Coder Social home page Coder Social logo

Comments (14)

Smitimus avatar Smitimus commented on September 28, 2024 2

I tried the above options, nothing seemed to work. I found this and compared what I had in the R3 Cert. It was close, but off in a few places. I replaced my R3 cert with the above, and it now works. Hope this helps.

https://forum.opnsense.org/index.php?topic=24950.msg119873#msg119873

from opn-repo.

mimugmail avatar mimugmail commented on September 28, 2024 1

Go on my website and search the folder where you fetched the conf, then remove the file and run pkg update

I will check the cert prob over the weekend

from opn-repo.

burntoc avatar burntoc commented on September 28, 2024

Fair enough. So just so I understand the processs and don't muck things up can you verify the following?
Step 1 - Go to /usr/local/etc/package/repos and delete mimugmail.conf
Step 2 - Do my OPN updates and wireguard-kmod reinstall
Step 3 - Run the fetch from your website again to re-pull the conf.
Step 4 - Reboot.

Sound right and my Adguardhome will retain the current config without requiring additional rework?

from opn-repo.

mimugmail avatar mimugmail commented on September 28, 2024

Can you replace recheck .. I dont get any errors

from opn-repo.

AdMeik avatar AdMeik commented on September 28, 2024

Hi Michael,

I have the same issue, remove the conf, remove the expired CA from System/Trust/Authorities, update OPNsense, re-add the Repository (with --no-verify-peer), but Repository Update still comes with:
Updating mimugmail repository catalogue... Certificate verification failed for /O=Digital Signature Trust Co./CN=DST Root CA X3 229124571136:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify

The https://opn-repo.routerperformance.net looks okay, but OPNsense use old/cached? DST RootCA X3.
How to remove, or recheck, what you mean.

THX

from opn-repo.

mimugmail avatar mimugmail commented on September 28, 2024

System : Trust : Authorities and remove the old one?

from opn-repo.

burntoc avatar burntoc commented on September 28, 2024

from opn-repo.

AdMeik avatar AdMeik commented on September 28, 2024

image
Only this is configured.
Repo looks fine: https://www.sslshopper.com/ssl-checker.html#hostname=opn-repo.routerperformance.net think it's a OPNsense thing.
@burntoc I remove the Repository, to update to Latest OPNsense (21.7.3_3), hope that the update fix it.

from opn-repo.

burntoc avatar burntoc commented on September 28, 2024

from opn-repo.

Smitimus avatar Smitimus commented on September 28, 2024

I am not a security professional... But the way I understand things the CA works as the first level of cert verification and is housed on the client side (which would be you opnsense box). In my case a new CA was present, but just had an inaccurate cert.

That said, I did not add the new CA to my box, and the date on it coresponds with an update I did. So, I am inclined to believe opnsense did this during an update. If so, opnsense sent the wrong CA cert to everyone. I may be way wrong on this, and it may just be me that had this particular issue, I am just trying to piece together what I see.

from opn-repo.

burntoc avatar burntoc commented on September 28, 2024

from opn-repo.

Smitimus avatar Smitimus commented on September 28, 2024

Again, not a security pro.... But certs are 3 parts. Ca, public, and private. Yes everything SHOULD work automatically. But in my case the CA cert was off. The CA is stored in opnsense and not usually updated, likely for security/spoofing reasons. I'm just sharing my experience and hoping it helps the community. Maybe not, who knows. 🤣

from opn-repo.

burntoc avatar burntoc commented on September 28, 2024

from opn-repo.

burntoc avatar burntoc commented on September 28, 2024

I got a reply that this repository has been moved to ZeroSSL to address the client-side CA and OPNsense config issues arising from this. Thought I'd confirm that this has fixed the issue here, with no additional adjustments needed on my part. As the CAs and certs are all valid now, the OPNsense update function completes properly again.

from opn-repo.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.