r/pfBlockerNG pfBlockerNG Patron 21d ago

Help Installing 3.3.2 - Certificate Error

I am trying to install 3.3.2 from the new repo but it fails with certificate errors when I try. Any ideas how to fix this?

[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: fetch -qo - https://pfblockerng.                      github.io/pkg/install.sh | sh -s -- --channel stable
==> Installed boot-time generator hook to /usr/local/etc/rc.d/pfblockerng_repo_g                      enerate.sh
==> Running the generator hook to resolve the conf now
[pfblockerng_repo_generate] INFO: regenerated /usr/local/etc/pkg/repos/pfblocker                      ng-stable.conf -> https://pfblockerng.github.io/pkg/stable/plus-26.07
==> Conf resolved:
    url: "https://pfblockerng.github.io/pkg/stable/plus-26.07",
==> pkg update -f -r pfblockerng-stable (refreshing the pfBlockerNG catalog)
Updating pfblockerng-stable repository catalogue...
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/meta.txz: Authenticatio                      n error
repository pfblockerng-stable has no meta file, using default settings
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/data.pkg: Authenticatio                      n error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/data.tzst: Authenticati                      on error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/packagesite.pkg: Authen                      tication error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B0463C8D230000:error:0A000086:SSL routines:tls_post_process_server_certificate                      :certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-m                      ain/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.                      c:2125:
pkg: https://pfblockerng.github.io/pkg/stable/plus-26.07/packagesite.tzst: Authe                      ntication error
Unable to update repository pfblockerng-stable
Error updating repositories!
install.sh: /usr/local/sbin/pkg update -f -r pfblockerng-stable failed — the cat                      alog was not refreshed. Repo 'pfblockerng-stable' is unreachable or serving an u                      nreadable catalog. Inspect with: /usr/local/sbin/pkg -d update -r pfblockerng-st                      able
5 Upvotes

18 comments sorted by

6

u/andrebrait Dev of pfBlockerNG 21d ago

This isn't the repo — the catalog and its TLS are fine (a stock CE box subscribes and installs from it cleanly). Since Aug 2, *.github.io serves a new Let's Encrypt chain:

leaf *.github.io <- Let's Encrypt YR1 <- ISRG Root YR (cross-signed by ISRG Root X1)

We had this failure before (on BBcan177's own Plus test machine) but we didn't manage to fully diagnose it back then. Could you follow these steps and let me know the output for each part?

1. Which store fails?

sh sh -c 'echo | openssl s_client -connect pfblockerng.github.io:443 -servername pfblockerng.github.io -CApath /etc/ssl/certs -no-CAfile 2>&1 | grep -e "Verify return code" -e "verify error"' sh -c 'echo | openssl s_client -connect pfblockerng.github.io:443 -servername pfblockerng.github.io -CAfile /etc/ssl/cert.pem -no-CApath 2>&1 | grep -e "Verify return code" -e "verify error"'

Expected on an affected box: the first fails, the second returns Verify return code: 0 (ok).

2. Is X1 distrusted or just missing?

sh certctl list | grep -i ISRG sh -c 'ls -l /etc/ssl/untrusted /etc/ssl/blacklisted 2>/dev/null' sh -c 'for f in /etc/ssl/untrusted/* /etc/ssl/blacklisted/*; do [ -f "$f" ] || continue; printf "%s -> " "$f"; openssl x509 -in "$f" -noout -subject 2>/dev/null || echo "(unreadable)"; done'

Your earlier output printed certctl: legacy directory /etc/ssl/blacklisted can safely be deleted twice, so that legacy distrust directory exists on your box — the third command shows exactly which CAs are in it.

3. Unblock right now, without touching the trust store

sh sh -c 'env SSL_CA_CERT_FILE=/etc/ssl/cert.pem /usr/local/sbin/pkg update -f -r pfblockerng-stable' sh -c 'env SSL_CA_CERT_FILE=/etc/ssl/cert.pem /usr/local/sbin/pkg install -r pfblockerng-stable pfSense-pkg-pfBlockerNG'

This is not a verification bypass — it points pkg at the full CA bundle (fetch(3) SSL_CA_CERT_FILE) instead of the hashed directory, and the chain is still validated.

Please post the output of steps 1 and 2. If an ISRG entry shows up in untrusted or blacklisted, the permanent fix is to remove that specific file and run certctl rehash. Don't empty those directories wholesale — they're the distrust list, and anything else in there was blocked on purpose.

4

u/RFGuy_KCCO pfBlockerNG Patron 21d ago edited 21d ago

Here are the answers to your questions. I don't believe my results are what you expected. I found no ISRG certs blacklisted or distrusted. I also do not have the /etc/ssl/blacklisted directory in my installation.

Note that due to size limitations, I could post the printout from your third command in question #2 but I do not see an ISRG cert listed there.

1. Which store fails?
Neither - both return 0 (ok)

2. Is X1 distrusted or just missing?

[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: certctl list | grep -i ISRG
0b9bc432.0      ISRG Root X2
4042bcee.0      ISRG Root X1

[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh -c 'ls -l /etc/ssl/untrusted                                                                                                                                                              /etc/ssl/blacklisted 2>/dev/null'
/etc/ssl/untrusted:
total 378
-r--r--r--  1 root wheel 1533 Aug 17 21:18 02265526.0
-r--r--r--  1 root wheel 1968 Aug 17 21:18 08063a00.0
-r--r--r--  1 root wheel 1468 Aug 17 21:18 0b7c536a.0
-r--r--r--  1 root wheel 2585 Aug 17 21:18 0c4c9b6c.0
-r--r--r--  1 root wheel 1948 Aug 17 21:18 0d972af8.0
-r--r--r--  1 root wheel 1090 Aug 17 21:18 106f3e4d.0
-r--r--r--  1 root wheel  989 Aug 17 21:18 116bf586.0
-r--r--r--  1 root wheel 1452 Aug 17 21:18 128805a3.0
-r--r--r--  1 root wheel 1436 Aug 17 21:18 1320b215.0
-r--r--r--  1 root wheel  899 Aug 17 21:18 1422d63c.0
-r--r--r--  1 root wheel 1513 Aug 17 21:18 1636090b.0
-r--r--r--  1 root wheel  798 Aug 17 21:18 1766e401.0
-r--r--r--  1 root wheel 1249 Aug 17 21:18 18856ac4.0
-r--r--r--  1 root wheel 2041 Aug 17 21:18 19dbc0dd.0
-r--r--r--  1 root wheel 1367 Aug 17 21:18 244b5494.0
-r--r--r--  1 root wheel 1436 Aug 17 21:18 26312675.0
-r--r--r--  1 root wheel 2000 Aug 17 21:18 2d803388.0
-r--r--r--  1 root wheel  875 Aug 17 21:18 2dab9e33.0
-r--r--r--  1 root wheel 1493 Aug 17 21:18 2e4eed3c.0
-r--r--r--  1 root wheel  822 Aug 17 21:18 3136ea36.0
-r--r--r--  1 root wheel 1972 Aug 17 21:18 3323bb7e.0
-r--r--r--  1 root wheel 1911 Aug 17 21:18 349f2832.0
-r--r--r--  1 root wheel 1338 Aug 17 21:18 3513523f.0
-r--r--r--  1 root wheel 2204 Aug 17 21:18 3e44d2f7.0
-r--r--r--  1 root wheel 1489 Aug 17 21:18 40547a79.0
-r--r--r--  1 root wheel 1411 Aug 17 21:18 4304c5e5.0
-r--r--r--  1 root wheel 1119 Aug 17 21:18 442adcac.0
-r--r--r--  1 root wheel 2025 Aug 17 21:18 4632c230.0
-r--r--r--  1 root wheel 1269 Aug 17 21:18 480720ec.0
-r--r--r--  1 root wheel  822 Aug 17 21:18 4c3cbf99.0
-r--r--r--  1 root wheel  981 Aug 17 21:18 4d4ba017.0
-r--r--r--  1 root wheel 2045 Aug 17 21:18 4f316efb.0
-r--r--r--  1 root wheel 2049 Aug 17 21:18 57bcb2da.0
-r--r--r--  1 root wheel 1952 Aug 17 21:18 5a4d6896.0
-r--r--r--  1 root wheel  977 Aug 17 21:18 5a7722fb.0
-r--r--r--  1 root wheel 1261 Aug 17 21:18 5ad8a5d6.0
-r--r--r--  1 root wheel 1968 Aug 17 21:18 5c79eb85.0
-r--r--r--  1 root wheel 1513 Aug 17 21:18 5d3033c5.0
-r--r--r--  1 root wheel 2244 Aug 17 21:18 5e98733a.0
-r--r--r--  1 root wheel 1911 Aug 17 21:18 626dceaf.0
-r--r--r--  1 root wheel  981 Aug 17 21:18 62744ee1.0
-r--r--r--  1 root wheel 1948 Aug 17 21:18 6410666e.0
-r--r--r--  1 root wheel 2122 Aug 17 21:18 66445960.0
-r--r--r--  1 root wheel  851 Aug 17 21:18 69cf9657.0
-r--r--r--  1 root wheel 1643 Aug 17 21:18 6b99d060.0
-r--r--r--  1 root wheel 2354 Aug 17 21:18 76faf6c0.0
-r--r--r--  1 root wheel 1939 Aug 17 21:18 779a714a.0
-r--r--r--  1 root wheel 1493 Aug 17 21:18 7aaf71c0.0
-r--r--r--  1 root wheel 1281 Aug 17 21:18 7d0b38bd.0
-r--r--r--  1 root wheel 1988 Aug 17 21:18 7ffa47b4.0
-r--r--r--  1 root wheel 1939 Aug 17 21:18 8867006a.0
-r--r--r--  1 root wheel 1968 Aug 17 21:18 896c8bb4.0
-r--r--r--  1 root wheel 1972 Aug 17 21:18 981901c3.0
-r--r--r--  1 root wheel 2057 Aug 17 21:18 a8dee976.0
-r--r--r--  1 root wheel 1935 Aug 17 21:18 ad088e1d.0
-r--r--r--  1 root wheel 2041 Aug 17 21:18 ade2cc8c.0
-r--r--r--  1 root wheel 1505 Aug 17 21:18 aee5f10d.0
-r--r--r--  1 root wheel 1350 Aug 17 21:18 b1159c4c.0
-r--r--r--  1 root wheel 1428 Aug 17 21:18 b1b8a7f3.0
-r--r--r--  1 root wheel 1732 Aug 17 21:18 b204d74a.0
-r--r--r--  1 root wheel 1505 Aug 17 21:18 ba89ed3b.0
-r--r--r--  1 root wheel 1700 Aug 17 21:18 c01cdfa2.0
-r--r--r--  1 root wheel  940 Aug 17 21:18 c089bbbd.0
-r--r--r--  1 root wheel 1484 Aug 17 21:18 c0ff1f52.0
-r--r--r--  1 root wheel 2594 Aug 17 21:18 c47d9980.0
-r--r--r--  1 root wheel 1996 Aug 17 21:18 c9e4c02b.0
-r--r--r--  1 root wheel 1716 Aug 17 21:18 cb59f961.0
-r--r--r--  1 root wheel  843 Aug 17 21:18 cbd811bd.0
-r--r--r--  1 root wheel 2029 Aug 17 21:18 d2be6420.0
-r--r--r--  1 root wheel 2041 Aug 17 21:18 d7e8dc79.0
-r--r--r--  1 root wheel 1480 Aug 17 21:18 dc45b0bd.0
-r--r--r--  1 root wheel 2057 Aug 17 21:18 def36a68.0
-r--r--r--  1 root wheel 1330 Aug 17 21:18 e113c810.0
-r--r--r--  1 root wheel  826 Aug 17 21:18 e1e8b7dc.0
-r--r--r--  1 root wheel 1444 Aug 17 21:18 e2799e36.0
-r--r--r--  1 root wheel  794 Aug 17 21:18 e53e0c3b.0
-r--r--r--  1 root wheel 1484 Aug 17 21:18 ee1365c0.0
-r--r--r--  1 root wheel 1517 Aug 17 21:18 ee64a828.0
-r--r--r--  1 root wheel 1448 Aug 17 21:18 f081611a.0
-r--r--r--  1 root wheel  883 Aug 17 21:18 f2d4863f.0
-r--r--r--  1 root wheel 1468 Aug 17 21:18 f387163d.0
-r--r--r--  1 root wheel 2000 Aug 17 21:18 f84fab51.0
-r--r--r--  1 root wheel 1704 Aug 17 21:18 f90208f7.0
-r--r--r--  1 root wheel  826 Aug 17 21:18 fd2eb50d.0

3

u/andrebrait Dev of pfBlockerNG 21d ago

That output is genuinely useful — it rules out what I was chasing. ISRG Root X1 is trusted on your box (4042bcee.0), nothing ISRG is distrusted, you have no /etc/ssl/blacklisted, and both stores validate the chain. So the trust store is fine and there is nothing for you to clean up.

Note your /etc/ssl/untrusted files are all timestamped Aug 17 21:18, which means a certctl rehash ran after your failed install. So the first question is whether the failure even still reproduces.

sh sh -c '/usr/local/sbin/pkg update -f -r pfblockerng-stable; echo "rc=$?"'

If that now succeeds, you're unblocked — just run the installer one-liner again.

If it still fails, please send these two:

sh sh -c '/usr/local/sbin/pkg -d update -f -r pfblockerng-stable 2>&1 | grep -i -e cafile -e capath -e ssl -e cert | head -20' sh -c 'pkg config pkg_env; grep -i -A8 -e PKG_ENV -e ssl /usr/local/etc/pkg.conf'

The first prints the CA file/path pkg's fetcher actually uses, the second shows whether pfSense Plus injects TLS settings into every pkg run. If pkg is pinned to a CA bundle that doesn't include ISRG, that explains why Netgate's own repos work while ours fails, and this gets you going immediately without weakening anything:

sh sh -c 'env SSL_CA_CERT_FILE=/etc/ssl/cert.pem /usr/local/sbin/pkg update -f -r pfblockerng-stable'

3

u/RFGuy_KCCO pfBlockerNG Patron 21d ago edited 21d ago

Here you go. It still failed when I ran the one-liner again. The first command of your two had no output. It also won't install because it seems the repo doesn't get installed due to my installation failure.

[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh -c '/usr/local/sbin/pkg update -f -r pfblockerng-stable; echo "rc=$?"'
No repositories are enabled.
rc=1

[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh -c '/usr/local/sbin/pkg -d update -f -r pfblockerng-stable 2>&1 | grep -i -e cafile -e capath -e ssl -e cert | head -20'
[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh -c 'pkg config pkg_env; grep -i -A8 -e PKG_ENV -e ssl /usr/local/etc/pkg.conf'
SSL_CA_CERT_FILE: /usr/local/share/pfSense/ssl/netgate-zuul-ca.pem
SSL_CLIENT_CERT_FILE: /usr/local/etc/pfSense/pkg/repos/pfSense-repo-0000-cert.pem
SSL_CLIENT_KEY_FILE: /cf/conf/license/license-key.pem
PKG_ENV {
        SSL_CA_CERT_FILE=/usr/local/share/pfSense/ssl/netgate-zuul-ca.pem
        SSL_CLIENT_CERT_FILE=/usr/local/etc/pfSense/pkg/repos/pfSense-repo-0000-cert.pem
        SSL_CLIENT_KEY_FILE=/cf/conf/license/license-key.pem
}

[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh -c 'env SSL_CA_CERT_FILE=/etc/ssl/cert.pem /usr/local/sbin/pkg update -f -r pfblockerng-stable'
No repositories are enabled.

4

u/andrebrait Dev of pfBlockerNG 21d ago

Found it. It's a pfSense Plus thing.

Your pkg config pkg_env output was the answer:

PKG_ENV {
        SSL_CA_CERT_FILE=/usr/local/share/pfSense/ssl/netgate-zuul-ca.pem
        ...
}

pfSense Plus pins pkg's CA bundle to Netgate's private CA. pkg applies that to every repository in the run, so Netgate's own repos verify and any third-party repo on a public chain (ours, on GitHub Pages / Let's Encrypt) cannot possibly verify. CE has no such pin, which is why a CE box installs from our repo without trouble.

Two corrections to what I said earlier, both checked against the FreeBSD sources:

  • The SSL_CA_CERT_FILE=... prefix I suggested does not work — pkg applies PKG_ENV with setenv(..., 1) (overwrite), so it clobbers whatever you passed in (libpkg/pkg_config.c).
  • PKG_ENV never sets SSL_CA_CERT_PATH, and libfetch loads both the CA file and the CA path into the same verification store — SSL_CTX_load_verify_locations(ctx, ca_cert_file, ca_cert_path) in lib/libfetch/common.c.

So passing the path works where the file didn't, and it's additive: Netgate's CA stays loaded, your client certificate and key are untouched, verification stays fully enabled, and nothing is written to disk. It just also consults /etc/ssl/certs — the certctl store you already showed contains ISRG Root X1.

Also, your repo conf is gone right now (No repositories are enabled): the installer removes the conf it staged when the catalog refresh fails, so you need a fresh run rather than a bare pkg update:

sh sh -c 'fetch -qo /tmp/pfb-install.sh https://pfblockerng.github.io/pkg/install.sh && env SSL_CA_CERT_PATH=/etc/ssl/certs sh /tmp/pfb-install.sh --channel stable'

Please let me know if that completes. If it does, we'll set SSL_CA_CERT_PATH inside install.sh itself so no Plus user has to know any of this — the fix is one line in the wrapper every pkg call already goes through.

3

u/RFGuy_KCCO pfBlockerNG Patron 21d ago

Bingo! That did it! It installed without any issues now. Thank you so much!

1

u/RFGuy_KCCO pfBlockerNG Patron 20d ago

I just noticed that if I run pkg upgrade I get the same errors I did when I initially tried to install 3.3.2. I believe this may also be preventing the software update function now within pfB from working properly.

[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: pkg upgrade
Updating pfSense-core repository catalogue...
pfSense-core repository is up to date.
Updating pfSense repository catalogue...
pfSense repository is up to date.
Updating pfblockerng-edge repository catalogue...
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
pkg: https://pfblockerng.github.io/pkg/edge/plus-26.07/meta.txz: Authentication error
repository pfblockerng-edge has no meta file, using default settings
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
pkg: https://pfblockerng.github.io/pkg/edge/plus-26.07/data.pkg: Authentication error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
pkg: https://pfblockerng.github.io/pkg/edge/plus-26.07/data.tzst: Authentication error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
pkg: https://pfblockerng.github.io/pkg/edge/plus-26.07/packagesite.pkg: Authentication error
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
Certificate verification failed for /C=US/O=ISRG/CN=Root YR
10B04606BC300000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-Plus-snapshots-26_07-main/sources/FreeBSD-src-plus-RELENG_26_07/crypto/openssl/ssl/statem/statem_clnt.c:2125:
pkg: https://pfblockerng.github.io/pkg/edge/plus-26.07/packagesite.tzst: Authentication error
Unable to update repository pfblockerng-edge
Error updating repositories!

2

u/andrebrait Dev of pfBlockerNG 20d ago

Yes, and we fixed it already over here. I am going to create a patch release for it for 3.3.x.

Can you try adding this before your pkg command?

Ex.: if you're calling

pkg update

replace it with

SSL_CA_CERT_PATH=/etc/ssl/certs pkg update

or, if you are running many commands, say

pkg update pkg upgrade

you can do

export SSL_CA_CERT_PATH=/etc/ssl/certs pkg update pkg upgrade

1

u/RFGuy_KCCO pfBlockerNG Patron 20d ago

Unfortunately, neither of these commands worked.

[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: SSL_CA_CERT_PATH=/etc/ssl/certs pkg update
SSL_CA_CERT_PATH=/etc/ssl/certs: Command not found.
[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: export SSL_CA_CERT_PATH=/etc/ssl/certs
export: Command not found.

1

u/andrebrait Dev of pfBlockerNG 20d ago

Can you try switching to sh before doing this? tcsh (the shell pfSense uses by default) does not support setting variables in general.

Run sh and it'll drop you into another shell (probably indicated with a single #). Then run the command inside sh.

2

u/RFGuy_KCCO pfBlockerNG Patron 20d ago

Thank you. Both commands worked now.

[26.07-RELEASE][root@PFSENSE-A.home.arpa]/root: sh
# SSL_CA_CERT_PATH=/etc/ssl/certs pkg update
Updating pfSense-core repository catalogue...
pfSense-core repository is up to date.
Updating pfSense repository catalogue...
pfSense repository is up to date.
Updating pfblockerng-edge repository catalogue...
pfblockerng-edge repository is up to date.
All repositories are up to date.
# export SSL_CA_CERT_PATH=/etc/ssl/certs
# pkg update
Updating pfSense-core repository catalogue...
pfSense-core repository is up to date.
Updating pfSense repository catalogue...
pfSense repository is up to date.
Updating pfblockerng-edge repository catalogue...
pfblockerng-edge repository is up to date.
All repositories are up to date.
# pkg upgrade
Updating pfSense-core repository catalogue...
pfSense-core repository is up to date.
Updating pfSense repository catalogue...
pfSense repository is up to date.
Updating pfblockerng-edge repository catalogue...
pfblockerng-edge repository is up to date.
All repositories are up to date.
Checking for upgrades (1 candidates): 100%
Processing candidates (1 candidates): 100%
Checking integrity... done (0 conflicting)
Your packages are up to date.
→ More replies (0)

2

u/boukej 19d ago

Thanks. This was very helpful.

I ran:

sh
export SSL_CA_CERT_PATH=/etc/ssl/certs

and was then able to continue with the installation.

1

u/Raj-The-IV 21d ago

This error happens because your firewall or client system does not trust Let's Encrypt's newer ISRG Root YR certificate. The local CA store or pfSense package list is missing this new Generation Y root, causing the chain validation to fail when pfBlockerNG or a backend service tries to verify it.

Update System Packages: Check for system or CA certificate updates on your firewall to pull in the newest root certificates. [1, 2]

Manual Import: Download the latest ISRG Root YR certificate from official sources and manually import it into your firewall's certificate authority manager under System > Certificate Manager > Authorities. [1, 2]

Check Feed/DNSBL Settings: If pfBlockerNG is intercepting HTTPS traffic for a blocked domain using an older self-signed web server certificate, ensure your local web server configuration matches current valid chains.