Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - SchengFui

#1
26.1, 26,4 Series / Re: nginx plugin missing
April 23, 2026, 04:50:15 PM
omg, this is so embarasssing...

thank you very much
#2
26.1, 26,4 Series / nginx plugin missing
April 23, 2026, 04:07:43 PM
Hi there,

i'm unable to find the nginx (or any possibly related plugin) in System: Firmware: Plugins

OPNSense 26.1.6 or 25.7.11_9, both checked.

What am i missing?

thank you in advance

#3
Problem solved...

in Addition to OpenVPN there was Wireguard configured, but with disabled peer (Instance was left enabled).

After disableing the Instance too, Firmwarecheck via Management started working again.

Strange behaviour in my opinion...
#4
yes, as written in my original Post: "Current date/time is correct and synced with NTP-Server. Timezone is also correct."
#5
Hi there,

the Date in System:Log Files:General Date is wrong (in the Future):

2026-04-25T02:53:20Noticekernel<118>[33] 99 66 49 25 E0 F0 9C 40 D5 C9 6E 36 AE FD 80 07
2026-04-25T02:53:20Noticekernel<118>[33] HTTPS: SHA256 7E 2E F7 CA 7B 87 66 66 D1 27 FB 2C 0F AF E7 06
2026-04-25T02:53:20Noticekernel<118>[33]
2026-04-25T02:53:20Noticekernel<118>[33] WAN (hn1) -> v4: 83.246.106.210/29
2026-04-25T02:53:20Noticekernel<118> LAN (hn0) -> v4: 172.17.101.1/24
2026-04-25T02:53:20Noticekernel<118>[33]
2026-04-25T02:53:20Noticekernel<118>*** OPNsenseLGPUG1.lgpug.intern: OPNsense 25.10.2 (amd64) ***
2026-04-25T02:53:20Noticekernel<118>[33]
2026-04-25T02:53:20Noticekernel<118>[33] Sat Apr 25 02:53:19 CEST 2026
2026-04-25T02:53:20Noticekernel<118>[33] Root file system: /dev/gpt/rootfs
2026-04-25T02:53:18Warningopnsense-business/usr/local/etc/rc.newwanip: Interface '' (ovpns44) is disabled or empty, nothing to do.
2026-04-25T02:53:18Warningopnsense-business/usr/local/etc/rc.newwanip: Interface '' (ovpns42) is disabled or empty, nothing to do.
2026-04-25T02:53:18Noticekernel<6>[31] ovpns44: link state changed to UP
2026-04-25T02:53:18Noticekernel<6>[31] ovpns42: link state changed to UP
2026-04-25T02:53:18Noticekernel<118>[31] >>> Invoking start script 'beep'

Connected since in VPN:OpenVPN:Connection Status shows the same wrong date.

I have no Idea why, Current date/time is correct and synced with NTP-Server. Timezone is also correct.

Any helpful thoughts?

Than you,
 SchengFui
#6
Hi There,

after Update from Version 25.7.11_9 to 26.1.5 Firmwarecheck via Management no longer works.

A new API-key has been generated without any effect.

Firmware-Check on other, not updated OPNSense works as expected.

Maybe it is VPN-related, the affected OPNSenses are connected via OpenVPN Site-to-Site.

Any ideas where to look next?

Thank you,
 SchengFui
#7
Hi Franco,

i purged 2 lists, now System: Firmware: Updates is showing 73 pending updates...

I think ist working again.

Thank you very much!

Kind regards;
 SchengFui
#8
no, still not working:

Log from just now:
***GOT REQUEST TO CHECK FOR UPDATES***
Currently running OPNsense 25.4.1 (amd64) at Mon Aug 18 14:09:42 CEST 2025
Strict TLS 1.3 and CRL checking is enabled.
Fetching subscription information, please wait... Certificate verification failed for /CN=opnsense-update.deciso.com (12)
00206177F6400000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
fetch: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/subscription: Authentication error
Fetching changelog information, please wait... Certificate verification failed for /CN=opnsense-update.deciso.com (12)
00206187D3370000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
fetch: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/sets/changelog.txz: Authentication error
Updating OPNsense repository catalogue...
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
pkg: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/latest/meta.txz: Authentication error
repository OPNsense has no meta file, using default settings
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
pkg: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/latest/packagesite.pkg: Authentication error
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002081C0571A0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
pkg: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/latest/packagesite.txz: Authentication error
Unable to update repository OPNsense
Error updating repositories!
Checking integrity... done (0 conflicting)
Your packages are up to date.
***DONE***
#9
Hi there,

OPNSense search for Updates fails with Certificate verification failed.

Last successfull Update was on Tue Aug 5 21:15:40 CEST 2025 (25.4.1)

Date and Time is correct, IPV6 is disabled.

Audit Conenctivity Log:
***GOT REQUEST TO AUDIT CONNECTIVITY***
Currently running OPNsense 25.4.1 (amd64) at Mon Aug 18 08:48:05 CEST 2025
Strict TLS 1.3 and CRL checking is enabled.
Checking connectivity for host: opnsense-update.deciso.com -> 89.149.211.205
PING 89.149.211.205 (89.149.211.205): 1500 data bytes
1508 bytes from 89.149.211.205: icmp_seq=0 ttl=58 time=13.925 ms
1508 bytes from 89.149.211.205: icmp_seq=1 ttl=58 time=13.682 ms
1508 bytes from 89.149.211.205: icmp_seq=2 ttl=58 time=13.605 ms
1508 bytes from 89.149.211.205: icmp_seq=3 ttl=58 time=13.734 ms

--- 89.149.211.205 ping statistics ---
4 packets transmitted, 4 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 13.605/13.737/13.925/0.118 ms
Checking connectivity for repository (IPv4): https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4
Updating OPNsense repository catalogue...
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
pkg: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/latest/meta.txz: Authentication error
repository OPNsense has no meta file, using default settings
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
pkg: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/latest/packagesite.pkg: Authentication error
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /CN=opnsense-update.deciso.com (12)
002061CDEB140000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
pkg: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/latest/packagesite.txz: Authentication error
Unable to update repository OPNsense
Error updating repositories!
Checking connectivity for host: opnsense-update.deciso.com -> 2001:1af8:4f00:a005:5::
ping: UDP connect: No route to host
Checking connectivity for repository (IPv6): https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4
Updating OPNsense repository catalogue...
pkg: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/latest/meta.txz: Non-recoverable resolver failure
repository OPNsense has no meta file, using default settings
pkg: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/latest/packagesite.pkg: Non-recoverable resolver failure
pkg: https://opnsense-update.deciso.com/${SUBSCRIPTION}/FreeBSD:14:amd64/25.4/latest/packagesite.txz: Non-recoverable resolver failure
Unable to update repository OPNsense
Error updating repositories!
Checking server certificate for host: opnsense-update.deciso.com
depth=2 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root G3
verify return:1
depth=1 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = RapidSSL TLS ECC CA G1
verify return:1
depth=0 CN = opnsense-update.deciso.com
verify return:1
DONE
***DONE***

Any Ideas?

Thank you in advance for any help!

Kind regards,
 SchengFui
#10
maybe i should download an the delete the backups and see what happens with newly created Backups...

thx,
SchengFui
#11
Hi there,

when comparing Backups, Date and Time is wrong (in the future):
You cannot view this attachment.

Date and time config seems correct:
You cannot view this attachment.

System was recently switched from 25.1 Community Edition to 25.4 Business Edition.

Any Ideas how to fix this?

Thank you in advance,
SchengFui
#12
Problem gelöst, der Fehler lag in den Client Specific Overrides
#13
Hi again,

finally i got my OpenVPN instances working, Problem was related to Client Specific Overrides.

You may want to double-check your Overwrite(s) under VPN: OpenVPN: Client Specific Overrides
#14
Hi,

exact same Problem here for OpenVPN...

OPNsense 25.1.7_4, OpenVPN configured as Instance, Tunnel is up but no traffic goes through.

When Tunnel is set up as Client/Server (Legacy) everything works.

On the other hand i have a working connection (not legacy) with IPSEC and an Netgate Firewall with Software 2.7x (not under my control, managed by someone else), so maybe your Problem is related to your Mikrotik Router...
#15
because in my curront configuration the tunnel does not route traffic and for testing purposes i want to bind to a specific interface to sort things out