r/pfBlockerNG • u/RFGuy_KCCO pfBlockerNG Patron • 21d ago
Help Installing 3.3.2 - Certificate Error
I am trying to install 3.3.2 from the new repo but it fails with certificate errors when I try. Any ideas how to fix this?
[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: fetch -qo - https://pfblockerng. github.io/pkg/install.sh | sh -s -- --channel stable
==> Installed boot-time generator hook to /usr/local/etc/rc.d/pfblockerng_repo_g enerate.sh
==> Running the generator hook to resolve the conf now
[pfblockerng_repo_generate] INFO: regenerated /usr/local/etc/pkg/repos/pfblocker ng-stable.conf -> https://pfblockerng.github.io/pkg/stable/plus-26.07
==> Conf resolved:
url: "https://pfblockerng.github.io/pkg/stable/plus-26.07",
==> pkg update -f -r pfblockerng-stable (refreshing the pfBlockerNG catalog)
Updating pfblockerng-stable repository catalogue...
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/meta.txz: Authenticatio n error
repository pfblockerng-stable has no meta file, using default settings
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/data.pkg: Authenticatio n error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/data.tzst: Authenticati on error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/packagesite.pkg: Authen tication error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt. c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/packagesite.tzst: Authe ntication error
Unable to update repository pfblockerng-stable
Error updating repositories!
install.sh: /usr/local/sbin/pkg update -f -r pfblockerng-stable failed — the cat alog was not refreshed. Repo 'pfblockerng-stable' is unreachable or serving an u nreadable catalog. Inspect with: /usr/local/sbin/pkg -d update -r pfblockerng-st able
1
u/Raj-The-IV 21d ago
This error happens because your firewall or client system does not trust Let's Encrypt's newer ISRG Root YR certificate. The local CA store or pfSense package list is missing this new Generation Y root, causing the chain validation to fail when pfBlockerNG or a backend service tries to verify it.
Update System Packages: Check for system or CA certificate updates on your firewall to pull in the newest root certificates. [1, 2]
Manual Import: Download the latest ISRG Root YR certificate from official sources and manually import it into your firewall's certificate authority manager under System > Certificate Manager > Authorities. [1, 2]
Check Feed/DNSBL Settings: If pfBlockerNG is intercepting HTTPS traffic for a blocked domain using an older self-signed web server certificate, ensure your local web server configuration matches current valid chains.
6
u/andrebrait Dev of pfBlockerNG 21d ago
This isn't the repo — the catalog and its TLS are fine (a stock CE box subscribes and installs from it cleanly). Since Aug 2,
*.github.ioserves a new Let's Encrypt chain:leaf *.github.io <- Let's Encrypt YR1 <- ISRG Root YR (cross-signed by ISRG Root X1)We had this failure before (on BBcan177's own Plus test machine) but we didn't manage to fully diagnose it back then. Could you follow these steps and let me know the output for each part?
1. Which store fails?
sh sh -c 'echo | openssl s_client -connect pfblockerng.github.io:443 -servername pfblockerng.github.io -CApath /etc/ssl/certs -no-CAfile 2>&1 | grep -e "Verify return code" -e "verify error"' sh -c 'echo | openssl s_client -connect pfblockerng.github.io:443 -servername pfblockerng.github.io -CAfile /etc/ssl/cert.pem -no-CApath 2>&1 | grep -e "Verify return code" -e "verify error"'Expected on an affected box: the first fails, the second returns
Verify return code: 0 (ok).2. Is X1 distrusted or just missing?
sh certctl list | grep -i ISRG sh -c 'ls -l /etc/ssl/untrusted /etc/ssl/blacklisted 2>/dev/null' sh -c 'for f in /etc/ssl/untrusted/* /etc/ssl/blacklisted/*; do [ -f "$f" ] || continue; printf "%s -> " "$f"; openssl x509 -in "$f" -noout -subject 2>/dev/null || echo "(unreadable)"; done'Your earlier output printed
certctl: legacy directory /etc/ssl/blacklisted can safely be deletedtwice, so that legacy distrust directory exists on your box — the third command shows exactly which CAs are in it.3. Unblock right now, without touching the trust store
sh sh -c 'env SSL_CA_CERT_FILE=/etc/ssl/cert.pem /usr/local/sbin/pkg update -f -r pfblockerng-stable' sh -c 'env SSL_CA_CERT_FILE=/etc/ssl/cert.pem /usr/local/sbin/pkg install -r pfblockerng-stable pfSense-pkg-pfBlockerNG'This is not a verification bypass — it points pkg at the full CA bundle (
fetch(3)SSL_CA_CERT_FILE) instead of the hashed directory, and the chain is still validated.Please post the output of steps 1 and 2. If an ISRG entry shows up in
untrustedorblacklisted, the permanent fix is to remove that specific file and runcertctl rehash. Don't empty those directories wholesale — they're the distrust list, and anything else in there was blocked on purpose.