Fixing The OPNsense Package Manager Part 2
Posted September 3, 2022
By Kevin Schwickrath1 min read
This post is a continuation of my post, Fixing The OPNsense Package Manager. This issue still bothered me, and I never did sort out the underlying cause. However, everything with all the affected instances continued working fine and updating, except one. Maybe I did something different on this instance because of the previous update issues?
My latest issues began as I started the update to 22.7.3_2. My problem instance threw the error Could not authenticate the selected mirror.
Changing the mirror and rebooting, I was greeted with all new errors:
***GOT REQUEST TO AUDIT CONNECTIVITY***Currently running OPNsense 22.7.2 (amd64/OpenSSL)Checking connectivity for host: pkg.opnsense.org -> 89.149.211.205PING 89.149.211.205 (89.149.211.205): 1500 data bytes1508 bytes from 89.149.211.205: icmp_seq=0 ttl=51 time=146.094 ms1508 bytes from 89.149.211.205: icmp_seq=1 ttl=51 time=145.938 ms1508 bytes from 89.149.211.205: icmp_seq=2 ttl=51 time=146.013 ms1508 bytes from 89.149.211.205: icmp_seq=3 ttl=51 time=146.115 ms
--- 89.149.211.205 ping statistics ---4 packets transmitted, 4 packets received, 0.0% packet lossround-trip min/avg/max/stddev = 145.938/146.040/146.115/0.070 msChecking connectivity for repository (IPv4): https://pkg.opnsense.org/FreeBSD:13:amd64/22.7Updating OPNsense repository catalogue...pkg: https://pkg.opnsense.org/FreeBSD:13:amd64/22.7/latest/meta.txz: Authentication errorrepository OPNsense has no meta file, using default settingspkg: https://pkg.opnsense.org/FreeBSD:13:amd64/22.7/latest/packagesite.pkg: Authentication errorpkg: https://pkg.opnsense.org/FreeBSD:13:amd64/22.7/latest/packagesite.txz: Authentication errorUnable to update repository OPNsenseError updating repositories!Checking connectivity for host: pkg.opnsense.org -> 2001:1af8:4f00:a005:5::ping: UDP connect: No route to hostChecking connectivity for repository (IPv6): https://pkg.opnsense.org/FreeBSD:13:amd64/22.7Updating OPNsense repository catalogue...pkg: https://pkg.opnsense.org/FreeBSD:13:amd64/22.7/latest/meta.txz: Non-recoverable resolver failurerepository OPNsense has no meta file, using default settingspkg: https://pkg.opnsense.org/FreeBSD:13:amd64/22.7/latest/packagesite.pkg: Non-recoverable resolver failurepkg: https://pkg.opnsense.org/FreeBSD:13:amd64/22.7/latest/packagesite.txz: Non-recoverable resolver failureUnable to update repository OPNsenseError updating repositories!***DONE***I have never experienced a problem with updating OPNsense like this before. I likely did something to induce it, so I set out to roll back anything I changed. Knowing I had a thoroughly tested and working backup, I started fiddling around and only made things worse until I got this error:
***GOT REQUEST TO CHECK FOR UPDATES***Currently running OPNsense 22.7.2 (amd64/OpenSSL)Fetching changelog information, please wait... Missing /usr/local/etc/pkg/repos/OPNsense.confAt this point, I knew I had pushed too many buttons.
Running audits revealed:
***GOT REQUEST TO AUDIT CONNECTIVITY***Currently running OPNsense 22.7.2 (amd64/OpenSSL)No IPv4 address could be found for host:No IPv6 address could be found for host:***DONE***and
***GOT REQUEST TO AUDIT HEALTH***Currently running OPNsense 22.7.2 (amd64/OpenSSL)>>> Check installed kernel versionVersion 22.7.2 is correct.Unverified consistency check for kernel: invalid /usr/local/opnsense/version/kernel.mtree.sig>>> Check for missing or altered kernel filesNo problems detected.>>> Check installed base versionVersion 22.7.2 is correct.Unverified consistency check for base: invalid /usr/local/opnsense/version/base.mtree.sig~~~~~~~~~~~~~~~~~~~~>>> Check for missing package dependenciesChecking all packages: .......... donepy37-markupsafe has a missing dependency: python37py37-markupsafe has a missing dependency: py37-setuptoolspy37-markupsafe is missing a required shared library: libpython3.7m.so.1.0>>> Check for missing or altered package filesChecking all packages: ....opnsense-22.7.2: missing file /usr/local/etc/pkg/fingerprints/OPNsense/revoked/pkg.opnsense.org.~~~~~~~~~~~~~~~~~~~~opnsense-22.7.2: missing file /usr/local/etc/pkg/fingerprints/OPNsense/trusted/pkg.opnsense.org.opnsense-22.7.2: missing file /usr/local/etc/pkg/repos/FreeBSD.conf.sampleopnsense-22.7.2: missing file /usr/local/etc/pkg/repos/OPNsense.conf.sampleChecking all packages......... done>>> Check for core packages consistency~~~~~~~~~~~~~~~~~~~~We are missing some things. I came across a post mentioning the opnsense-bootstrap tool. The opnsense-bootstrap will completely reinstall a running system in place while also automatically picking up the latest available version.
Run this as root within the local console (not ssh). Change the version 22.7 to your target version.
pkg install ca_root_nssfetch https://raw.githubusercontent.com/opnsense/update/master/src/bootstrap/opnsense-bootstrap.sh.insh ./opnsense-bootstrap.sh.in -r 22.7When the script completed repairs, it automatically rebooted the system. A few plugins were missing. Since this is mostly a default installation now that is to be expected. , I installed the missing plugins and rebooted the system once more and we were operational.
This resolved all the issues and updated my installation to the latest version. These tools are going straight into the toolbox.
Happy Routing!
This post is licensed under CC BY 4.0 by the author.
Related Posts
Fixing The OPNsense Package Manager
I recently had a very unusually rough time updating OPNsense. I use OPNsense as a backup backdoor management VPN server at various data centers. Two…