Updated acme to 1.3.2 and pfBlockerNG to 3.2.8_1 while still in version 2.8.1
-
Good day. Can I safely update from 2.8.1 to 2.9.0 if I have already updated acme to 1.3.2 and pfBlockerNG to 3.2.8_1? Last week the dashboard showed update to 2.9.0beta is available but I did not apply because it's beta. Shortly after, I saw in System > "Package Manager" that acme and pfBlockerNG updates are available. I updated the packages and then I noticed later in the dashboard showing update to 2.9.0 production is available. I should have realized that the 2.9.0beta will shortly be 2.9.0 production, and that the acme and pfblockerNG package updates are probably for the upcoming 2.9.0. Will there be update issue if I update to 2.9.0, or should I first uninstall the acme and pfBlockerNG packages before updating to 2.9.0?
Additional questions in case the answer is I need to uninstall the packages first before updating to 2.9.0:
Additional question 1.) Will this mean that if I uninstall acme, then update to 2.9.0, then re-install acme, then I need to manually type-in all the acme changes under "Account Keys" and "Certificates" menu? I can't find a "Keep Settings" for acme:



Additional question 2.) Do I understand correctly that the "Keep Settings" checkbox will allow me to uninstall pfBlockerNG, then update to 2.9.0, then re-install pfblockerNG and all my previous pfBlockerNG settings will be restored automatically?

-
@richardsago to what was your update branch set when you upgraded the packages?
Most packages will leave their settings upon uninstall. A few have an option to remove them. (Uncheck “keep”)
-
Thank you @SteveITS for the reply. Not sure where to get that information but I hope one of these screenshots has the information needed:

This is the System > Update page:


-
@richardsago said in Updated acme to 1.3.2 and pfBlockerNG to 3.2.8_1 while still in version 2.8.1:
Good day. Can I safely update from ...
Don't do that.
The latest pfSense packages are always build against the latest pfSense version.
Example : look at acme.sh :
it pulls in also the latest PHP version.
Check that version against the version you use now : quick and dirty way to discover that :Diagnostics > Command Prompt :

But the rest of pfSense itself, and other packages (FreeBSD or 'pfSense') are (can be) based on a previous version.
That's a situation like using Windows 10 and pulling in Windows 11 programs.You are of course allowed to stay on 2.8.1. Whatever your reason are, they are your reasons.
But a rule applies : you 'freeze' what you have, and you become the expert (support) on your version, as the rest of us is already further ahead. Most people deal with 2.9.0 issues if any, and tend to forget 2.8.1 related stuff. Btw : the forum has a lot of 2.8.1 questions and answers.Conclusion : If you decide to update the packages anyway, please backup and have a plan B ready. I prefer that I'm wrong about what I've said above, and all goes well for you.
@richardsago said in Updated acme to 1.3.2 and pfBlockerNG to 3.2.8_1 while still in version 2.8.1:
Additional questions in case the answer is I need to uninstall the packages first before updating to 2.9.0:
That is advised.
pfSense has a manual, you can trust it, do what's written there, you shouldn't even use my words here, use what Netgate wrote about the product.
The main topic Upgrade Guide
For you : read this one : Pre-Upgrade Tasks -
Thank you @Gertjan for the reply. I was not even thinking of updating pfsense when I updated acme and pfblockerNG. At that time I was a bit paranoid looking for explanation about a captive portal error messages. When I saw that there was available update for acme and pfblockerNG I thought that will solve the captive portal error messages. When I later saw the new pfsense version was available was when I realized I should not have updated acme and pfblockerNG. I tried to look for how to reverse the updates but there does not seem to be a way to do that. Without a backup (which I should have made but foolishly did not) is there a way to reverse the updates to acme and pfblockerNG?
-
@richardsago said in Updated acme to 1.3.2 and pfBlockerNG to 3.2.8_1 while still in version 2.8.1:
When I saw that there was available update for acme and pfblockerNG I thought that will solve the captive portal error messages
I use all 3 of them.
acme.sh and pfBlockerng don't impact the captive portal.
The captive portal doesn't need acme.sh, neither pfBlockerng.acmes.sh is useful for the captive portal, as you could use it to create a "portal.mycompany.tld" certificate, and use that certificate with the captive portal.
You can also get your certificate from elsewhere, but that will need a manual operation from you each xxx days, just before your certificate expires.I use pfBlockerng for my portal with a minimal DNSBL list that lists world's worst web sites.
On one side, I shouldn't do this, as :
Who am I to decide what you (the hotel client, mostly adult persons) can access with your device connected to my portal (internet access) ? Me, my role, as a captive portal supplier for a hotel, I supply an access. I'm not going the check what you do with it. I'm not logging (the paces visited) neither.
On the other hand, we all know without knowing what will happen if a person using my captive portal tries to access and use the nukes launch access codes. Black helicopters will swirl above my head, and I will sleep in another "hotel" the very same day. As it is me, the subscriber, who is responsible for what has be done with my connection, not the who ever uses the connection (these two can be the same person).Let me touch wood, I never had an issue with my portal.
Most Internet users already know that they should VPN if they do things on the Internet that can create 'unhappy persons or entities'. they do this to protect themselves, not me.So all is well, there is a balance.
edit :
@richardsago said in Updated acme to 1.3.2 and pfBlockerNG to 3.2.8_1 while still in version 2.8.1:
I tried to look for how to reverse the updates but there does not seem to be a way to do that
See it like this : If a multi trillion company like Microsoft, with thousans of programmes and many (like a lot) of users doesn't really support downgrading updates, a smaller company like Netgate with 5 (just inventing a number) programmers won't even start thinking about it.
That said, check the /var/cache/pkg/ folder. The folder is what it implies.
So you might have the older package.
So, if the GUI doesn't know how to deal with 'pkg' (package) file, you, you are the admin, the god of the keyboard, the one with the ultimate control, the one that spoon-feeds all AI with dust.
I'm pretty sure that with the command line you can install a package already downloaded.As always, don't believe what is written here, what I'm saying. You don't need to. You already know. And if you don't, how so ?? ^^
My own common sense pfSense upgrade and pfSense package upgrade rules :
- You take notice of the arrival of a new version of a package or pfSense.
- You wait.
- You start visiting the forum redit facebook, an orcale, whatever.
- Starting reading about the newest upgrade, as they are very often announced, and issues are always written about. People rarely post if all goes well ^^
- Apply the extension of Murphy's law : the one from Mickey, his brother. He will go fist (upgrading the package). If it fails, Mickey will post on this fourm, and by preference, if it's a pfBlockerng issue, he'll post in the Home > pfSense
Software > Routing and Multi WAN forum or some other random place (it's still unknown why Mickey pick this place, let me get back on that). - Let the dust settle, read about work a-rounds, or a gotcha-type of solution.
- Now you are ready to upgrade, using the guides I posted above.
Btw : I use the latest pfSense version and all the latest packages.
No issues for me, but be aware, as I use acme.sh and pfBolckerng probably with different settings as you. -
Thank you @Gertjan for the reply. I admit I don't know how to reverse my recent acme and pfblockerNG updates. Is there a webpage that lists the steps I need to do? I can't find this in the Netgate Docs.
-
Update to 2.9.0 and done

-
@richardsago you’re set to 2.8.1 so you’re fine. Older versions of pfSense defaulted to “current” which changed over time when a new version was released.
-
-
Yes, there's no problem here. Those packages were pulled back into 2.8.1 to provide fixes there which is why they showed up for you whilst you still had the upgrade branch set to 2.8.1.
-
Thank you @stephenw10 for the information and reassurance.
-
@richardsago said in Updated acme to 1.3.2 and pfBlockerNG to 3.2.8_1 while still in version 2.8.1:
vmware
What is that ?
-
Hi @Gertjan our pfsense is installed inside a virtual machine software named vmware.
-
@richardsago
Oh ....
Then you can : snapshot the install.
Clone it.
Boot in the clone.
Upgrade the clone and test drive.
If all goes well, keep the now '2.9.0' clone as your new 'current'.
Not ? Boot back in the original, back into 2.8.1.
And all this with the speed of a click ... -
Hi @Gertjan yes that will be my steps when updating to 2.9.0. I came to the forum because I was worried that the update will fail because I had updated acme and pfblockerNG earlier, when I was not thinking straight during a captive portal error message I did not even make a snapshot before updating acme and pfblockerNG. Lessons learned :(
Privacy Policy · Cookie Policy