Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    pFsense+ Update issues

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    17 Posts 7 Posters 1.1k Views 7 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      CRowmAN
      last edited by

      Hi, I hope you can help,

      I have been using PFSense for several years on the same computer without too many issues. Originally I installed the CE Edition then upgraded to PFSense+.

      I had upgraded back around March from 25.11.1 to 26.03.1

      Yesterday I was configuring a wireguard VPN interface, Its the first changes I have made to my pfsense in some time.

      Today, I started getting these notifications.

      check_upgrade: "Updating repositories metadata" returned error code 1 @ 2026-08-12 10:20:55
      check_upgrade: "Updating repositories metadata" returned error code 1 @ 2026-08-12 10:21:54
      check_upgrade: "Updating repositories metadata" returned error code 1 @ 2026-08-12 10:22:39
      check_upgrade: "Updating repositories metadata" returned error code 1 @ 2026-08-12 10:22:50
      pkg: "Fetching drm package" returned error code 1 @ 2026-08-12 10:23:12

      when I goto the system update it appears my licence is no longer working as I see this message.

      MessagesYour TAC Subscription expired on 2023-11-17. Please renew your TAC Subscription or purchase a pfSense+ subscription by visiting the Netgate store.

      I have tried rolling back the config changes and tried restoring back to 25.11.1 but it has not helped.

      How can I fix this TAC message and get my pfsense back up to date ?

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        What does pfSense-repoc -ND show? You can remove the NDI from that. Or send me the output in chat.

        C 1 Reply Last reply Reply Quote 0
        • C Offline
          CRowmAN @stephenw10
          last edited by

          @stephenw10 Thankyou for your help, I Sent it in Chat as requested

          1 Reply Last reply Reply Quote 1
          • T Offline
            tantu07
            last edited by tantu07

            Seeing same issue. Trying to update from 26.03 to 26.03.1 but the updater wont let me update. Also getting the same error message for TAC subscription ended.

            b42121ce-8f4c-4bf5-9218-298fc5caad07-image.png

            04aac8fc-a976-4e65-b9ea-a3ba943d4a0d-image.png

            1 Reply Last reply Reply Quote 0
            • patient0P patient0 referenced this topic
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              If that device was upgraded to Plus on a Home/Lab license it's a temporary issue on the backend. It should be fixed later today.

              T 1 Reply Last reply Reply Quote 0
              • T Offline
                tantu07 @stephenw10
                last edited by

                @stephenw10 Yes, this device was updated to plus on a home/lab license. Thank you

                1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  Then you should be good when we deploy the fix later. It will pull a new client cert and see the upgrade again. Nothing you need to do.

                  1 Reply Last reply Reply Quote 0
                  • T techpro2004 referenced this topic
                  • T Offline
                    techpro2004
                    last edited by

                    My router did not pull the new cert. How do I manually do it. thanks.

                    N 1 Reply Last reply Reply Quote 0
                    • N Offline
                      netblues @techpro2004
                      last edited by

                      @techpro2004 Patience is a gift.

                      1 Reply Last reply Reply Quote 0
                      • Bob.DigB Offline
                        Bob.Dig LAYER 8
                        last edited by

                        I was upgrading to Release today but had problems afterwards. None of my Port Forwards with pass worked anymore, they were broken and unfixable. But all of this happened in a Hyper-V VM and while I made the upgrade, I also run a Veeam Backup on the host at the same time. So I guess, that was a very bad idea. I restored from an earlier Veeam Backup and now I am waiting to try it again. ๐Ÿ˜‰

                        pfSense-repoc: zuul_repo_fetch: Failed to read the repository data (1). pfSense-repoc: server returned error response: 400 Bad Request

                        stephenw10S 1 Reply Last reply Reply Quote 0
                        • C Offline
                          CRowmAN
                          last edited by

                          now resolved,mine has pulled the new cert, Thankyou

                          1 Reply Last reply Reply Quote 1
                          • stephenw10S Offline
                            stephenw10 Netgate Administrator @Bob.Dig
                            last edited by

                            @Bob.Dig said in pFsense+ Update issues:

                            None of my Port Forwards with pass worked anymore,

                            You should open a new topic for that. It will be lost here in the license issue posts.

                            Bob.DigB 1 Reply Last reply Reply Quote 0
                            • Bob.DigB Offline
                              Bob.Dig LAYER 8 @stephenw10
                              last edited by

                              @stephenw10 said in pFsense+ Update issues:

                              You should open a new topic for that.

                              I will not unless I tried it a second time to upgrade, then without doing a veeam backup at the same time. This machine already was on latest RC showing no problems, so I bet, there is none.

                              1 Reply Last reply Reply Quote 1
                              • O Offline
                                OliB
                                last edited by

                                Fresh 26.07-RELEASE install (Proxmox/QEMU VM) โ€” license/registration backend unreachable

                                Hitting the same failure across three different paths, all pointing to the same backend:

                                1. pfSense-repoc -NZ:

                                pfSense-repoc: zuul_license_check: Failed to check the license (1).
                                pfSense-repoc: failed to contact server: Post "https://services.netgate.com/api/license/check": context deadline exceeded

                                1. pkg install against pfSense-core/pfSense repos:

                                pkg: https://update01.atx.netgate.com/pfSense_plus-v26_07_amd64-core/meta.txz: Bad Request

                                1. System > Register:

                                The registration system is not currently available. Please check your network connection and try again.

                                Ruled out network/local causes before posting:

                                DNS resolves cleanly, full 1500-byte packets pass with 0% loss (~100ms RTT), no PMTU issue

                                curl -v to services.netgate.com completes instantly โ€” clean TLS, and manually replaying the exact same license-check POST body gets an immediate 400 invalid license phrase response. So the server is reachable and responsive; it's specifically rejecting this request.

                                truss -f on pfSense-repoc -NZ shows it stuck in a tight loop of repeated poll() calls with no read(), right up until timeout โ€” looks like a client-side stall, not a network timeout, despite the "context deadline exceeded" message.

                                The device's client cert (pfSense-repo-0000-cert.pem) has a one-hour validity window (notBefore=Aug 26 15:33 2026 GMT, notAfter=Aug 26 16:33 2026 GMT) and has been expired for several days, since the license check has never successfully completed to refresh it.

                                Given the other thread about backend licensing issues for Plus devices โ€” is this the same root cause? Happy to share the full truss log or NDI in chat.

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S Offline
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  @OliB said in pFsense+ Update issues:

                                  context deadline exceeded

                                  That's an unrelated error. We have seen that one time internally, also on a VM.

                                  How many CPU cores on that VM? The system we hit this on had a single CPU core and increasing that to two prevented the error. If you're able to test that it would be a very interesting result.

                                  What repoc version do you have? (pfSense-repoc -v)

                                  O 1 Reply Last reply Reply Quote 0
                                  • O Offline
                                    OliB @stephenw10
                                    last edited by

                                    @stephenw10

                                    pfSense-repoc version: 0.41
                                    gnid version: 0.21

                                    Currently running on Proxmox 9.2.3/2 vCPU/12GB RAM/50GB SSD - have increased to 4vCPU for now and will test tomorrow. Mostly running offline but can connect to internet for updates when needed.

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S Offline
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Ah, this issue has been fixed in 0.42 which is now available. Run pkg upgrade at the CLI to upgrade it.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                      Privacy Policy · Cookie Policy