OPNsense Forum

Archive => 21.1 Legacy Series => Topic started by: ktx on February 02, 2021, 08:24:06 pm

Title: webif update to 21.1 stuck
Post by: ktx on February 02, 2021, 08:24:06 pm
hey guys!

i hope somebody can help me or give me advice:

after waiting some days and having a look into the forums i decided to finally start the update from 20.7.6 to 21.1.
everything started fine when i hit the update button in the webif.

now its stuck there:

Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Updating OPNsense repository catalogue...
OPNsense repository is up to date.
All repositories are up to date.
Checking for upgrades (62 candidates): .......... done
Processing candidates (62 candidates): .......... done
The following 76 package(s) will be affected (of 0 checked):

New packages to be INSTALLED:
   hidapi: 0.8.0.r1_3
   iftop: 1.0.p4
   libcbor: 0.8.0
   libcjson: 1.7.14
   libfido2: 1.5.0_1
   libgcrypt: 1.8.7
   libgpg-error: 1.41
   libxslt: 1.1.34_1
   py37-beautifulsoup: 4.9.3
   py37-html5lib: 1.0.1
   py37-lxml: 4.6.2
   py37-markupsafe: 1.1.1_1
   py37-soupsieve: 2.0.1
   py37-webencodings: 0.5.1
   syslog-ng: 3.30.1_1

Installed packages to be UPGRADED:
   acme.sh: 2.8.7 -> 2.8.8
   bind-tools: 9.16.7 -> 9.16.10
   curl: 7.73.0 -> 7.74.0
   dhcp6c: 20200512 -> 20200512_1
   expat: 2.2.8 -> 2.2.10
   glib: 2.66.2,1 -> 2.66.4_1,1
   gmp: 6.2.0 -> 6.2.1
   haproxy20: 2.0.18 -> 2.0.20
   krb5: 1.18.2 -> 1.18.3
   ldns: 1.7.1_1 -> 1.7.1_2
   liblz4: 1.9.2_1,1 -> 1.9.3,1
   libnghttp2: 1.41.0 -> 1.42.0
   libxml2: 2.9.10_1 -> 2.9.10_2
   lighttpd: 1.4.55_1 -> 1.4.58
   monit: 5.27.0 -> 5.27.1
   nano: 5.2 -> 5.4
   nss: 3.58 -> 3.60.1
   openldap-sasl-client: 2.4.51 -> 2.4.56
   openssh-portable: 8.2.p1_1,1 -> 8.4.p1_3,1
   openssl: 1.1.1h_1,1 -> 1.1.1i,1
   opnsense: 20.7.4 -> 20.7.8_4
   opnsense-update: 20.7.4 -> 20.7.8
   os-acme-client: 1.36 -> 2.2
   os-haproxy: 2.25 -> 2.26
   pcre: 8.44 -> 8.44_1
   pcre2: 10.35 -> 10.36
   perl5: 5.32.0 -> 5.32.0_1
   php73: 7.3.23 -> 7.3.26
   php73-ctype: 7.3.23 -> 7.3.26
   php73-curl: 7.3.23 -> 7.3.26
   php73-dom: 7.3.23 -> 7.3.26
   php73-filter: 7.3.23 -> 7.3.26
   php73-gettext: 7.3.23 -> 7.3.26
   php73-hash: 7.3.23 -> 7.3.26
   php73-json: 7.3.23 -> 7.3.26
   php73-ldap: 7.3.23 -> 7.3.26
   php73-openssl: 7.3.23 -> 7.3.26
   php73-pdo: 7.3.23 -> 7.3.26
   php73-session: 7.3.23 -> 7.3.26
   php73-simplexml: 7.3.23 -> 7.3.26
   php73-sockets: 7.3.23 -> 7.3.26
   php73-sqlite3: 7.3.23 -> 7.3.26
   php73-xml: 7.3.23 -> 7.3.26
   php73-zlib: 7.3.23 -> 7.3.26
   py37-Jinja2: 2.11.2 -> 2.11.2_1
   py37-certifi: 2020.6.20 -> 2020.12.5
   py37-cffi: 1.14.3 -> 1.14.4
   py37-cryptography: 2.6.1 -> 2.9.2
   py37-dns-lexicon: 3.3.28 -> 3.5.0
   py37-openssl: 19.0.0 -> 19.1.0
   py37-pytz: 2020.1,1 -> 2020.5,1
   py37-urllib3: 1.25.10,1 -> 1.25.11,1
   radvd: 2.18_2 -> 2.19
   readline: 8.0.4 -> 8.0.4_1
   socat: ->
   sqlite3: 3.33.0,1 -> 3.34.0,1
   strongswan: 5.8.4_1 -> 5.9.1
   sudo: 1.9.3p1 -> 1.9.5p2
   suricata: 5.0.4 -> 5.0.5
   unbound: 1.12.0 -> 1.13.0_1

Installed packages to be REINSTALLED:
   wpa_supplicant-2.9_7 (options changed)

Number of packages to be installed: 15
Number of packages to be upgraded: 60
Number of packages to be reinstalled: 1

The process will require 17 MiB more space.
56 MiB to be downloaded.
[1/76] Fetching wpa_supplicant-2.9_7.txz: .......... done
[2/76] Fetching unbound-1.13.0_1.txz: .......... done
[3/76] Fetching suricata-5.0.5.txz: .......... done
[4/76] Fetching sudo-1.9.5p2.txz: .......... done
[5/76] Fetching strongswan-5.9.1.txz: .......... done
[6/76] Fetching sqlite3-3.34.0,1.txz: .......... done
[7/76] Fetching socat- .......... done
[8/76] Fetching readline-8.0.4_1.txz: .......... done
[9/76] Fetching radvd-2.19.txz: .......... done
[10/76] Fetching py37-urllib3-1.25.11,1.txz: .......... done
[11/76] Fetching py37-pytz-2020.5,1.txz: .......... done
[12/76] Fetching py37-openssl-19.1.0.txz: .......... done
[13/76] Fetching py37-dns-lexicon-3.5.0.txz: .......... done
[14/76] Fetching py37-cryptography-2.9.2.txz: .......... done
[15/76] Fetching py37-cffi-1.14.4.txz: .......... done
[16/76] Fetching py37-certifi-2020.12.5.txz: .......... done
[17/76] Fetching py37-markupsafe-1.1.1_1.txz: ... done
[18/76] Fetching py37-Jinja2-2.11.2_1.txz: .......... done
[19/76] Fetching php73-zlib-7.3.26.txz: ... done
[20/76] Fetching php73-xml-7.3.26.txz: ... done
[21/76] Fetching php73-sqlite3-7.3.26.txz: ... done
[22/76] Fetching php73-sockets-7.3.26.txz: ..... done
[23/76] Fetching php73-simplexml-7.3.26.txz: ... done
[24/76] Fetching php73-session-7.3.26.txz: ..... done
[25/76] Fetching php73-pdo-7.3.26.txz: ...... done
[26/76] Fetching php73-openssl-7.3.26.txz: ........ done
[27/76] Fetching php73-ldap-7.3.26.txz: .... done
[28/76] Fetching php73-json-7.3.26.txz: ... done
[29/76] Fetching php73-hash-7.3.26.txz: .......... done
[30/76] Fetching php73-gettext-7.3.26.txz: . done
[31/76] Fetching php73-filter-7.3.26.txz: ... done
[32/76] Fetching php73-dom-7.3.26.txz: ........ done
[33/76] Fetching php73-curl-7.3.26.txz: .... done
[34/76] Fetching php73-ctype-7.3.26.txz: . done
[35/76] Fetching php73-7.3.26.txz: .......... done
[36/76] Fetching perl5-5.32.0_1.txz: .......... done
[37/76] Fetching pcre2-10.36.txz: .......... done
[38/76] Fetching pcre-8.44_1.txz: .......... done
[39/76] Fetching os-haproxy-2.26.txz: ....... done
[40/76] Fetching os-acme-client-2.2.txz: ......... done
[41/76] Fetching opnsense-update-20.7.8.txz: ........ done
[42/76] Fetching opnsense-20.7.8_4.txz: .......... done
[43/76] Fetching openssl-1.1.1i,1.txz: .......... done
[44/76] Fetching openssh-portable-8.4.p1_3,1.txz: .......... done
[45/76] Fetching openldap-sasl-client-2.4.56.txz: .......... done
[46/76] Fetching nss-3.60.1.txz: .......... done
[47/76] Fetching nano-5.4.txz: .......... done
[48/76] Fetching monit-5.27.1.txz: .......... done
[49/76] Fetching lighttpd-1.4.58.txz: .......... done
[50/76] Fetching libxml2-2.9.10_2.txz: .......... done
[51/76] Fetching libnghttp2-1.42.0.txz: .......... done
[52/76] Fetching liblz4-1.9.3,1.txz: .......... done
[53/76] Fetching ldns-1.7.1_2.txz: .......... done
[54/76] Fetching krb5-1.18.3.txz: .......... done
[55/76] Fetching haproxy20-2.0.20.txz: .......... done
[56/76] Fetching gmp-6.2.1.txz: .......... done
[57/76] Fetching glib-2.66.4_1,1.txz: .......... done
[58/76] Fetching expat-2.2.10.txz: .......... done
[59/76] Fetching dhcp6c-20200512_1.txz: .......... done
[60/76] Fetching curl-7.74.0.txz: .......... done
[61/76] Fetching bind-tools-9.16.10.txz: .......... done
[62/76] Fetching acme.sh-2.8.8.txz: .......... done
[63/76] Fetching py37-beautifulsoup-4.9.3.txz: .......... done
[64/76] Fetching py37-soupsieve-2.0.1.txz: ....... done
[65/76] Fetching py37-html5lib-1.0.1.txz: .......... done
[66/76] Fetching py37-webencodings-0.5.1.txz: .. done
[67/76] Fetching py37-lxml-4.6.2.txz: .......... done
[68/76] Fetching libxslt-1.1.34_1.txz: .......... done
[69/76] Fetching libgcrypt-1.8.7.txz: .......... done
[70/76] Fetching libgpg-error-1.41.txz: .......... done
[71/76] Fetching syslog-ng-3.30.1_1.txz: .......... done
[72/76] Fetching iftop-1.0.p4.txz: ......... done
[73/76] Fetching libfido2-1.5.0_1.txz: .......... done
[74/76] Fetching libcbor-0.8.0.txz: .... done
[75/76] Fetching libcjson-1.7.14.txz: ..... done
[76/76] Fetching hidapi-0.8.0.r1_3.txz: .... done
Checking integrity... done (2 conflicting)
  - py37-markupsafe-1.1.1_1 conflicts with py37-MarkupSafe-1.1.1 on /usr/local/lib/python3.7/site-packages/MarkupSafe-1.1.1-py3.7.egg-info/PKG-INFO
  - syslog-ng-3.30.1_1 conflicts with syslog-ng329-3.29.1_2 on /usr/local/bin/dqtool
Checking integrity... done (0 conflicting)
Conflicts with the existing packages have been found.
One more solver iteration is needed to resolve them.
The following 78 package(s) will be affected (of 0 checked):

Installed packages to be REMOVED:
   py37-MarkupSafe: 1.1.1
   syslog-ng329: 3.29.1_2

New packages to be INSTALLED:
   hidapi: 0.8.0.r1_3
   iftop: 1.0.p4
   libcbor: 0.8.0
   libcjson: 1.7.14
   libfido2: 1.5.0_1
   libgcrypt: 1.8.7
   libgpg-error: 1.41
   libxslt: 1.1.34_1
   py37-beautifulsoup: 4.9.3
   py37-html5lib: 1.0.1
   py37-lxml: 4.6.2
   py37-markupsafe: 1.1.1_1
   py37-soupsieve: 2.0.1
   py37-webencodings: 0.5.1
   syslog-ng: 3.30.1_1

Installed packages to be UPGRADED:
   acme.sh: 2.8.7 -> 2.8.8
   bind-tools: 9.16.7 -> 9.16.10
   curl: 7.73.0 -> 7.74.0
   dhcp6c: 20200512 -> 20200512_1
   expat: 2.2.8 -> 2.2.10
   glib: 2.66.2,1 -> 2.66.4_1,1
   gmp: 6.2.0 -> 6.2.1
   haproxy20: 2.0.18 -> 2.0.20
   krb5: 1.18.2 -> 1.18.3
   ldns: 1.7.1_1 -> 1.7.1_2
   liblz4: 1.9.2_1,1 -> 1.9.3,1
   libnghttp2: 1.41.0 -> 1.42.0
   libxml2: 2.9.10_1 -> 2.9.10_2
   lighttpd: 1.4.55_1 -> 1.4.58
   monit: 5.27.0 -> 5.27.1
   nano: 5.2 -> 5.4
   nss: 3.58 -> 3.60.1
   openldap-sasl-client: 2.4.51 -> 2.4.56
   openssh-portable: 8.2.p1_1,1 -> 8.4.p1_3,1
   openssl: 1.1.1h_1,1 -> 1.1.1i,1
   opnsense: 20.7.4 -> 20.7.8_4
   opnsense-update: 20.7.4 -> 20.7.8
   os-acme-client: 1.36 -> 2.2
   os-haproxy: 2.25 -> 2.26
   pcre: 8.44 -> 8.44_1
   pcre2: 10.35 -> 10.36
   perl5: 5.32.0 -> 5.32.0_1
   php73: 7.3.23 -> 7.3.26
   php73-ctype: 7.3.23 -> 7.3.26
   php73-curl: 7.3.23 -> 7.3.26
   php73-dom: 7.3.23 -> 7.3.26
   php73-filter: 7.3.23 -> 7.3.26
   php73-gettext: 7.3.23 -> 7.3.26
   php73-hash: 7.3.23 -> 7.3.26
   php73-json: 7.3.23 -> 7.3.26
   php73-ldap: 7.3.23 -> 7.3.26
   php73-openssl: 7.3.23 -> 7.3.26
   php73-pdo: 7.3.23 -> 7.3.26
   php73-session: 7.3.23 -> 7.3.26
   php73-simplexml: 7.3.23 -> 7.3.26
   php73-sockets: 7.3.23 -> 7.3.26
   php73-sqlite3: 7.3.23 -> 7.3.26
   php73-xml: 7.3.23 -> 7.3.26
   php73-zlib: 7.3.23 -> 7.3.26
   py37-Jinja2: 2.11.2 -> 2.11.2_1
   py37-certifi: 2020.6.20 -> 2020.12.5
   py37-cffi: 1.14.3 -> 1.14.4
   py37-cryptography: 2.6.1 -> 2.9.2
   py37-dns-lexicon: 3.3.28 -> 3.5.0
   py37-openssl: 19.0.0 -> 19.1.0
   py37-pytz: 2020.1,1 -> 2020.5,1
   py37-urllib3: 1.25.10,1 -> 1.25.11,1
   radvd: 2.18_2 -> 2.19
   readline: 8.0.4 -> 8.0.4_1
   socat: ->
   sqlite3: 3.33.0,1 -> 3.34.0,1
   strongswan: 5.8.4_1 -> 5.9.1
   sudo: 1.9.3p1 -> 1.9.5p2
   suricata: 5.0.4 -> 5.0.5
   unbound: 1.12.0 -> 1.13.0_1

Installed packages to be REINSTALLED:
   wpa_supplicant-2.9_7 (options changed)

Number of packages to be removed: 2
Number of packages to be installed: 15
Number of packages to be upgraded: 60
Number of packages to be reinstalled: 1

The process will require 13 MiB more space.
[1/78] Upgrading readline from 8.0.4 to 8.0.4_1...
[1/78] Extracting readline-8.0.4_1: .......... done
[2/78] Upgrading openssl from 1.1.1h_1,1 to 1.1.1i,1...
[2/78] Extracting openssl-1.1.1i,1: .......... done
[3/78] Installing libcjson-1.7.14...
[3/78] Extracting libcjson-1.7.14: .......... done
[4/78] Upgrading pcre2 from 10.35 to 10.36...
[4/78] Extracting pcre2-10.36: .......... done
[5/78] Upgrading libxml2 from 2.9.10_1 to 2.9.10_2...
[5/78] Extracting libxml2-2.9.10_2: .......... done
[6/78] Upgrading sqlite3 from 3.33.0,1 to 3.34.0,1...
[6/78] Extracting sqlite3-3.34.0,1: .......... done
[7/78] Upgrading libnghttp2 from 1.41.0 to 1.42.0...
[7/78] Extracting libnghttp2-1.42.0: .......... done
[8/78] Upgrading gmp from 6.2.0 to 6.2.1...
[8/78] Extracting gmp-6.2.1: .......... done
[9/78] Installing libcbor-0.8.0...
[9/78] Extracting libcbor-0.8.0: .......... done
[10/78] Installing hidapi-0.8.0.r1_3...
[10/78] Extracting hidapi-0.8.0.r1_3: .......... done
[11/78] Upgrading php73 from 7.3.23 to 7.3.26...
[11/78] Extracting php73-7.3.26: .......... done
[12/78] Upgrading pcre from 8.44 to 8.44_1...
[12/78] Extracting pcre-8.44_1: .......... done
[13/78] Upgrading openldap-sasl-client from 2.4.51 to 2.4.56...
[13/78] Extracting openldap-sasl-client-2.4.56: .......... done
[14/78] Upgrading nss from 3.58 to 3.60.1...
[14/78] Extracting nss-3.60.1: .......... done
[15/78] Upgrading liblz4 from 1.9.2_1,1 to 1.9.3,1...
[15/78] Extracting liblz4-1.9.3,1: .......... done
[16/78] Upgrading ldns from 1.7.1_1 to 1.7.1_2...
[16/78] Extracting ldns-1.7.1_2: .......... done
[17/78] Upgrading expat from 2.2.8 to 2.2.10...
[17/78] Extracting expat-2.2.10: .......... done
[18/78] Upgrading curl from 7.73.0 to 7.74.0...
[18/78] Extracting curl-7.74.0: .......... done
[19/78] Installing libfido2-1.5.0_1...
[19/78] Extracting libfido2-1.5.0_1: .......... done
[20/78] Upgrading php73-pdo from 7.3.23 to 7.3.26...
[20/78] Extracting php73-pdo-7.3.26: .......... done
[21/78] Upgrading php73-json from 7.3.23 to 7.3.26...
[21/78] Extracting php73-json-7.3.26: .......... done
[22/78] Upgrading php73-hash from 7.3.23 to 7.3.26...
[22/78] Extracting php73-hash-7.3.26: .......... done
[23/78] Reinstalling wpa_supplicant-2.9_7...
[23/78] Extracting wpa_supplicant-2.9_7: ....... done
[24/78] Upgrading unbound from 1.12.0 to 1.13.0_1...
===> Creating groups.
Using existing group 'unbound'.
===> Creating users
Using existing user 'unbound'.
[24/78] Extracting unbound-1.13.0_1: .......... done
[25/78] Upgrading suricata from 5.0.4 to 5.0.5...
[25/78] Extracting suricata-5.0.5: .......... done
[26/78] Upgrading sudo from 1.9.3p1 to 1.9.5p2...
[26/78] Extracting sudo-1.9.5p2: .......... done
[27/78] Upgrading strongswan from 5.8.4_1 to 5.9.1...
[27/78] Extracting strongswan-5.9.1: .......... done
You may need to manually remove /usr/local/etc/ipsec.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/ipsec.secrets if it is no longer needed.
You may need to manually remove /usr/local/etc/strongswan.conf if it is no longer needed.
[28/78] Upgrading radvd from 2.18_2 to 2.19...
[28/78] Extracting radvd-2.19: .......... done
[29/78] Upgrading php73-zlib from 7.3.23 to 7.3.26...
[29/78] Extracting php73-zlib-7.3.26: ....... done
[30/78] Upgrading php73-xml from 7.3.23 to 7.3.26...
[30/78] Extracting php73-xml-7.3.26: ........ done
[31/78] Upgrading php73-sqlite3 from 7.3.23 to 7.3.26...
[31/78] Extracting php73-sqlite3-7.3.26: ........ done
[32/78] Upgrading php73-sockets from 7.3.23 to 7.3.26...
[32/78] Extracting php73-sockets-7.3.26: .......... done
[33/78] Upgrading php73-simplexml from 7.3.23 to 7.3.26...
[33/78] Extracting php73-simplexml-7.3.26: ......... done
[34/78] Upgrading php73-session from 7.3.23 to 7.3.26...
[34/78] Extracting php73-session-7.3.26: .......... done
[35/78] Upgrading php73-openssl from 7.3.23 to 7.3.26...
[35/78] Extracting php73-openssl-7.3.26: ....... done
[36/78] Upgrading php73-ldap from 7.3.23 to 7.3.26...
[36/78] Extracting php73-ldap-7.3.26: ....... done
[37/78] Upgrading php73-gettext from 7.3.23 to 7.3.26...
[37/78] Extracting php73-gettext-7.3.26: ....... done
[38/78] Upgrading php73-filter from 7.3.23 to 7.3.26...
[38/78] Extracting php73-filter-7.3.26: ........ done
[39/78] Upgrading php73-dom from 7.3.23 to 7.3.26...
[39/78] Extracting php73-dom-7.3.26: .......... done
[40/78] Upgrading php73-curl from 7.3.23 to 7.3.26...
[40/78] Extracting php73-curl-7.3.26: ....... done
[41/78] Upgrading php73-ctype from 7.3.23 to 7.3.26...
[41/78] Extracting php73-ctype-7.3.26: ....... done
[42/78] Upgrading opnsense-update from 20.7.4 to 20.7.8...
[42/78] Extracting opnsense-update-20.7.8: .......... done
[43/78] Upgrading openssh-portable from 8.2.p1_1,1 to 8.4.p1_3,1...
[43/78] Extracting openssh-portable-8.4.p1_3,1: .......... done
You may need to manually remove /usr/local/etc/ssh/sshd_config if it is no longer needed.
[44/78] Upgrading monit from 5.27.0 to 5.27.1...
[44/78] Extracting monit-5.27.1: ....... done
[45/78] Upgrading lighttpd from 1.4.55_1 to 1.4.58...
===> Creating groups.
Using existing group 'www'.
===> Creating users
Using existing user 'www'.
[45/78] Extracting lighttpd-1.4.58: .......... done
[46/78] Upgrading dhcp6c from 20200512 to 20200512_1...
[46/78] Extracting dhcp6c-20200512_1: ........ done
[47/78] Upgrading glib from 2.66.2,1 to 2.66.4_1,1...
[47/78] Extracting glib-2.66.4_1,1: .......... done
No schema files found: doing nothing.
[48/78] Deinstalling syslog-ng329-3.29.1_2...
[48/78] Deleting files for syslog-ng329-3.29.1_2: .......... done
[49/78] Deinstalling py37-MarkupSafe-1.1.1...
[49/78] Deleting files for py37-MarkupSafe-1.1.1: .......... done
[50/78] Upgrading py37-certifi from 2020.6.20 to 2020.12.5...
[50/78] Extracting py37-certifi-2020.12.5: .......... done
[51/78] Installing libgpg-error-1.41...
[51/78] Extracting libgpg-error-1.41: .......... done
[52/78] Installing libgcrypt-1.8.7...
[52/78] Extracting libgcrypt-1.8.7: .......... done
[53/78] Installing py37-webencodings-0.5.1...
[53/78] Extracting py37-webencodings-0.5.1: .......... done
[54/78] Installing libxslt-1.1.34_1...
[54/78] Extracting libxslt-1.1.34_1: .......... done
[55/78] Upgrading py37-cffi from 1.14.3 to 1.14.4...
[55/78] Extracting py37-cffi-1.14.4: .......... done
[56/78] Installing py37-soupsieve-2.0.1...
[56/78] Extracting py37-soupsieve-2.0.1: .......... done
[57/78] Installing py37-html5lib-1.0.1...
[57/78] Extracting py37-html5lib-1.0.1: .......... done
[58/78] Installing py37-lxml-4.6.2...
[58/78] Extracting py37-lxml-4.6.2: .......... done
[59/78] Upgrading py37-cryptography from 2.6.1 to 2.9.2...
[59/78] Extracting py37-cryptography-2.9.2: .......... done
[60/78] Upgrading socat from to
[60/78] Extracting socat- ......... done
[61/78] Installing py37-markupsafe-1.1.1_1...
[61/78] Extracting py37-markupsafe-1.1.1_1: .......... done
[62/78] Upgrading bind-tools from 9.16.7 to 9.16.10...
[62/78] Extracting bind-tools-9.16.10: .......... done
[63/78] Installing py37-beautifulsoup-4.9.3...
[63/78] Extracting py37-beautifulsoup-4.9.3: .......... done
[64/78] Upgrading py37-openssl from 19.0.0 to 19.1.0...
[64/78] Extracting py37-openssl-19.1.0: .......... done
[65/78] Upgrading py37-dns-lexicon from 3.3.28 to 3.5.0...
[65/78] Extracting py37-dns-lexicon-3.5.0: .......... done
[66/78] Upgrading py37-Jinja2 from 2.11.2 to 2.11.2_1...
[66/78] Extracting py37-Jinja2-2.11.2_1: .......... done
[67/78] Upgrading haproxy20 from 2.0.18 to 2.0.20...
[67/78] Extracting haproxy20-2.0.20: ........ done
[68/78] Upgrading acme.sh from 2.8.7 to 2.8.8...
===> Creating groups.
Using existing group 'acme'.
===> Creating users
Using existing user 'acme'.
===> Creating homedir(s)
[68/78] Extracting acme.sh-2.8.8: .......... done
[69/78] Installing syslog-ng-3.30.1_1...
[69/78] Extracting syslog-ng-3.30.1_1: .......... done
[70/78] Installing iftop-1.0.p4...
[70/78] Extracting iftop-1.0.p4: ..... done
[71/78] Upgrading py37-urllib3 from 1.25.10,1 to 1.25.11,1...
[71/78] Extracting py37-urllib3-1.25.11,1: .......... done
[72/78] Upgrading perl5 from 5.32.0 to 5.32.0_1...
[72/78] Extracting perl5-5.32.0_1: .......... done
[73/78] Upgrading krb5 from 1.18.2 to 1.18.3...
[73/78] Extracting krb5-1.18.3: .......... done
[74/78] Upgrading py37-pytz from 2020.1,1 to 2020.5,1...
[74/78] Extracting py37-pytz-2020.5,1: .......... done
[75/78] Upgrading os-haproxy from 2.25 to 2.26...
[75/78] Extracting os-haproxy-2.26: .......... done
Stopping configd...done
Starting configd.
Keep version OPNsense\HAProxy\HAProxy (2.10.0)
Reloading plugin configuration
Configuring system logging...done.
Reloading template OPNsense/HAProxy: OK
Reloading template OPNsense/Syslog: OK
[76/78] Upgrading os-acme-client from 1.36 to 2.2...
[76/78] Extracting os-acme-client-2.2: .......... done
Stopping configd...done
Starting configd.
Migrated OPNsense\AcmeClient\AcmeClient from 1.6.2 to 2.0.0
Reloading plugin configuration
Configuring system logging...done.
Reloading template OPNsense/AcmeClient: OK
[77/78] Upgrading opnsense from 20.7.4 to 20.7.8_4...
[77/78] Extracting opnsense-20.7.8_4: .......... done
Stopping configd...done
Resetting root shell
Updating /etc/shells
Unhooking from /etc/rc
Unhooking from /etc/rc.shutdown
Updating /etc/shells
Registering root shell
Hooking into /etc/rc
Hooking into /etc/rc.shutdown
Starting configd.
Keep version OPNsense\Monit\Monit (1.0.8)
Keep version OPNsense\Firewall\Alias (1.0.0)
Keep version OPNsense\OpenVPN\Export (0.0.1)
Keep version OPNsense\CaptivePortal\CaptivePortal (1.0.0)
Keep version OPNsense\Cron\Cron (1.0.2)
Keep version OPNsense\Backup\NextcloudSettings (1.0.0)
Keep version OPNsense\TrafficShaper\TrafficShaper (1.0.3)
Keep version OPNsense\Syslog\Syslog (1.0.0)
Keep version OPNsense\IDS\IDS (1.0.5)
Migrated OPNsense\Proxy\Proxy from 1.0.3 to 1.0.4
Keep version OPNsense\Diagnostics\Netflow (1.0.1)
Migrated OPNsense\Routes\Route from 0.0.0 to 1.0.0
Keep version OPNsense\IPsec\IPsec (0.0.0)
Migrated OPNsense\Interfaces\VxLan from 0.0.0 to 1.0.1
Migrated OPNsense\Interfaces\Loopback from 0.0.0 to 1.0.0
Keep version OPNsense\Unboundplus\Miscellaneous (0.0.2)
Keep version OPNsense\Unboundplus\Dnsbl (0.0.1)
Keep version OPNsense\HAProxy\HAProxy (2.10.0)
Keep version OPNsense\AcmeClient\AcmeClient (2.0.0)
Writing firmware setting...done.
Writing trust files...done.
Configuring login behaviour...done.
Configuring system logging...done.
[78/78] Upgrading nano from 5.2 to 5.4...
[78/78] Extracting nano-5.4: .......... done
You may need to manually remove /usr/local/etc/php-fpm.d/www.conf if it is no longer needed.
You may need to manually remove /usr/local/etc/suricata/classification.config if it is no longer needed.
You may need to manually remove /usr/local/etc/suricata/suricata.yaml if it is no longer needed.
You may need to manually remove /usr/local/etc/syslog-ng.conf if it is no longer needed.
Message from syslog-ng-3.30.1_1:

syslog-ng is now installed!  To replace FreeBSD's standard syslogd
(/usr/sbin/syslogd), complete these steps:

1. Create a configuration file named /usr/local/etc/syslog-ng.conf
   (a sample named syslog-ng.conf.sample has been included in
   /usr/local/etc). Note that this is a change in 2.0.2
   version, previous ones put the config file in
   /usr/local/etc/syslog-ng/syslog-ng.conf, so if this is an update
   move that file in the right place

2. Configure syslog-ng to start automatically by adding the following
   to /etc/rc.conf:


3. Prevent the standard FreeBSD syslogd from starting automatically by
   adding a line to the end of your /etc/rc.conf file that reads:


4. Shut down the standard FreeBSD syslogd:

     kill `cat /var/run/syslog.pid`

5. Start syslog-ng:

     /usr/local/etc/rc.d/syslog-ng start
Message from py37-urllib3-1.25.11,1:

Since version 1.25 HTTPS connections are now verified by default which is done
via "cert_reqs = 'CERT_REQUIRED'".  While certificate verification can be
disabled via "cert_reqs = 'CERT_NONE'", it's highly recommended to leave it on.

Various consumers of net/py-urllib3 already have implemented routines that
either explicitly enable or disable HTTPS certificate verification (e.g. via
configuration settings, CLI arguments, etc.).

Yet it may happen that there are still some consumers which don't explicitly
enable/disable certificate verification for HTTPS connections which could then
lead to errors (as is often the case with self-signed certificates).

In case of an error one should try first to temporarily disable certificate
verification of the problematic urllib3 consumer to see if that approach will
remedy the issue.
Message from opnsense-20.7.8_4:

The lion sleeps tonight
Checking integrity... done (0 conflicting)
Deinstallation has been requested for the following 2 packages:

Installed packages to be REMOVED:
   py37-asn1crypto: 1.3.0
   rate: 0.9_2

Number of packages to be removed: 2

The operation will free 1 MiB.
[1/2] Deinstalling py37-asn1crypto-1.3.0...
[1/2] Deleting files for py37-asn1crypto-1.3.0: .......... done
[2/2] Deinstalling rate-0.9_2...
[2/2] Deleting files for rate-0.9_2: ..... done
The following package files will be deleted:

internet went back online but i cant access the webgui


i sucessfully logged in via ssh, went to shell and entered "configctl webgui restart renew". it said "ok" but didnt change the problem.

the ssh console says: "OPNsense 20.7.8_4" (i noticed that the webgui updated to 20.7.8).

[EDIT] - solved

"opnsense-revert -r 20.7.6 lighttpd && configctl webgui restart" worked.

after i did the 21.1 upgrade (again?) i got the same problem but the "configctl webgui restart renew" then worked (since it was first introduced in this update and couldnt work on 20.7.8).

sorry i'm dumb. can be closed / deleted.
Title: Re: webif update to 21.1 stuck
Post by: franco on February 03, 2021, 09:44:41 am
Hi killtux,

No worries. Lighttpd has caused quite the fuzz with its latest releases and the workarounds aren't all that obvious although we tried to provide them where we could like the console-based certificate renew to unbreak...
