STunnel cannot start after upgrade to 26.03
-
Hi,
the upgrade from 25.11.1 was smooth and took about 5 minutes then the system back online. All packages redownloaded and work as expected but STunnel. I tried reinstalled the package, but still unable to get it started. I am now restored the system with the 25.11.1 environment backup. The same config has been using for last 2 years. So I am not sure what is wrong. Does anyone have the same problem?
Found this error message on system log:
pid 55291 (stunnel), jid 0, uid 0: exited on signal 10 (core dumped)Thanks for help in advance.
-
Hmm, what are you running that on?
How are you using STunnel?
-
@stephenw10 Hi Stephen, I am running it in a mini PC with Intel Celeron N5105 and 8GB RAM. I use STunnel to listen port 443 and redirect it to Openvpn server running in another port which is not open publicly. The purpose is to wrap the Openvpn with TLS. I do not know what has changed, the same setting has been using for last 2 years with no issue at all. Just happened after upgrade to 26.03. I do not know much in pfsense although am using use for a few years in a basic setting for a small home network. By any chance you know what is that error means?
-
That's some relatively low level problem in the STunnel binary causing it to core dump with no other output.
Does it happen immediately or only when it tries to carry traffic? Does it log that every time you try to start it? Is anything else logged?
Is the webgui using a different port?
-
Yes, the GUI use other ports. When the system restart, all packages load and up, except STunnel cannot. I tried manually start it, still the same. Doesn't know why. The system log only have that message, and every time I tried to start, the same message show. Excpet different pid.
-
Hmm, OK I've replicated that. Digging.....
-
@stephenw10 thank you for your time, Stephen. I look forward to the solution.
-
For tracking: https://redmine.pfsense.org/issues/16785
-
OK it's trying to set both the default and custom tunnel cert at the same time and failing. It's fixed upstream (5.78) so we will have to pull it in:
Fixed a startup crash when both global (default) and service-level lists of values are configured for an option.It starts fine if you do not specify a cert to use and it just uses the default. But that may not be useful in your application.
-
@stephenw10 -yes, I have a dedicated cert for the openvpn. You mean it is fixed in 5.78? Then I wait for the next update. I will be staying at 25.11.1 for now. Thanks for all your help. I am very appreciated.
-
Yup it's fixed in 5.78.
-
@stephenw10 Glad to know this should be resolved shortly, also facing the same concern here had to downgrade back to
25.11.1for now from26.03
Privacy Policy · Cookie Policy