$ curl -k https://fw.domain.tld/curl: (56) OpenSSL SSL_read: error:14094438:SSL routines:ssl3_read_bytes:tlsv1 alert internal error, errno 0
root@fw:/var/log # opnsense-revert -r 21.1.3 opensslFetching openssl.txz: .... doneVerifying signature with trusted certificate pkg.opnsense.org.20210104... doneopenssl-1.1.1k,1: already unlockedUpdating OPNsense repository catalogue...OPNsense repository is up to date.All repositories are up to date.Checking integrity... done (0 conflicting)The following 1 package(s) will be affected (of 0 checked):New packages to be INSTALLED: openssl: 1.1.1j_1,1Number of packages to be installed: 1The process will require 14 MiB more space.[1/1] Installing openssl-1.1.1j_1,1...Extracting openssl-1.1.1j_1,1: 100%root@fw:/var/log # configctl webgui restartOKroot@fw:/var/log #
$ curl -k https://fw.domain.tld/<!doctype html>[...]
firefox : SSL_ERROR_RX_RECORD_TOO_LONG
curl: (35) error: 1408F10B: SSL routines: ssl3_get_record: wrong version number
PS: does this work too?# devfs rule apply path crypto hide# configctl webgui restart
root@iefw01:/var/log # opnsense-revert -r 21.1.4 opensslFetching openssl.txz: ... doneVerifying signature with trusted certificate pkg.opnsense.org.20210104... doneopenssl-1.1.1j_1,1: already unlockedUpdating OPNsense repository catalogue...OPNsense repository is up to date.All repositories are up to date.Checking integrity... done (0 conflicting)The following 1 package(s) will be affected (of 0 checked):New packages to be INSTALLED: openssl: 1.1.1k,1Number of packages to be installed: 1The process will require 14 MiB more space.[1/1] Installing openssl-1.1.1k,1...Extracting openssl-1.1.1k,1: 100%root@iefw01:/var/log # configctl webgui restartOKroot@iefw01:/var/log # devfs rule apply path crypto hideroot@iefw01:/var/log # configctl webgui restartOKroot@iefw01:/var/log #
$ curl -k https://fw/ | head -n1 % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed100 2952 100 2952 0 0 38337 0 --:--:-- --:--:-- --:--:-- 38337<!doctype html>
# devfs rule apply path crypto hide# opnsense-revert openssl# configctl webgui restart
# devfs rule apply path crypto hide# configctl webgui restart
Thanks all so far. The following package should work:# pkg add -f https://pkg.opnsense.org/FreeBSD:12:amd64/21.1/misc/openssl-1.1.1k,1.txz
# devfs rule apply path crypto unhide# pkg add -f https://pkg.opnsense.org/FreeBSD:12:amd64/21.1/misc/openssl-1.1.1k,1.txz# configctl webgui restart