error updating repositories!</p>
<p dir="auto">pkg-static -d update throws the same as pfSense-upgrade -d</p>
<p dir="auto">and this 120 seconds post time restriction due to reputation is lame :)</p>
]]></description><link>https://forum.netgate.com/post/1069114</link><guid isPermaLink="true">https://forum.netgate.com/post/1069114</guid><dc:creator><![CDATA[j3hst3r]]></dc:creator><pubDate>Wed, 02 Nov 2022 22:22:52 GMT</pubDate></item><item><title><![CDATA[Reply to upgrade woes - openssl SSL alert on Wed, 02 Nov 2022 22:20:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a></p>
<p dir="auto">I've done each one. The initial post was pfSense-upgrade -d but all pkg commands or pfSense-upgrade fails with the same :(</p>
<p dir="auto">And yes, you're right, I just passed -k and handshake went through</p>
]]></description><link>https://forum.netgate.com/post/1069113</link><guid isPermaLink="true">https://forum.netgate.com/post/1069113</guid><dc:creator><![CDATA[j3hst3r]]></dc:creator><pubDate>Wed, 02 Nov 2022 22:20:46 GMT</pubDate></item><item><title><![CDATA[Reply to upgrade woes - openssl SSL alert on Wed, 02 Nov 2022 22:19:50 GMT]]></title><description><![CDATA[<p dir="auto">Yes, that's expected to fail unless you pass the client cert with the request.</p>
]]></description><link>https://forum.netgate.com/post/1069112</link><guid isPermaLink="true">https://forum.netgate.com/post/1069112</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 02 Nov 2022 22:19:50 GMT</pubDate></item><item><title><![CDATA[Reply to upgrade woes - openssl SSL alert on Wed, 02 Nov 2022 22:18:45 GMT]]></title><description><![CDATA[<p dir="auto">For more information, there seems to be a local cert issue? Not sure why, I never changed anything in terms of the certificates in the cert store:</p>
<p dir="auto">curl -vvv https://repo01.atx.netgate.com</p>
<ul>
<li>Trying 208.123.73.209:443...</li>
<li>Connected to repo01.atx.netgate.com (208.123.73.209) port 443 (#0)</li>
<li>ALPN: offers h2</li>
<li>ALPN: offers http/1.1</li>
<li>CAfile: /usr/local/share/certs/ca-root-nss.crt</li>
<li>CApath: none</li>
<li>TLSv1.3 (OUT), TLS handshake, Client hello (1):</li>
<li>TLSv1.3 (IN), TLS handshake, Server hello (2):</li>
<li>TLSv1.2 (IN), TLS handshake, Certificate (11):</li>
<li>TLSv1.2 (OUT), TLS alert, unknown CA (560):</li>
<li>SSL certificate problem: unable to get local issuer certificate</li>
<li>Closing connection 0<br />
curl: (60) SSL certificate problem: unable to get local issuer certificate<br />
More details here: https://curl.se/docs/sslcerts.html</li>
</ul>
<p dir="auto">curl failed to verify the legitimacy of the server and therefore could not<br />
establish a secure connection to it. To learn more about this situation and<br />
how to fix it, please visit the web page mentioned above.</p>
]]></description><link>https://forum.netgate.com/post/1069111</link><guid isPermaLink="true">https://forum.netgate.com/post/1069111</guid><dc:creator><![CDATA[j3hst3r]]></dc:creator><pubDate>Wed, 02 Nov 2022 22:18:45 GMT</pubDate></item><item><title><![CDATA[Reply to upgrade woes - openssl SSL alert on Wed, 02 Nov 2022 22:18:05 GMT]]></title><description><![CDATA[<p dir="auto">Hmm, that was a known issue during 22.05 development but should be fixed in  the release images. Has that been running release for some time?</p>
<p dir="auto">Try running at the command line:</p>
<pre><code>pkg-static -d update
</code></pre>
<p dir="auto">Should show that same error but with more debug output.<br />
Then try:</p>
<pre><code>pkg -d update
</code></pre>
<p dir="auto">That may succeed.</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/1069110</link><guid isPermaLink="true">https://forum.netgate.com/post/1069110</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 02 Nov 2022 22:18:05 GMT</pubDate></item></channel></rss>