Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2100 upgrade to 25.07.1 hangs at install of ca_root_nss

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    9 Posts 4 Posters 771 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jacksonp
      last edited by

      • Hardware: Netgate 2100
      • Current OS: 24.11-RELEASE
      • Target OS: 25.07.1
      • Packages:
        • apcupsd
        • Avahi
        • aws-wizard
        • iperf (disabled)
        • ipsec-profile-wizard
        • pfBlockerNG-devel (tried enabled and disabled)
        • Service_Watchdog
        • System_Patches

      I am trying to upgrade to 25.07.1, would anyone have suggestions to get past the process hanging. ideally without having to re-flash the device for once to upgrade...

      I am doing the upgrade via the web UI, and it processes along until it reaches the download / install of ca_root_nss. When it hits this it appears to hang indefinitely.

      [50/79] Upgrading php83-readline from 8.3.12 to 8.3.19...
      [50/79] Extracting php83-readline-8.3.19: ......... done
      [51/79] Upgrading miniupnpd from 2.3.7,1 to 2.3.7_1,1...
      [51/79] Extracting miniupnpd-2.3.7_1,1: ....... done
      [52/79] Upgrading ca_root_nss from 3.104 to 3.104_1...
      [52/79] Extracting ca_root_nss-3.104_1: ....... done
      

      I have noticed however if I decided the issue the reboot via the WebUI the upgrade processes ever so slightly before the device reboots.

      [51/79] Extracting miniupnpd-2.3.7_1,1: ....... done
      [52/79] Upgrading ca_root_nss from 3.104 to 3.104_1...
      [52/79] Extracting ca_root_nss-3.104_1: ....... done
      <reboot issued after 5-10 min waiting>
      [52/79] Upgrading ca_root_nss from 3.104 to 3.104_1...
      [52/79] Extracting ca_root_nss-3.104_1: ....... done
      [53/79] Upgrading php83-sqlite3 from 8.3.12 to 8.3.19...
      <lose connection to webUI and device restarts>
      

      A secondary question :) how long can the boot environment name get before it may cause problems:

      >>> Renaming current boot environment from default_20250831235405_20250901001722 to default_20250831235405_20250901001722_20250901003445...done.
      
      S S 2 Replies Last reply Reply Quote 0
      • S Offline
        slu @jacksonp
        last edited by slu

        @jacksonp said in 2100 upgrade to 25.07.1 hangs at install of ca_root_nss:

        When it hits this it appears to hang indefinitely.

        This step need time...

        Edit: I would recommend to update via SSH.

        pfSense Gold subscription

        J 2 Replies Last reply Reply Quote 0
        • J Offline
          jacksonp @slu
          last edited by jacksonp

          @slu define time? I've given this ~30 minutes sitting at xtracting ca_root_nss

          1 Reply Last reply Reply Quote 0
          • J Offline
            jacksonp @slu
            last edited by

            @slu said in 2100 upgrade to 25.07.1 hangs at install of ca_root_nss:

            Edit: I would recommend to update via SSH.

            So I can understand better, ffor what reason?

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              You can still see the output from the upgrade process at the CLI even if the webgui process disconnects for some reason.

              Even better is to upgrade from the serial console directly.

              Yes extracting the ca_root_nss pkg can take a while on lower power CPUs. But not 30mins.

              1 Reply Last reply Reply Quote 0
              • J Offline
                jacksonp
                last edited by jacksonp

                thanks @slu and @stephenw10 it looks that another benefit of the ssh is it actually gets the upgrade working. 😵

                no errors, no delays, quick simple upgrade via ssh

                1 Reply Last reply Reply Quote 2
                • S Offline
                  SteveITS Rebel Alliance @jacksonp
                  last edited by

                  @jacksonp

                  if I decided the issue the reboot via the WebUI

                  I can’t stress enough not to reboot mid upgrade. If you did I’d be surprised you didn’t need to manually reinstall. Perhaps the boot environment install/check/rollback will catch that now (which would be terrific).

                  My rule of thumb has been that a 2100 on eMMC storage takes 10-15 minutes at least, without packages.

                  If viewing the console or ssh you can run top and see what’s going on.

                  The BE name is because you’re not running on ā€œdefaultā€ which it still assumes it needs to rename. Dunno about length. IIRC you can rename it?

                  If you have multiple BEs I’d suggest deleting old ones to free space.

                  Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                  Upvote šŸ‘ helpful posts!

                  J 1 Reply Last reply Reply Quote 0
                  • J Offline
                    jacksonp @SteveITS
                    last edited by

                    @SteveITS said in 2100 upgrade to 25.07.1 hangs at install of ca_root_nss:

                    I can’t stress enough not to reboot mid upgrade.

                    I was prepared to flash the device again, I've had to do it for nearly every upgrade since I got the device. It's has not been the most reliable. A bit better for the 24.x after the intro of a/b but nearly always something

                    S 1 Reply Last reply Reply Quote 1
                    • S Offline
                      SteveITS Rebel Alliance @jacksonp
                      last edited by

                      @jacksonp Well that’s unexpected also, haven’t had that sort of issue across our clients. I think the only reinstalls on 2100s were for the EFI issue.

                      Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                      Upvote šŸ‘ helpful posts!

                      1 Reply Last reply Reply Quote 1
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.