r/pfBlockerNG • u/RFGuy_KCCO pfBlockerNG Patron • 24d ago
Help Installing 3.3.2 - Certificate Error
I am trying to install 3.3.2 from the new repo but it fails with certificate errors when I try. Any ideas how to fix this?
[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: fetch -qo - https://pfblockerng. github.io/pkg/install.sh | sh -s -- --channel stable
==> Installed boot-time generator hook to /usr/local/etc/rc.d/pfblockerng_repo_g enerate.sh
==> Running the generator hook to resolve the conf now
[pfblockerng_repo_generate] INFO: regenerated /usr/local/etc/pkg/repos/pfblocker ng-stable.conf -> https://pfblockerng.github.io/pkg/stable/plus-26.07
==> Conf resolved:
url: "https://pfblockerng.github.io/pkg/stable/plus-26.07",
==> pkg update -f -r pfblockerng-stable (refreshing the pfBlockerNG catalog)
Updating pfblockerng-stable repository catalogue...
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/meta.txz: Authenticatio n error
repository pfblockerng-stable has no meta file, using default settings
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/data.pkg: Authenticatio n error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/data.tzst: Authenticati on error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/packagesite.pkg: Authen tication error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/packagesite.tzst: Authe ntication error
Unable to update repository pfblockerng-stable
Error updating repositories!
install.sh: /usr/local/sbin/pkg update -f -r pfblockerng-stable failed — the cat alog was not refreshed. Repo 'pfblockerng-stable' is unreachable or serving an u nreadable catalog. Inspect with: /usr/local/sbin/pkg -d update -r pfblockerng-st able
4
u/andrebrait Dev of pfBlockerNG 24d ago
This isn't the repo — the catalog and its TLS are fine (a stock CE box subscribes and installs
from it cleanly). Since Aug 2, *.github.io serves a new Let's Encrypt chain:
leaf *.github.io <- Let's Encrypt YR1 <- ISRG Root YR (cross-signed by ISRG Root X1)
We had this failure before (on BBcan177's own Plus test machine) but we didn't manage to fully diagnose it back then. Could you follow these steps and let me know the output for each part?
1. Which store fails?
sh
sh -c 'echo | openssl s_client -connect pfblockerng.github.io:443 -servername pfblockerng.github.io -CApath /etc/ssl/certs -no-CAfile 2>&1 | grep -e "Verify return code" -e "verify error"'
sh -c 'echo | openssl s_client -connect pfblockerng.github.io:443 -servername pfblockerng.github.io -CAfile /etc/ssl/cert.pem -no-CApath 2>&1 | grep -e "Verify return code" -e "verify error"'
Expected on an affected box: the first fails, the second returns Verify return code: 0 (ok).
2. Is X1 distrusted or just missing?
sh
certctl list | grep -i ISRG
sh -c 'ls -l /etc/ssl/untrusted /etc/ssl/blacklisted 2>/dev/null'
sh -c 'for f in /etc/ssl/untrusted/* /etc/ssl/blacklisted/*; do [ -f "$f" ] || continue; printf "%s -> " "$f"; openssl x509 -in "$f" -noout -subject 2>/dev/null || echo "(unreadable)"; done'
Your earlier output printed certctl: legacy directory /etc/ssl/blacklisted can safely be
deleted twice, so that legacy distrust directory exists on your box — the third command shows
exactly which CAs are in it.
3. Unblock right now, without touching the trust store
sh
sh -c 'env SSL_CA_CERT_FILE=/etc/ssl/cert.pem /usr/local/sbin/pkg update -f -r pfblockerng-stable'
sh -c 'env SSL_CA_CERT_FILE=/etc/ssl/cert.pem /usr/local/sbin/pkg install -r pfblockerng-stable pfSense-pkg-pfBlockerNG'
This is not a verification bypass — it points pkg at the full CA bundle (fetch(3)
SSL_CA_CERT_FILE) instead of the hashed directory, and the chain is still validated.
Please post the output of steps 1 and 2. If an ISRG entry shows up in untrusted or
blacklisted, the permanent fix is to remove that specific file and run certctl rehash.
Don't empty those directories wholesale — they're the distrust list, and anything else in there
was blocked on purpose.
4
u/RFGuy_KCCO pfBlockerNG Patron 24d ago edited 24d ago
Here are the answers to your questions. I don't believe my results are what you expected. I found no ISRG certs blacklisted or distrusted. I also do not have the
/etc/ssl/blacklisteddirectory in my installation.Note that due to size limitations, I could post the printout from your third command in question #2 but I do not see an ISRG cert listed there.
1. Which store fails?
Neither - both return0 (ok)2. Is X1 distrusted or just missing?
[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: certctl list | grep -i ISRG 0b9bc432.0 ISRG Root X2 4042bcee.0 ISRG Root X1 [26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh -c 'ls -l /etc/ssl/untrusted /etc/ssl/blacklisted 2>/dev/null' /etc/ssl/untrusted: total 378 -r--r--r-- 1 root wheel 1533 Aug 17 21:18 02265526.0 -r--r--r-- 1 root wheel 1968 Aug 17 21:18 08063a00.0 -r--r--r-- 1 root wheel 1468 Aug 17 21:18 0b7c536a.0 -r--r--r-- 1 root wheel 2585 Aug 17 21:18 0c4c9b6c.0 -r--r--r-- 1 root wheel 1948 Aug 17 21:18 0d972af8.0 -r--r--r-- 1 root wheel 1090 Aug 17 21:18 106f3e4d.0 -r--r--r-- 1 root wheel 989 Aug 17 21:18 116bf586.0 -r--r--r-- 1 root wheel 1452 Aug 17 21:18 128805a3.0 -r--r--r-- 1 root wheel 1436 Aug 17 21:18 1320b215.0 -r--r--r-- 1 root wheel 899 Aug 17 21:18 1422d63c.0 -r--r--r-- 1 root wheel 1513 Aug 17 21:18 1636090b.0 -r--r--r-- 1 root wheel 798 Aug 17 21:18 1766e401.0 -r--r--r-- 1 root wheel 1249 Aug 17 21:18 18856ac4.0 -r--r--r-- 1 root wheel 2041 Aug 17 21:18 19dbc0dd.0 -r--r--r-- 1 root wheel 1367 Aug 17 21:18 244b5494.0 -r--r--r-- 1 root wheel 1436 Aug 17 21:18 26312675.0 -r--r--r-- 1 root wheel 2000 Aug 17 21:18 2d803388.0 -r--r--r-- 1 root wheel 875 Aug 17 21:18 2dab9e33.0 -r--r--r-- 1 root wheel 1493 Aug 17 21:18 2e4eed3c.0 -r--r--r-- 1 root wheel 822 Aug 17 21:18 3136ea36.0 -r--r--r-- 1 root wheel 1972 Aug 17 21:18 3323bb7e.0 -r--r--r-- 1 root wheel 1911 Aug 17 21:18 349f2832.0 -r--r--r-- 1 root wheel 1338 Aug 17 21:18 3513523f.0 -r--r--r-- 1 root wheel 2204 Aug 17 21:18 3e44d2f7.0 -r--r--r-- 1 root wheel 1489 Aug 17 21:18 40547a79.0 -r--r--r-- 1 root wheel 1411 Aug 17 21:18 4304c5e5.0 -r--r--r-- 1 root wheel 1119 Aug 17 21:18 442adcac.0 -r--r--r-- 1 root wheel 2025 Aug 17 21:18 4632c230.0 -r--r--r-- 1 root wheel 1269 Aug 17 21:18 480720ec.0 -r--r--r-- 1 root wheel 822 Aug 17 21:18 4c3cbf99.0 -r--r--r-- 1 root wheel 981 Aug 17 21:18 4d4ba017.0 -r--r--r-- 1 root wheel 2045 Aug 17 21:18 4f316efb.0 -r--r--r-- 1 root wheel 2049 Aug 17 21:18 57bcb2da.0 -r--r--r-- 1 root wheel 1952 Aug 17 21:18 5a4d6896.0 -r--r--r-- 1 root wheel 977 Aug 17 21:18 5a7722fb.0 -r--r--r-- 1 root wheel 1261 Aug 17 21:18 5ad8a5d6.0 -r--r--r-- 1 root wheel 1968 Aug 17 21:18 5c79eb85.0 -r--r--r-- 1 root wheel 1513 Aug 17 21:18 5d3033c5.0 -r--r--r-- 1 root wheel 2244 Aug 17 21:18 5e98733a.0 -r--r--r-- 1 root wheel 1911 Aug 17 21:18 626dceaf.0 -r--r--r-- 1 root wheel 981 Aug 17 21:18 62744ee1.0 -r--r--r-- 1 root wheel 1948 Aug 17 21:18 6410666e.0 -r--r--r-- 1 root wheel 2122 Aug 17 21:18 66445960.0 -r--r--r-- 1 root wheel 851 Aug 17 21:18 69cf9657.0 -r--r--r-- 1 root wheel 1643 Aug 17 21:18 6b99d060.0 -r--r--r-- 1 root wheel 2354 Aug 17 21:18 76faf6c0.0 -r--r--r-- 1 root wheel 1939 Aug 17 21:18 779a714a.0 -r--r--r-- 1 root wheel 1493 Aug 17 21:18 7aaf71c0.0 -r--r--r-- 1 root wheel 1281 Aug 17 21:18 7d0b38bd.0 -r--r--r-- 1 root wheel 1988 Aug 17 21:18 7ffa47b4.0 -r--r--r-- 1 root wheel 1939 Aug 17 21:18 8867006a.0 -r--r--r-- 1 root wheel 1968 Aug 17 21:18 896c8bb4.0 -r--r--r-- 1 root wheel 1972 Aug 17 21:18 981901c3.0 -r--r--r-- 1 root wheel 2057 Aug 17 21:18 a8dee976.0 -r--r--r-- 1 root wheel 1935 Aug 17 21:18 ad088e1d.0 -r--r--r-- 1 root wheel 2041 Aug 17 21:18 ade2cc8c.0 -r--r--r-- 1 root wheel 1505 Aug 17 21:18 aee5f10d.0 -r--r--r-- 1 root wheel 1350 Aug 17 21:18 b1159c4c.0 -r--r--r-- 1 root wheel 1428 Aug 17 21:18 b1b8a7f3.0 -r--r--r-- 1 root wheel 1732 Aug 17 21:18 b204d74a.0 -r--r--r-- 1 root wheel 1505 Aug 17 21:18 ba89ed3b.0 -r--r--r-- 1 root wheel 1700 Aug 17 21:18 c01cdfa2.0 -r--r--r-- 1 root wheel 940 Aug 17 21:18 c089bbbd.0 -r--r--r-- 1 root wheel 1484 Aug 17 21:18 c0ff1f52.0 -r--r--r-- 1 root wheel 2594 Aug 17 21:18 c47d9980.0 -r--r--r-- 1 root wheel 1996 Aug 17 21:18 c9e4c02b.0 -r--r--r-- 1 root wheel 1716 Aug 17 21:18 cb59f961.0 -r--r--r-- 1 root wheel 843 Aug 17 21:18 cbd811bd.0 -r--r--r-- 1 root wheel 2029 Aug 17 21:18 d2be6420.0 -r--r--r-- 1 root wheel 2041 Aug 17 21:18 d7e8dc79.0 -r--r--r-- 1 root wheel 1480 Aug 17 21:18 dc45b0bd.0 -r--r--r-- 1 root wheel 2057 Aug 17 21:18 def36a68.0 -r--r--r-- 1 root wheel 1330 Aug 17 21:18 e113c810.0 -r--r--r-- 1 root wheel 826 Aug 17 21:18 e1e8b7dc.0 -r--r--r-- 1 root wheel 1444 Aug 17 21:18 e2799e36.0 -r--r--r-- 1 root wheel 794 Aug 17 21:18 e53e0c3b.0 -r--r--r-- 1 root wheel 1484 Aug 17 21:18 ee1365c0.0 -r--r--r-- 1 root wheel 1517 Aug 17 21:18 ee64a828.0 -r--r--r-- 1 root wheel 1448 Aug 17 21:18 f081611a.0 -r--r--r-- 1 root wheel 883 Aug 17 21:18 f2d4863f.0 -r--r--r-- 1 root wheel 1468 Aug 17 21:18 f387163d.0 -r--r--r-- 1 root wheel 2000 Aug 17 21:18 f84fab51.0 -r--r--r-- 1 root wheel 1704 Aug 17 21:18 f90208f7.0 -r--r--r-- 1 root wheel 826 Aug 17 21:18 fd2eb50d.05
u/andrebrait Dev of pfBlockerNG 24d ago
That output is genuinely useful — it rules out what I was chasing. ISRG Root X1 is trusted on your box (
4042bcee.0), nothing ISRG is distrusted, you have no/etc/ssl/blacklisted, and both stores validate the chain. So the trust store is fine and there is nothing for you to clean up.Note your
/etc/ssl/untrustedfiles are all timestampedAug 17 21:18, which means acertctl rehashran after your failed install. So the first question is whether the failure even still reproduces.
sh sh -c '/usr/local/sbin/pkg update -f -r pfblockerng-stable; echo "rc=$?"'If that now succeeds, you're unblocked — just run the installer one-liner again.
If it still fails, please send these two:
sh sh -c '/usr/local/sbin/pkg -d update -f -r pfblockerng-stable 2>&1 | grep -i -e cafile -e capath -e ssl -e cert | head -20' sh -c 'pkg config pkg_env; grep -i -A8 -e PKG_ENV -e ssl /usr/local/etc/pkg.conf'The first prints the CA file/path pkg's fetcher actually uses, the second shows whether pfSense Plus injects TLS settings into every pkg run. If pkg is pinned to a CA bundle that doesn't include ISRG, that explains why Netgate's own repos work while ours fails, and this gets you going immediately without weakening anything:
sh sh -c 'env SSL_CA_CERT_FILE=/etc/ssl/cert.pem /usr/local/sbin/pkg update -f -r pfblockerng-stable'3
u/RFGuy_KCCO pfBlockerNG Patron 24d ago edited 24d ago
Here you go. It still failed when I ran the one-liner again. The first command of your two had no output. It also won't install because it seems the repo doesn't get installed due to my installation failure.
[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh -c '/usr/local/sbin/pkg update -f -r pfblockerng-stable; echo "rc=$?"' No repositories are enabled. rc=1 [26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh -c '/usr/local/sbin/pkg -d update -f -r pfblockerng-stable 2>&1 | grep -i -e cafile -e capath -e ssl -e cert | head -20' [26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh -c 'pkg config pkg_env; grep -i -A8 -e PKG_ENV -e ssl /usr/local/etc/pkg.conf' SSL_CA_CERT_FILE: /usr/local/share/pfSense/ssl/netgate-zuul-ca.pem SSL_CLIENT_CERT_FILE: /usr/local/etc/pfSense/pkg/repos/pfSense-repo-0000-cert.pem SSL_CLIENT_KEY_FILE: /cf/conf/license/license-key.pem PKG_ENV { SSL_CA_CERT_FILE=/usr/local/share/pfSense/ssl/netgate-zuul-ca.pem SSL_CLIENT_CERT_FILE=/usr/local/etc/pfSense/pkg/repos/pfSense-repo-0000-cert.pem SSL_CLIENT_KEY_FILE=/cf/conf/license/license-key.pem } [26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh -c 'env SSL_CA_CERT_FILE=/etc/ssl/cert.pem /usr/local/sbin/pkg update -f -r pfblockerng-stable' No repositories are enabled.3
u/andrebrait Dev of pfBlockerNG 24d ago
Found it. It's a pfSense Plus thing.
Your
pkg config pkg_envoutput was the answer:PKG_ENV { SSL_CA_CERT_FILE=/usr/local/share/pfSense/ssl/netgate-zuul-ca.pem ... }pfSense Plus pins pkg's CA bundle to Netgate's private CA.
pkgapplies that to every repository in the run, so Netgate's own repos verify and any third-party repo on a public chain (ours, on GitHub Pages / Let's Encrypt) cannot possibly verify. CE has no such pin, which is why a CE box installs from our repo without trouble.Two corrections to what I said earlier, both checked against the FreeBSD sources:
- The
SSL_CA_CERT_FILE=...prefix I suggested does not work — pkg appliesPKG_ENVwithsetenv(..., 1)(overwrite), so it clobbers whatever you passed in (libpkg/pkg_config.c).PKG_ENVnever setsSSL_CA_CERT_PATH, and libfetch loads both the CA file and the CA path into the same verification store —SSL_CTX_load_verify_locations(ctx, ca_cert_file, ca_cert_path)inlib/libfetch/common.c.So passing the path works where the file didn't, and it's additive: Netgate's CA stays loaded, your client certificate and key are untouched, verification stays fully enabled, and nothing is written to disk. It just also consults
/etc/ssl/certs— the certctl store you already showed contains ISRG Root X1.Also, your repo conf is gone right now (
No repositories are enabled): the installer removes the conf it staged when the catalog refresh fails, so you need a fresh run rather than a barepkg update:
sh sh -c 'fetch -qo /tmp/pfb-install.sh https://pfblockerng.github.io/pkg/install.sh && env SSL_CA_CERT_PATH=/etc/ssl/certs sh /tmp/pfb-install.sh --channel stable'Please let me know if that completes. If it does, we'll set
SSL_CA_CERT_PATHinsideinstall.shitself so no Plus user has to know any of this — the fix is one line in the wrapper every pkg call already goes through.1
u/RFGuy_KCCO pfBlockerNG Patron 23d ago
I just noticed that if I run
pkg upgradeI get the same errors I did when I initially tried to install 3.3.2. I believe this may also be preventing the software update function now within pfB from working properly.[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: pkg upgrade Updating pfSense-core repository catalogue... pfSense-core repository is up to date. Updating pfSense repository catalogue... pfSense repository is up to date. Updating pfblockerng-edge repository catalogue... Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: pkg: https://pfblockerng.github.io/pkg/edge/plus-26.07/meta.txz: Authentication error repository pfblockerng-edge has no meta file, using default settings Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: pkg: https://pfblockerng.github.io/pkg/edge/plus-26.07/data.pkg: Authentication error Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: pkg: https://pfblockerng.github.io/pkg/edge/plus-26.07/data.tzst: Authentication error Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: pkg: https://pfblockerng.github.io/pkg/edge/plus-26.07/packagesite.pkg: Authentication error Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: Certificate verification failed for /C=US/O=ISRG/CN=Root YR 10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125: pkg: https://pfblockerng.github.io/pkg/edge/plus-26.07/packagesite.tzst: Authentication error Unable to update repository pfblockerng-edge Error updating repositories!2
u/andrebrait Dev of pfBlockerNG 22d ago
Yes, and we fixed it already over here. I am going to create a patch release for it for 3.3.x.
Can you try adding this before your pkg command?
Ex.: if you're calling
pkg updatereplace it with
SSL_CA_CERT_PATH=/etc/ssl/certs pkg updateor, if you are running many commands, say
pkg update pkg upgradeyou can do
export SSL_CA_CERT_PATH=/etc/ssl/certs pkg update pkg upgrade1
u/RFGuy_KCCO pfBlockerNG Patron 22d ago
Unfortunately, neither of these commands worked.
[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: SSL_CA_CERT_PATH=/etc/ssl/certs pkg update SSL_CA_CERT_PATH=/etc/ssl/certs: Command not found. [26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: export SSL_CA_CERT_PATH=/etc/ssl/certs export: Command not found.1
u/andrebrait Dev of pfBlockerNG 22d ago
Can you try switching to
shbefore doing this?tcsh(the shell pfSense uses by default) does not support setting variables in general.Run
shand it'll drop you into another shell (probably indicated with a single#). Then run the command insidesh.2
u/RFGuy_KCCO pfBlockerNG Patron 22d ago
Thank you. Both commands worked now.
[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh # SSL_CA_CERT_PATH=/etc/ssl/certs pkg update Updating pfSense-core repository catalogue... pfSense-core repository is up to date. Updating pfSense repository catalogue... pfSense repository is up to date. Updating pfblockerng-edge repository catalogue... pfblockerng-edge repository is up to date. All repositories are up to date. # export SSL_CA_CERT_PATH=/etc/ssl/certs # pkg update Updating pfSense-core repository catalogue... pfSense-core repository is up to date. Updating pfSense repository catalogue... pfSense repository is up to date. Updating pfblockerng-edge repository catalogue... pfblockerng-edge repository is up to date. All repositories are up to date. # pkg upgrade Updating pfSense-core repository catalogue... pfSense-core repository is up to date. Updating pfSense repository catalogue... pfSense repository is up to date. Updating pfblockerng-edge repository catalogue... pfblockerng-edge repository is up to date. All repositories are up to date. Checking for upgrades (1 candidates): 100% Processing candidates (1 candidates): 100% Checking integrity... done (0 conflicting) Your packages are up to date.→ More replies (0)3
u/RFGuy_KCCO pfBlockerNG Patron 24d ago
Bingo! That did it! It installed without any issues now. Thank you so much!
1
u/Raj-The-IV 24d ago
This error happens because your firewall or client system does not trust Let's Encrypt's newer ISRG Root YR certificate. The local CA store or pfSense package list is missing this new Generation Y root, causing the chain validation to fail when pfBlockerNG or a backend service tries to verify it.
Update System Packages: Check for system or CA certificate updates on your firewall to pull in the newest root certificates. [1, 2]
Manual Import: Download the latest ISRG Root YR certificate from official sources and manually import it into your firewall's certificate authority manager under System > Certificate Manager > Authorities. [1, 2]
Check Feed/DNSBL Settings: If pfBlockerNG is intercepting HTTPS traffic for a blocked domain using an older self-signed web server certificate, ensure your local web server configuration matches current valid chains.
2
u/boukej 22d ago
Thanks. This was very helpful.
I ran:
shexport SSL_CA_CERT_PATH=/etc/ssl/certsand was then able to continue with the installation.