[admin@OPNsense ~]$ fetch -o mimugmail.conf https://www.routerperformance.net/mimugmail.confCertificate verification failed for /O=Digital Signature Trust Co./CN=DST Root CA X35843273977856:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1915:fetch: https://www.routerperformance.net/mimugmail.conf: Authentication error
[admin@OPNsense ~]# fetch -o mimugmail.conf https://www.routerperformance.net/mimugmail.confCertificate verification failed for /C=US/O=Internet Security Research Group/CN=ISRG Root X1898400673792:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1915:fetch: https://www.routerperformance.net/mimugmail.conf: Authentication error
CONNECTED(00000003)depth=3 O = Digital Signature Trust Co., CN = DST Root CA X3verify error:num=10:certificate has expirednotAfter=Sep 30 14:01:15 2021 GMTverify return:1depth=3 O = Digital Signature Trust Co., CN = DST Root CA X3notAfter=Sep 30 14:01:15 2021 GMTverify return:1depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1notAfter=Sep 30 18:14:03 2024 GMTverify return:1depth=1 C = US, O = Let's Encrypt, CN = R3notAfter=Sep 15 16:00:00 2025 GMTverify return:1depth=0 CN = unicast.censurfridns.dknotAfter=Nov 18 18:38:31 2021 GMTverify return:1---Certificate chain 0 s:CN = unicast.censurfridns.dk i:C = US, O = Let's Encrypt, CN = R3 1 s:C = US, O = Let's Encrypt, CN = R3 i:C = US, O = Internet Security Research Group, CN = ISRG Root X1 2 s:C = US, O = Internet Security Research Group, CN = ISRG Root X1 i:O = Digital Signature Trust Co., CN = DST Root CA X3---Server certificate...subject=CN = unicast.censurfridns.dkissuer=C = US, O = Let's Encrypt, CN = R3---No client certificate CA names sentPeer signing digest: SHA384Peer signature type: ECDSAServer Temp Key: X25519, 253 bits---SSL handshake has read 4404 bytes and written 409 bytesVerification error: certificate has expired...
***GOT REQUEST TO CHECK FOR UPDATES***Currently running OPNsense 21.7.2_1 (amd64/OpenSSL) at Thu Sep 30 12:40:03 CDT 2021Fetching changelog information, please wait... Certificate verification failed for /O=Digital Signature Trust Co./CN=DST Root CA X34703086047232:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1915:fetch: https://pkg.opnsense.org/FreeBSD:12:amd64/21.7/sets/changelog.txz.sig: Authentication errorUpdating OPNsense repository catalogue...Certificate verification failed for /O=Digital Signature Trust Co./CN=DST Root CA X31578206494720:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1915:Certificate verification failed for /O=Digital Signature Trust Co./CN=DST Root CA X3
let me guess..added cross-signed ISRG Root X1 cert to Trusted?)
Quote from: Fright on September 30, 2021, 07:46:59 pmlet me guess..added cross-signed ISRG Root X1 cert to Trusted?)Kind of. I did delete the old DST Root CA X3 (called R3 (Let's Encrypt) from Trusted and recreated all the certificates.This then seems to have added the ISRG Root X1 (called R3 (ACME Client). I removed this and recreated all of them again. This solved the issues.I can update from mirrors with LE certs, DoT is working again with uncensoreddns.org and the openssl s_client also verifies the LE certs again.ThanksKH
If you do not use the ACME client plug-in, the first two steps might be sufficient.