Recent posts

#1
Excellent to hear, I'm in no hurry. Let's see what happens :)
#2
26.7 Series / ACME Client Issues
Last post by madj42 - Today at 07:07:08 PM
I've been having ACME client issues for a few releases now.  It was working years ago but for some reason stopped.  The certificates are generated and stored to the disk but for some reason they are not imported into the trust store.  I have also reinstalled my firewall and imported the configuration during this to see if it fixes the issue, it didn't.  What is weird is that I get the does not contain 'dns' message at the end when things stop.  Trying to get a second set of eyes on this as I'm lost.  Thank you in advance.


2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] '' does not contain 'dns'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _on_issue_success
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 24:Le_InstallCertSuccessTimeStr='2026-08-21T16:56:41Z'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 23:Le_InstallCertSuccessTime='1787331401'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Installing full chain to: /var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/fullchain.pem
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Installing key to: /var/etc/acme-client/keys/xxxxxxxxxx.xxxxx/private.key
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Installing CA to: /var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/chain.pem
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Installing cert to: /var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/cert.pem
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 22:Le_RealFullChainPath='/var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/fullchain.pem'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 21:Le_ReloadCmd=''
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 20:Le_RealKeyPath='/var/etc/acme-client/keys/xxxxxxxxxx.xxxxx/private.key'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 19:Le_RealCACertPath='/var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/chain.pem'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 18:Le_RealCertPath='/var/etc/acme-client/certs/xxxxxxxxxx.xxxxx/cert.pem'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 17:Le_NextRenewTime='1792558083'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 16:Le_NextRenewTimeStr='2026-10-21T04:48:03Z'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Next renewal time picked from ARI window: 2026-10-21T04:48:03Z
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] ARI suggestedWindow: 2026-10-19T18:42:12Z to 2026-10-21T13:53:02Z
}'
}
"end": "2026-10-21T13:53:02Z"
"start": "2026-10-19T18:42:12Z",
"suggestedWindow": {
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _ari_resp_new='{
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] ret='0'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _CURL='curl --silent --dump-header /var/etc/acme-client/home/http.header -L --trace-ascii /tmp/tmp.JIfWAgIcfd -g '
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Http already initialized.
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] timeout=
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] url='https://acme-v02.api.letsencrypt.org/acme/renewal-info/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx';
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] GET
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _serurl='BcZbS5XH9xxRHR3c2MPguL6HxZ'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _URGLY_PRINTF='1'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] base64 single line.
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] xxd exists=127
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _akiurl='QBUtJnntMiCe35pyHdYyH4EMgQw'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _URGLY_PRINTF='1'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] xxd exists=127
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] base64 single line.
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _ser='05C65B4B95C7X511D1XXCD8C3E0B8BE87C59'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _aki='40152D2679EDX2209EXX9A721DD6321F810C810C'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 15:Le_RenewalDays='60'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 14:Le_CertCreateTimeStr='2026-08-21T16:56:41Z'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 13:Le_CertCreateTime='1787331401'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] And the full-chain cert is in: /var/etc/acme-client/cert-home/xxxxxxxxxx.xxxxx/test2.xxxxxx.xxx/fullchain.cer
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] The intermediate CA cert is in: /var/etc/acme-client/cert-home/xxxxxxxxxx.xxxxx/test2.xxxxxx.xxx/ca.cer
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 6:USER_PATH='/sbin:/bin:/usr/sbin:/usr/bin:/usr/games:/usr/local/sbin:/usr/local/bin'
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Your cert key is in: /var/etc/acme-client/cert-home/xxxxxxxxxx.xxxxx/test2.xxxxxx.xxx/test2.xxxxxx.xxx.key
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Your cert is in: /var/etc/acme-client/cert-home/xxxxxxxxxx.xxxxx/test2.xxxxxx.xxx/test2.xxxxxx.xxx.cer
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Cert success.
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] 12:Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/xxxxxxxxxxxxxxxxx';
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] APP
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] Le_LinkCert='https://acme-v02.api.letsencrypt.org/acme/cert/xxxxxxxxxxxxxxxxxxx';
2026-08-21T11:56:41-05:00acme.sh[Fri Aug 21 11:56:41 CDT 2026] _end_n='34'
2026-08-21T11:56:40-05:00acme.sh[Fri Aug 21 11:56:40 CDT 2026] Found cert chain
#3
26.7 Series / OPNsense 26.7.2_2 Paket Captur...
Last post by Meg - Today at 05:43:38 PM
Hello: I was trying to troubleshoot NTP update on my DDWRT wireless access point with opnsense packet capture. I tried using several different filters such as UDP Port 123 and the routers local ip address on packet capture. My DDWRT logs showed NTP request being sent and successfully updated but packet capture showed no packets. I tried leaving IP blank with UDP and Port 123, then only UDP, then only Port 123. I tried every possible combination and nothing was captured from the ddwrt device. Request when IP left blank were captured from other devices on my network but not the DDWRT access point. Only when putting the DDWRT access point MAC address in did it capture the NTP request from the AP. Can anyone explain this behavior and why it wouldn't capture when all relavant filters were in place using IP address and not Mac address or even with no filters at all.
#4
German - Deutsch / Re: Zentrale Verwaltung mehrer...
Last post by Tuxtom007 - Today at 05:14:02 PM
Quote from: trixter on Today at 08:58:10 AMVielleicht macht es mehr Sinn zu versuchen sich am eigentlichen Projekt zu beteiligen?
Sehe ich auch so, weil ich sehe kein Zielgruppe dafür.

Die Leute, die eine OPNSense im Geschäftsumfeld einsetzen, werden eh die BE nehmen und haben dann
bei Bedarf Opencentral inkl., da würde ich mich nicht auf eine Produkt eine Single-Mann Show
stürzen ( keine Kritik, aber ich erlebe immer, was da raus wird )
#5
26.7 Series / Re: Log rate limiting - any be...
Last post by meyergru - Today at 04:55:27 PM
Yes, actually your impression is correct. The limited rate after the duplicated rules obviously was limited to 9 log entries per second, because I originally had 9 rules and imposed an 1/1 limit on them. I just want to see indications as to what is happening in the logs. I still can look at the counters if I want to see how many requests come in.

I cannot say for sure how many requests per second were there at the time of attack and I also think many may have been dropped because the storage could not keep up. It is a 1 Gbps connection, but with just port probing, that may still amount to a few thousand requests per second, each of which has a significant log impact. I cannot really say what has happened, because obviously the filterlog process was out for several hours (there is also a gap into log file history on one day), such that not even remote logging shows anything. As a matter-of-fact IDK if the CPU load was only a side effect.

Logging for default deny is off here.

#6
26.7 Series / Re: Unbound stopps suddenly
Last post by _Mike - Today at 04:39:11 PM
Not sure if this is related or a different issue, but for me Unbound is crashing after rebooting OPNsense.  It seems to happen with about 50% of reboots.  Unbound starts running for a minute or so and then crashes.  It works after I manually restart the service.  I'm on 26.7.2.
#7
26.7 Series / Re: Log rate limiting - any be...
Last post by Monviech (Cedrik) - Today at 04:32:49 PM
Thats a good idea. Disable logging for default deny and create your own single default deny with rate limiting. When it falls through the logging ends.

But ofc that doesnt include allowed traffic.

And you might miss interesting info in the logs.
#8
Zenarmor (Sensei) / Re: OPNsense 26.7 Kernel Panic...
Last post by Seimus - Today at 04:26:50 PM
Oh thats nasty...

Thanks for providing the official ticket!

Regards,
S.
#9
26.7 Series / Re: Log rate limiting - any be...
Last post by Seimus - Today at 04:24:37 PM
Quote from: meyergru on Today at 02:46:56 PM2. Would there be a way to have the desired behavior for block rules (i.e. "rate-limit logging without affecting rule matching"), probably as a feature request for OpnSense?
3. Should there be a more prominent web UI warning about this "unexpected" behaviour for block rules?

I think this is more for a feature request.
But its bothersome that the DDOS came actually within when you think about it. A DDOS attack was prevented by block rules yet it was so huge that a feedback loop via logging happened that caused practically a DDOS caused by the logging rules.

So the only feasible way, is to disable logging for block rules?

Regards,
S.
#10
Zenarmor (Sensei) / Re: OPNsense 26.7 Kernel Panic...
Last post by sy - Today at 04:19:09 PM
Hi everyone,

Good news for those experiencing this exact kernel panic on OPNsense 26.7:

The root cause—a race condition in generic_mbuf_dtor() during Netmap generic adapter teardown (generic_netmap_dtor)— officially addressed by the OPNsense core team.

You can track the issue, patch status, and upcoming fixes directly on GitHub here:

👉 https://github.com/opnsense/src/issues/314

Thanks to the OPNsense team!