Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - madj42

#1
26.7 Series / Re: ACME Client Issues
August 21, 2026, 10:40:42 PM
Forgot to mention, I did this too.  Everything works except the import to be the trust store.  It's like that routine is missing.
#2
26.7 Series / ACME Client Issues
August 21, 2026, 07:07:08 PM
I've been having ACME client issues for a few releases now.  It was working years ago but for some reason stopped.  The certificates are generated and stored to the disk but for some reason they are not imported into the trust store.  I have also reinstalled my firewall and imported the configuration during this to see if it fixes the issue, it didn't.  What is weird is that I get the does not contain 'dns' message at the end when things stop.  Trying to get a second set of eyes on this as I'm lost.  Thank you in advance.


2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] '' does not contain 'dns'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _on_issue_success
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 24:Le_InstallCertSuccessTimeStr='2026-08-21T16:56:41Z'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 23:Le_InstallCertSuccessTime='1787331401'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Installing full chain to: /var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/fullchain.pem
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Installing key to: /var/etc/acme-client/keys/xxxxxxxxxx.xxxxx/private.key
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Installing CA to: /var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/chain.pem
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Installing cert to: /var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/cert.pem
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 22:Le_RealFullChainPath='/var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/fullchain.pem'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 21:Le_ReloadCmd=''
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 20:Le_RealKeyPath='/var/etc/acme-client/keys/xxxxxxxxxx.xxxxx/private.key'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 19:Le_RealCACertPath='/var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/chain.pem'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 18:Le_RealCertPath='/var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/cert.pem'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 17:Le_NextRenewTime='1792558083'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 16:Le_NextRenewTimeStr='2026-10-21T04:48:03Z'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Next renewal time picked from ARI window: 2026-10-21T04:48:03Z
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] ARI suggestedWindow: 2026-10-19T18:42:12Z to 2026-10-21T13:53:02Z
}'
}
"end": "2026-10-21T13:53:02Z"
"start": "2026-10-19T18:42:12Z",
"suggestedWindow": {
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _ari_resp_new='{
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] ret='0'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _CURL='curl --silent --dump-header /var/etc/acme-client/home/http.header -L --trace-ascii /tmp/tmp.JIfWAgIcfd -g '
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Http already initialized.
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] timeout=
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] url='https://acme-v02.api.letsencrypt.org/acme/renewal-info/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx';
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] GET
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _serurl='BcZbS5XH9xxRHR3c2MPguL6HxZ'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _URGLY_PRINTF='1'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] base64 single line.
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] xxd exists=127
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _akiurl='QBUtJnntMiCe35pyHdYyH4EMgQw'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _URGLY_PRINTF='1'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] xxd exists=127
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] base64 single line.
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _ser='05C65B4B95C7X511D1XXCD8C3E0B8BE87C59'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _aki='40152D2679EDX2209EXX9A721DD6321F810C810C'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 15:Le_RenewalDays='60'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 14:Le_CertCreateTimeStr='2026-08-21T16:56:41Z'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 13:Le_CertCreateTime='1787331401'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] And the full-chain cert is in: /var/etc/acme-client/cert-home/xxxxxxxxxx.xxxxx/test2.xxxxxx.xxx/fullchain.cer
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] The intermediate CA cert is in: /var/etc/acme-client/cert-home/xxxxxxxxxx.xxxxx/test2.xxxxxx.xxx/ca.cer
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 6:USER_PATH='/sbin:/bin:/usr/sbin:/usr/bin:/usr/games:/usr/local/sbin:/usr/local/bin'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Your cert key is in: /var/etc/acme-client/cert-home/xxxxxxxxxx.xxxxx/test2.xxxxxx.xxx/test2.xxxxxx.xxx.key
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Your cert is in: /var/etc/acme-client/cert-home/xxxxxxxxxx.xxxxx/test2.xxxxxx.xxx/test2.xxxxxx.xxx.cer
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Cert success.
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 12:Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/xxxxxxxxxxxxxxxxx';
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/xxxxxxxxxxxxxxxxxxx';
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _end_n='34'
2026-08-21T11:56:40-05:00acme.sh[Fri Aug 21 11:56:40 CDT 2026] Found cert chain
#3
26.7 Series / Re: OPNsense 26.7-BETA images
July 09, 2026, 08:12:52 PM
For what it's worth, I upgraded from 26.1.11 to 26.7rc1 last night and had issues . I had to rollback. I just upgraded to rc2 and it worked straight away.
#4
On UDPBroadcastRelay, leave the source and broadcast blank in your config. Set port as 65001.

Create a floating firewall rule and set the following:

Interfaces: select the same interfaces you put in the UDPBR config.
Protocol: UDP
Source: IP of HDR
Source Port: 65001
Dest: Net option for the network your device running the app is on.  Mine was LAN Net.

Good luck.
#5
I was able to downgrade the opnsense package to 25.7.1 to fix my issue until a fix comes out.
#7
Are you using cloudflare DNS?  I had the same issue and it turns out cloudflare had an outage.
#8
Upgraded to the beta.  All is working here so far except for the missing menu button like others reported.  Still testing and will report issues if I find them.
#9
I have this exact card on the latest firmware and I'm able to achieve this link speed with opnsense.   Are you running into issues?
#10
No issues after applying this.  Will run for a few days and report any issues.
#11
Pardon me for asking, when I lookup pfsync, it deals with high availability. Do you have this setup? Reason I ask is that I don't have it setup and I'm trying to determine if I should upgrade and test.  I'd rather wait if it's impacting those without HA too.
#12
Thanks for the info.  I bit the bullet and recreated my groups.  No big deal.
#13
@franco, not sure if you'll see this but I did notice the commit that fixes this issue.  If I upgraded now that it's fixed, would I still encounter this issue?  Just wondering since there won't be a RC2 and I'm itching to try it.
#14
Don't quote me on this but I swear I had the same issue with one of my internal hosts.  I was able to manually clear the block from the CrowdSec console and then identify a solution to the issue for the future.  I used the link below to create a whitelist for my internal LAN ranges.

https://hub.crowdsec.net/author/crowdsecurity/configurations/whitelists

In hindsight it might not have been the best solution as I'd probably want to subject my internal IoT ranges to filtering but still, it's at least might be some sort of starting point for you.
#15
You're blocking all traffic on every port to those IP addresses.  You most likely want to block just 22, 80, and 443 for a destination port.