Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    502 Bad Gateway (nginx) after Update to 2.3

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    93 Posts 44 Posters 59.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      BeerCan
      last edited by

      will not fetch that one either.  This is weird

      1 Reply Last reply Reply Quote 0
      • L
        lordalfa
        last edited by

        BeerCan, can you get into https://github.com

        If your browser gives you an error, you will have problems downloading. It is something to do with HSTS.

        1 Reply Last reply Reply Quote 0
        • B
          BeerCan
          last edited by

          @lordalfa:

          BeerCan, can you get into https://github.com

          If your browser gives you an error, you will have problems downloading. It is something to do with HSTS.

          I can't get in with FF or chrome

          1 Reply Last reply Reply Quote 0
          • ?
            Guest
            last edited by

            Even stranger… :)

            I think this is one for the Netgate developers to answer, as they maintain it.

            1 Reply Last reply Reply Quote 0
            • P
              PiBa
              last edited by

              I don t think netgate maintains the github.com certificates.
              It sounds to me like like a invasive proxy with ssl bump.

              Edit:
              Or perhaps pfBlocker dnsblock list that redirects to a pfSense hosted site for tracking blocking statistics..

              1 Reply Last reply Reply Quote 0
              • ?
                Guest
                last edited by

                It works fine for me though, and others apparently, it's only BeerCan who is having an issue I think.

                PiBa, can you try and fetch the patch, see if it's working for you?

                To be honest, I only have to click on the link I posted yesterday and I can see the patch.

                I did not think that netgate maintains the Github certs, just the pfsense repository, it's just that maybe they may have an idea what's causing the issue.

                I've just checked Github's cert and it reports it as OK on my system.

                1 Reply Last reply Reply Quote 0
                • P
                  PiBa
                  last edited by

                  Fetch patch works fine, both the link in a browser and the 2c131b1 id in patches package.

                  So a proxy like squid with ssl bump or dns-intercept (DNSBL pfBlockerNG) are the likely causes imho.

                  1 Reply Last reply Reply Quote 0
                  • ?
                    Guest
                    last edited by

                    @PiBa:

                    Fetch patch works fine, both the link in a browser and the 2c131b1 id in patches package.

                    So a proxy like squid with ssl bump or dns-intercept (DNSBL pfBlockerNG) are the likely causes imho.

                    Thank you sir. I think you are correct on the likely cause.

                    1 Reply Last reply Reply Quote 0
                    • B
                      BeerCan
                      last edited by

                      So I turned unbound off and went back to dnsmasq and github worked.  So I went back and turned unbound back on and no github.

                      So I ran this cmd

                      that looks like my pfblocker address.  Problem is pfblocker has been off during all this

                      1 Reply Last reply Reply Quote 0
                      • P
                        PiBa
                        last edited by

                        Are you sure the "Enable DNSBL" box is also disabled? (not only the "Enable pfBlockerNG")

                        1 Reply Last reply Reply Quote 0
                        • B
                          BeerCan
                          last edited by

                          @PiBa:

                          Are you sure the "Enable DNSBL" box is also disabled? (not only the "Enable pfBlockerNG")

                          OK I went through all of the feeds and it is dansguardian that is blocking the patch system (I xx out my uid) 
                          https://lists.malwarepatrol.net/cgi/getfile?receipt=xxxxxxxxxxx&product=8&list=dansguardian

                          found this blocks it as well  https://malc0de.com/bl/BOOT

                          Do others have this enabled and are able to attach to the patch system?

                          1 Reply Last reply Reply Quote 0
                          • O
                            Olman
                            last edited by

                            2.4.2; haproxy ; cluster

                            main - patch installed from this thread ; backup -not installed ;
                            bot are behave, with patch seems a bit better (but I'm not sure), but actively using web management,  cause a problem, an early evidence, it cant sync HA config, starting throwing sync errors , then everything collapsed ….

                            so far my understanding since my use of pfsense version 1 ( 2009 i think) , any add-on installed , caused a potential instability ... you may get lucky it works well, or it may hang after a couple month of usage ....

                            so far are great product , but adding some add-on .... think twice ....  that sad ...

                            1 Reply Last reply Reply Quote 0
                            • S
                              serlogo53
                              last edited by

                              also i have problem in 2.4.2-RELEASE (amd64). patch not working. also i tried do it by manual lines was different. is anybody have this problem in 2.4.2?

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.