Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - SchengFui

#1
no, i have two different certificates, one dedicated server-cert, assigned to the instance, and one dedicated client-cert
#2
i'm pretty sure i do it right, because of the fact that choosing the right ca (and not leave it selfsigned) autofills most of the lines under general. i noticed that every time i created a new cert.

i'll ivestigate further. i have both (the working and non-working) installations as VMs.
#3
for testing purposes i created an new ca, created a server and a client cert from this ca and the error occured when trying to export...

maybe i'll investigate further when i find some time, but to be honest i'm not familiar with openssl...
#4
26.7 Series / Re: legacy ipsec settings on 26.7..1_1
August 11, 2026, 08:58:47 AM
hi there,

go to System: Firmware: plugins, Click to view the community plugins.

and install plugin: os-strongswan-legacy   1.0_1   120KiB   3   OPNsense   IPsec legacy support
#5
hi there,

im the guy with the "exporting OpenVPN profiles"-Problem.

FYI: i had to downgrade to 26.1.11_10 to make this working again.
#6
Hi there,

Problem was solved by downgrading to 26.1.11_10, export now works as expected again.
#7
Could someone please help me with the certificate-storage-paths ?

i found the root certs in /usr/local/share/certs, but i have no idea where to look for the leaf certificates.
#8
Quote from: Monviech (Cedrik) on August 06, 2026, 02:00:17 PMIn der shell mal folgendes ausführen

opnsense-bootstrap
das installiert die neueste version
Danke für den Hinweis, der Befehl war mir neu, merke ich mir für später.
#9
so, der Vollständigkeit halber:

nach rm tar und ln -s bsdtar tar ist die Fehlermeldung verschwunden und ich sehe wieder ein changelog.
#10
Quote from: Patrick M. Hausen on August 06, 2026, 02:03:08 PMJemand hat ihn kaputt gemacht.
wer war das? keiner verlässt den Raum...
#11
lutsch mich rund und nenn mich Bärbel...

auf einer anderen OPNSense ergibt ls -l tar:
lrwxr-xr-x  1 root wheel 6 Jul 13 12:49 tar -> bsdtar

und /usr/bin/bsdtar ergibt nun:
bsdtar: Must specify one of -c, -r, -t, -u, -x

da ist doch wohl tatsächlich der Symlink kaputt... wie kann das?
#12
mich beschleicht der Verdacht, dass tar an sich (als Befehl) das Problem ist...

/usr/bin # tar gibt:
tar: Command not found.

ls -l tar ausgeführt in /usr/bin ergibt:
lrwxr-xr-x  1 root wheel 0 May 11 04:07 tar ->

sollte hinter dem -> nicht noch was kommen? Ein Pfad oder so?
#13
unfortunately i am not familiar with openssl in console :-(

and honestly, i dont understand the error-message... the option "Certificate Authority" is set to "-Use from certificate", so how is it possible the the ca does not belong to the certificate? Setting the option "Certificate Authority" to the correct ca for the certificate leads to this error message too. CA and server certificate have been multiple times deleted and newly created (without any errors).

I'm in doubt, that this problem is related to the ca and certificate, but i have no idea where to look now.
   
   
#14
hab ich schon probiert, mehrere sogar, ändert aber nicht.

auch wenn ich ein plugin installiere (das geht) ändert sich nichts.

er scheint irgendwas nicht zu finden, aber die Fehlermeldung (tar: not found) ist für mich zu schwammig um sinnvoll irgendwo zu suchen...

Wenn ich allerdings den Ordner "/usr/local/opnsense/changelog" in changelogalt umbenenne, ändert sich zumindest die Fehlermeldung:

Fetching changelog information, please wait... opnsense-verify: Unable to open /usr/local/opnsense/changelog/changelog.txz: No such file or directory


#15
i think this is normal, they are shown but you cannot edit them.

in the commands-column you can only lookup the rule reference, after migration, you can edit them.