Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Skipping untrusted certificate - messages during update

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 1.2k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      FSC830
      last edited by FSC830

      Hi,
      I have looked up in forum search and found this topic, but actually I cant see a solution.

      I am using pfSense plus (in an appliance SG-3100 and in a VM for testing purposes), issue exists in both environments.
      When updating, a lot of error messages as seen in screenshot appearing, slowing down the update process by several minutes (in appliance).
      In VM it is rather quick, in appliance I thought update process was hanging.
      After several minutes update process continues.
      I noticed that the messages appeared for first time when updating from 23.09.1 to 24.x.
      Where do this messages come from?
      Any way to edit/replace some file(s) and to avoid the delay?
      pfSense_cert_update.png

      Regards and happy holidays.

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @FSC830
        last edited by

        @FSC830 said in Skipping untrusted certificate - messages during update:

        updating from 23.09.1 to 24.x.
        Any way to edit/replace some file(s) and to avoid the delay?
        Where do this messages come from?

        This was shown by others, if I recall well ... you have to go back in the forum history ... ;)

        Back then way in the past, when 23.09.1 was introduced, this "housekeeping task of testing and removing of old, not used certificates" showed up. It's harmless.
        I guess we all saw this long list of old certificates being removed 'fore good'.
        Remember : these main 'CA' certificates all have a end date.

        Continue to upgrade. Even 24.x is old these days. As pfSense tends to be a security related device, always use the latest release : 25.11 as of today.
        You still can encounter issues, but these have one major advantage : we've seen them all, and most are discussed recently on the forum, so if an 'solution' exist, it's easy to find.

        So, in short : how to avoid ?
        Easy : use a recent version ^^

        No "help me" PM's please. Use the forum, the community will thank you.

        F 1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          Those are not errors. That's just informatipnal output from the certctl rehash process.

          In 25.11 that process should be much faster. The process was rewritten upstream. See: https://redmine.pfsense.org/issues/16341

          1 Reply Last reply Reply Quote 0
          • F Offline
            FSC830 @Gertjan
            last edited by

            @Gertjan said in Skipping untrusted certificate - messages during update:

            Easy : use a recent version ^^

            Hehe, I am using now 25.11, but this messages are occuring by every update (23.09.1 -> 24.11 -> 25.07 -> 25.11)

            @stephenw10 said in Skipping untrusted certificate - messages during update:

            In 25.11 that process should be much faster.

            May be, when I updated the appliance to 25.11 it "feels" a bit faster than updating to 24.x or 25.07.
            But I did not stopping the time.

            Just wondering, why this happens now for all updates.

            Regards

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by stephenw10

              It was added specifically to address an issue in 2.7.0 where certs were lost at upgrade: https://redmine.pfsense.org/issues/14876

              But in 25.11 it really is a lot faster. For example here is a 3100:

              [25.11-RELEASE][admin@fw1.stevew.lan]/root: time certctl rehash
              0.562u 0.046s 0:00.62 96.7%	20+171k 1+1io 0pf+0w
              

              Compared with an older VM:

              [2.7.2-RELEASE][admin@cedev-3.stevew.lan]/root: time certctl rehash
              Scanning /usr/share/certs/untrusted for certificates...
              Scanning /usr/share/certs/trusted for certificates...
              Scanning /usr/local/share/certs for certificates...
              27.333u 1.296s 0:29.57 96.7%	532+222k 0+0io 0pf+0w
              
              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
              Privacy Policy · Cookie Policy