>>> Executing build step base on 24.7 ABI_FILE=/usr/lib/crt1.o BLOCKSIZE=K CONFIGDIR=/usr/tools/config/24.7 CONFIG_XML=/usr/local/etc/config.xml COREBRANCH=stable/24.7 COREDIR=/usr/core COREENV=CORE_PHP=82 CORE_ABI=24.7 CORE_PYTHON=311 CPUS=8 DEVICEDIR=/usr/tools/device ENV_FILTER=env -i USER=root LOGNAME=root HOME=/root SHELL=/bin/sh BLOCKSIZE=K MAIL= PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin TERM= HOSTTYPE= VENDOR= OSTYPE= MACHTYPE= PWD=/usr/tools/build GROUP= HOST= EDITOR= PAGER= ABI_FILE=/usr/lib/crt1.o EXTRABRANCH= HOME=/root IMAGESDIR=/usr/local/opnsense/build/24.7/amd64/images LANG=C.UTF-8 LOGNAME=root LOGSDIR=/usr/local/opnsense/build/24.7/amd64/logs MAKEFLAGS= PORTSENV=MISMATCH=no SERVER=nightly@pkg.opnsense.org UPLOADDIR=incoming MAKELEVEL=2 META_MODE=normal MM_CHARSET=UTF-8 OLDPWD=/usr/obj/usr/tools PACKAGESDIR=/.pkg PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin PLUGINSBRANCH=stable/24.7 PLUGINSDIR=/usr/plugins PLUGINSENV=PLUGIN_PHP=82 PLUGIN_ABI=24.7 PLUGIN_PYTHON=311 PORTSBRANCH=master PORTSDIR=/usr/ports PORTSENV=MISMATCH=no PORTSREFBRANCH=main PORTSREFDIR=/usr/freebsd-ports PORTSREFURL=https://git.FreeBSD.org/ports.git PRINT_ENV_SKIP=1 PRODUCT_ABI=24.7 PRODUCT_ADDITIONS= PRODUCT_APACHE=24 PRODUCT_ARCH=amd64 PRODUCT_COMSPEED=115200 PRODUCT_CORE=opnsense PRODUCT_CORES=opnsense opnsense-devel opnsense-business PRODUCT_DEBUG= PRODUCT_DEVEL= PRODUCT_DEVICE_REAL=A10 PRODUCT_GITBASE=https://github.com/opnsense PRODUCT_HOST=amd64 PRODUCT_KERNEL=SMP PRODUCT_LUA=5.4 PRODUCT_MIRROR=https://mirror.ams1.nl.leaseweb.net/opnsense PRODUCT_NAME=OPNsense PRODUCT_PERL=5.36 PRODUCT_PHP=82 PRODUCT_PLUGIN=os-* PRODUCT_PLUGINS=os-* PRODUCT_PRIVKEY=/usr/tools/config/24.7/repo.key PRODUCT_PUBKEY=/usr/tools/config/24.7/repo.pub PRODUCT_PYTHON=311 PRODUCT_RELEASE=OPNsense-202501101429 PRODUCT_RUBY=31 PRODUCT_SERVER=nightly@pkg.opnsense.org PRODUCT_SETTINGS=24.7 PRODUCT_SIGNCHK=/usr/tools/scripts/pkg_fingerprint.sh /usr/tools/config/24.7/repo.pub PRODUCT_SIGNCMD=/usr/tools/scripts/pkg_sign.sh /usr/tools/config/24.7/repo.pub /usr/tools/config/24.7/repo.key PRODUCT_SSL=openssl PRODUCT_SUFFIX= PRODUCT_TARGET=amd64 PRODUCT_TYPE=opnsense PRODUCT_UEFI=arm dvd serial vga vm PRODUCT_VERSION=202501101429 PRODUCT_ZFS= PWD=/usr/tools/build SERVER=nightly@pkg.opnsense.org SETSDIR=/usr/local/opnsense/build/24.7/amd64/sets SHELL=/bin/sh SRCABI=FreeBSD:14:amd64 SRCBRANCH=stable/24.7 SRCDIR=/usr/src SRCREVISION=14.1 STAGEDIR=/usr/obj/usr/tools/config/24.7/amd64 STAGEDIRPREFIX=/usr/obj TARGETDIR=/usr/local/opnsense/build/24.7/amd64 TARGETDIRPREFIX=/usr/local/opnsense/build TOOLSBRANCH=master TOOLSDIR=/usr/tools UPLOADDIR=incoming USER=root >>> Running build step: base >>> Passing arguments: (none) >>> Reusing base set: /usr/local/opnsense/build/24.7/amd64/sets/base-24.7-amd64.txz >>> Executing build step ports on 24.7 ABI_FILE=/usr/lib/crt1.o BLOCKSIZE=K CONFIGDIR=/usr/tools/config/24.7 CONFIG_XML=/usr/local/etc/config.xml COREBRANCH=stable/24.7 COREDIR=/usr/core COREENV=CORE_PHP=82 CORE_ABI=24.7 CORE_PYTHON=311 CPUS=8 DEVICEDIR=/usr/tools/device ENV_FILTER=env -i USER=root LOGNAME=root HOME=/root SHELL=/bin/sh BLOCKSIZE=K MAIL= PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin TERM= HOSTTYPE= VENDOR= OSTYPE= MACHTYPE= PWD=/usr/tools/build GROUP= HOST= EDITOR= PAGER= ABI_FILE=/usr/lib/crt1.o EXTRABRANCH= HOME=/root IMAGESDIR=/usr/local/opnsense/build/24.7/amd64/images LANG=C.UTF-8 LOGNAME=root LOGSDIR=/usr/local/opnsense/build/24.7/amd64/logs MAKEFLAGS= PORTSENV=MISMATCH=no SERVER=nightly@pkg.opnsense.org UPLOADDIR=incoming MAKELEVEL=2 META_MODE=normal MM_CHARSET=UTF-8 OLDPWD=/usr/obj/usr/tools PACKAGESDIR=/.pkg PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin PLUGINSBRANCH=stable/24.7 PLUGINSDIR=/usr/plugins PLUGINSENV=PLUGIN_PHP=82 PLUGIN_ABI=24.7 PLUGIN_PYTHON=311 PORTSBRANCH=master PORTSDIR=/usr/ports PORTSENV=MISMATCH=no PORTSREFBRANCH=main PORTSREFDIR=/usr/freebsd-ports PORTSREFURL=https://git.FreeBSD.org/ports.git PRINT_ENV_SKIP=1 PRODUCT_ABI=24.7 PRODUCT_ADDITIONS= PRODUCT_APACHE=24 PRODUCT_ARCH=amd64 PRODUCT_COMSPEED=115200 PRODUCT_CORE=opnsense PRODUCT_CORES=opnsense opnsense-devel opnsense-business PRODUCT_DEBUG= PRODUCT_DEVEL= PRODUCT_DEVICE_REAL=A10 PRODUCT_GITBASE=https://github.com/opnsense PRODUCT_HOST=amd64 PRODUCT_KERNEL=SMP PRODUCT_LUA=5.4 PRODUCT_MIRROR=https://opnsense.c0urier.net PRODUCT_NAME=OPNsense PRODUCT_PERL=5.36 PRODUCT_PHP=82 PRODUCT_PLUGIN=os-* PRODUCT_PLUGINS=os-* PRODUCT_PRIVKEY=/usr/tools/config/24.7/repo.key PRODUCT_PUBKEY=/usr/tools/config/24.7/repo.pub PRODUCT_PYTHON=311 PRODUCT_RELEASE=OPNsense-202501101429 PRODUCT_RUBY=31 PRODUCT_SERVER=nightly@pkg.opnsense.org PRODUCT_SETTINGS=24.7 PRODUCT_SIGNCHK=/usr/tools/scripts/pkg_fingerprint.sh /usr/tools/config/24.7/repo.pub PRODUCT_SIGNCMD=/usr/tools/scripts/pkg_sign.sh /usr/tools/config/24.7/repo.pub /usr/tools/config/24.7/repo.key PRODUCT_SSL=openssl PRODUCT_SUFFIX= PRODUCT_TARGET=amd64 PRODUCT_TYPE=opnsense PRODUCT_UEFI=arm dvd serial vga vm PRODUCT_VERSION=202501101429 PRODUCT_ZFS= PWD=/usr/tools/build SERVER=nightly@pkg.opnsense.org SETSDIR=/usr/local/opnsense/build/24.7/amd64/sets SHELL=/bin/sh SRCABI=FreeBSD:14:amd64 SRCBRANCH=stable/24.7 SRCDIR=/usr/src SRCREVISION=14.1 STAGEDIR=/usr/obj/usr/tools/config/24.7/amd64 STAGEDIRPREFIX=/usr/obj TARGETDIR=/usr/local/opnsense/build/24.7/amd64 TARGETDIRPREFIX=/usr/local/opnsense/build TOOLSBRANCH=master TOOLSDIR=/usr/tools UPLOADDIR=incoming USER=root >>> Running build step: ports >>> Passing arguments: (none) >>> Step ports is up to date >>> Executing build step plugins on 24.7 ABI_FILE=/usr/lib/crt1.o BLOCKSIZE=K CONFIGDIR=/usr/tools/config/24.7 CONFIG_XML=/usr/local/etc/config.xml COREBRANCH=stable/24.7 COREDIR=/usr/core COREENV=CORE_PHP=82 CORE_ABI=24.7 CORE_PYTHON=311 CPUS=8 DEVICEDIR=/usr/tools/device ENV_FILTER=env -i USER=root LOGNAME=root HOME=/root SHELL=/bin/sh BLOCKSIZE=K MAIL= PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin TERM= HOSTTYPE= VENDOR= OSTYPE= MACHTYPE= PWD=/usr/tools/build GROUP= HOST= EDITOR= PAGER= ABI_FILE=/usr/lib/crt1.o EXTRABRANCH= HOME=/root IMAGESDIR=/usr/local/opnsense/build/24.7/amd64/images LANG=C.UTF-8 LOGNAME=root LOGSDIR=/usr/local/opnsense/build/24.7/amd64/logs MAKEFLAGS= PORTSENV=MISMATCH=no SERVER=nightly@pkg.opnsense.org UPLOADDIR=incoming MAKELEVEL=2 META_MODE=normal MM_CHARSET=UTF-8 OLDPWD=/usr/obj/usr/tools PACKAGESDIR=/.pkg PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin PLUGINSBRANCH=stable/24.7 PLUGINSDIR=/usr/plugins PLUGINSENV=PLUGIN_PHP=82 PLUGIN_ABI=24.7 PLUGIN_PYTHON=311 PORTSBRANCH=master PORTSDIR=/usr/ports PORTSENV=MISMATCH=no PORTSREFBRANCH=main PORTSREFDIR=/usr/freebsd-ports PORTSREFURL=https://git.FreeBSD.org/ports.git PRINT_ENV_SKIP=1 PRODUCT_ABI=24.7 PRODUCT_ADDITIONS= PRODUCT_APACHE=24 PRODUCT_ARCH=amd64 PRODUCT_COMSPEED=115200 PRODUCT_CORE=opnsense PRODUCT_CORES=opnsense opnsense-devel opnsense-business PRODUCT_DEBUG= PRODUCT_DEVEL= PRODUCT_DEVICE_REAL=A10 PRODUCT_GITBASE=https://github.com/opnsense PRODUCT_HOST=amd64 PRODUCT_KERNEL=SMP PRODUCT_LUA=5.4 PRODUCT_MIRROR=https://mirror.wdc1.us.leaseweb.net/opnsense PRODUCT_NAME=OPNsense PRODUCT_PERL=5.36 PRODUCT_PHP=82 PRODUCT_PLUGIN=os-* PRODUCT_PLUGINS=os-* PRODUCT_PRIVKEY=/usr/tools/config/24.7/repo.key PRODUCT_PUBKEY=/usr/tools/config/24.7/repo.pub PRODUCT_PYTHON=311 PRODUCT_RELEASE=OPNsense-202501101429 PRODUCT_RUBY=31 PRODUCT_SERVER=nightly@pkg.opnsense.org PRODUCT_SETTINGS=24.7 PRODUCT_SIGNCHK=/usr/tools/scripts/pkg_fingerprint.sh /usr/tools/config/24.7/repo.pub PRODUCT_SIGNCMD=/usr/tools/scripts/pkg_sign.sh /usr/tools/config/24.7/repo.pub /usr/tools/config/24.7/repo.key PRODUCT_SSL=openssl PRODUCT_SUFFIX= PRODUCT_TARGET=amd64 PRODUCT_TYPE=opnsense PRODUCT_UEFI=arm dvd serial vga vm PRODUCT_VERSION=202501101429 PRODUCT_ZFS= PWD=/usr/tools/build SERVER=nightly@pkg.opnsense.org SETSDIR=/usr/local/opnsense/build/24.7/amd64/sets SHELL=/bin/sh SRCABI=FreeBSD:14:amd64 SRCBRANCH=stable/24.7 SRCDIR=/usr/src SRCREVISION=14.1 STAGEDIR=/usr/obj/usr/tools/config/24.7/amd64 STAGEDIRPREFIX=/usr/obj TARGETDIR=/usr/local/opnsense/build/24.7/amd64 TARGETDIRPREFIX=/usr/local/opnsense/build TOOLSBRANCH=master TOOLSDIR=/usr/tools UPLOADDIR=incoming USER=root >>> Running build step: plugins >>> Passing arguments: (none) >>> Step plugins is up to date >>> Executing build step core on 24.7 ABI_FILE=/usr/lib/crt1.o BLOCKSIZE=K CONFIGDIR=/usr/tools/config/24.7 CONFIG_XML=/usr/local/etc/config.xml COREBRANCH=stable/24.7 COREDIR=/usr/core COREENV=CORE_PHP=82 CORE_ABI=24.7 CORE_PYTHON=311 CPUS=8 DEVICEDIR=/usr/tools/device ENV_FILTER=env -i USER=root LOGNAME=root HOME=/root SHELL=/bin/sh BLOCKSIZE=K MAIL= PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin TERM= HOSTTYPE= VENDOR= OSTYPE= MACHTYPE= PWD=/usr/tools/build GROUP= HOST= EDITOR= PAGER= ABI_FILE=/usr/lib/crt1.o EXTRABRANCH= HOME=/root IMAGESDIR=/usr/local/opnsense/build/24.7/amd64/images LANG=C.UTF-8 LOGNAME=root LOGSDIR=/usr/local/opnsense/build/24.7/amd64/logs MAKEFLAGS= PORTSENV=MISMATCH=no SERVER=nightly@pkg.opnsense.org UPLOADDIR=incoming MAKELEVEL=2 META_MODE=normal MM_CHARSET=UTF-8 OLDPWD=/usr/obj/usr/tools PACKAGESDIR=/.pkg PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin PLUGINSBRANCH=stable/24.7 PLUGINSDIR=/usr/plugins PLUGINSENV=PLUGIN_PHP=82 PLUGIN_ABI=24.7 PLUGIN_PYTHON=311 PORTSBRANCH=master PORTSDIR=/usr/ports PORTSENV=MISMATCH=no PORTSREFBRANCH=main PORTSREFDIR=/usr/freebsd-ports PORTSREFURL=https://git.FreeBSD.org/ports.git PRINT_ENV_SKIP=1 PRODUCT_ABI=24.7 PRODUCT_ADDITIONS= PRODUCT_APACHE=24 PRODUCT_ARCH=amd64 PRODUCT_COMSPEED=115200 PRODUCT_CORE=opnsense PRODUCT_CORES=opnsense opnsense-devel opnsense-business PRODUCT_DEBUG= PRODUCT_DEVEL= PRODUCT_DEVICE_REAL=A10 PRODUCT_GITBASE=https://github.com/opnsense PRODUCT_HOST=amd64 PRODUCT_KERNEL=SMP PRODUCT_LUA=5.4 PRODUCT_MIRROR=https://mirror.wdc1.us.leaseweb.net/opnsense PRODUCT_NAME=OPNsense PRODUCT_PERL=5.36 PRODUCT_PHP=82 PRODUCT_PLUGIN=os-* PRODUCT_PLUGINS=os-* PRODUCT_PRIVKEY=/usr/tools/config/24.7/repo.key PRODUCT_PUBKEY=/usr/tools/config/24.7/repo.pub PRODUCT_PYTHON=311 PRODUCT_REBUILD=yes PRODUCT_RELEASE=OPNsense-202501101429 PRODUCT_RUBY=31 PRODUCT_SERVER=nightly@pkg.opnsense.org PRODUCT_SETTINGS=24.7 PRODUCT_SIGNCHK=/usr/tools/scripts/pkg_fingerprint.sh /usr/tools/config/24.7/repo.pub PRODUCT_SIGNCMD=/usr/tools/scripts/pkg_sign.sh /usr/tools/config/24.7/repo.pub /usr/tools/config/24.7/repo.key PRODUCT_SSL=openssl PRODUCT_SUFFIX= PRODUCT_TARGET=amd64 PRODUCT_TYPE=opnsense PRODUCT_UEFI=arm dvd serial vga vm PRODUCT_VERSION=202501101429 PRODUCT_ZFS= PWD=/usr/tools/build SERVER=nightly@pkg.opnsense.org SETSDIR=/usr/local/opnsense/build/24.7/amd64/sets SHELL=/bin/sh SRCABI=FreeBSD:14:amd64 SRCBRANCH=stable/24.7 SRCDIR=/usr/src SRCREVISION=14.1 STAGEDIR=/usr/obj/usr/tools/config/24.7/amd64 STAGEDIRPREFIX=/usr/obj TARGETDIR=/usr/local/opnsense/build/24.7/amd64 TARGETDIRPREFIX=/usr/local/opnsense/build TOOLSBRANCH=master TOOLSDIR=/usr/tools UPLOADDIR=incoming USER=root >>> Running build step: core >>> Passing arguments: nightly >>> Setting up stage in /usr/obj/usr/tools/config/24.7/amd64 >>> Setting up base in /usr/obj/usr/tools/config/24.7/amd64 >>> Setting up chroot in /usr/obj/usr/tools/config/24.7/amd64 ELF ldconfig path: /lib /usr/lib /usr/lib/compat 32-bit compatibility ldconfig path: >>> Extracting packages in /usr/obj/usr/tools/config/24.7/amd64 >>> Removing packages in /usr/obj/usr/tools/config/24.7/amd64: nightly >>> Installing packages in /usr/obj/usr/tools/config/24.7/amd64: pkg git pkg: No packages installed. Nothing to do! Installing pkg-1.19.2_5... Extracting pkg-1.19.2_5: .......... done Installing pkg-1.19.2_5... the most recent version of pkg-1.19.2_5 is already installed Installing git-2.47.1... `-- Installing expat-2.6.4... `-- Extracting expat-2.6.4: .......... done `-- Installing openssl-3.0.15_1,1... `-- Extracting openssl-3.0.15_1,1: .......... done `-- Installing python311-3.11.11... | `-- Installing mpdecimal-4.0.0... | `-- Extracting mpdecimal-4.0.0: .......... done | `-- Installing readline-8.2.13_2... | | `-- Installing indexinfo-0.3.1... | | `-- Extracting indexinfo-0.3.1: .... done | `-- Extracting readline-8.2.13_2: .......... done | `-- Installing libffi-3.4.6... | `-- Extracting libffi-3.4.6: .......... done `-- Extracting python311-3.11.11: .......... done `-- Installing perl5-5.36.3_2... `-- Extracting perl5-5.36.3_2: .......... done `-- Installing p5-Error-0.17029... `-- Extracting p5-Error-0.17029: ......... done `-- Installing curl-8.11.1_1... | `-- Installing libnghttp2-1.64.0... | `-- Extracting libnghttp2-1.64.0: .......... done | `-- Installing libpsl-0.21.5_1... | | `-- Installing libidn2-2.3.7... | | `-- Installing libunistring-1.2... | | `-- Extracting libunistring-1.2: .......... done | | `-- Extracting libidn2-2.3.7: .......... done | `-- Extracting libpsl-0.21.5_1: .......... done | `-- Installing zstd-1.5.6... | | `-- Installing liblz4-1.10.0,1... | | `-- Extracting liblz4-1.10.0,1: .......... done | `-- Extracting zstd-1.5.6: .......... done | `-- Installing brotli-1.1.0,1... | `-- Extracting brotli-1.1.0,1: .......... done `-- Extracting curl-8.11.1_1: .......... done `-- Installing pcre2-10.43... `-- Extracting pcre2-10.43: .......... done ===> Creating groups Creating group 'git_daemon' with gid '964' ===> Creating users Creating user 'git_daemon' with uid '964' Extracting git-2.47.1: .......... done ===== Message from python311-3.11.11: -- Note that some standard Python modules are provided as separate ports as they require additional dependencies. They are available as: py311-gdbm databases/py-gdbm@py311 py311-sqlite3 databases/py-sqlite3@py311 py311-tkinter x11-toolkits/py-tkinter@py311 ===== Message from git-2.47.1: -- If you installed the GITWEB option please follow these instructions: In the directory /usr/local/share/examples/git/gitweb you can find all files to make gitweb work as a public repository on the web. All you have to do to make gitweb work is: 1) Please be sure you're able to execute CGI scripts in /usr/local/share/examples/git/gitweb. 2) Set the GITWEB_CONFIG variable in your webserver's config to /usr/local/etc/git/gitweb.conf. This variable is passed to gitweb.cgi. 3) Restart server. If you installed the CONTRIB option please note that the scripts are installed in /usr/local/share/git-core/contrib. Some of them require other ports to be installed (perl, python, etc), which you may need to install manually. >>> Locking packages in /usr/obj/usr/tools/config/24.7/amd64: -a >>> Setting up /usr/core copy in /usr/obj/usr/tools/config/24.7/amd64 HEAD is now at a675e29e2 network time: small PHP related cleanup make[2]: "/usr/obj/usr/tools/config/24.7/amd64/usr/core/Mk/defaults.mk" line 66: warning: "/usr/local/sbin/pkg query %v syslog-ng" returned non-zero status make[2]: "/usr/obj/usr/tools/config/24.7/amd64/usr/core/Mk/defaults.mk" line 66: warning: "/usr/local/sbin/pkg query %v syslog-ng" returned non-zero status make[2]: "/usr/obj/usr/tools/config/24.7/amd64/usr/core/Mk/defaults.mk" line 66: warning: "/usr/local/sbin/pkg query %v syslog-ng" returned non-zero status >>> Installing packages in /usr/obj/usr/tools/config/24.7/amd64: ca_root_nss choparp cpustats dhcp6c dhcrelay dnsmasq dpinger expiretable filterlog flock flowd hostapd ifinfo iftop isc-dhcp44-server kea lighttpd monit mpd5 ntp openssh-portable openvpn opnsense-installer opnsense-lang opnsense-update pam_opnsense pftop php82-ctype php82-curl php82-dom php82-filter php82-gettext php82-google-api-php-client php82-ldap php82-pcntl php82-pdo php82-pear-Crypt_CHAP php82-pecl-radius php82-phalcon php82-phpseclib php82-session php82-simplexml php82-sockets php82-sqlite3 php82-xml php82-zlib pkg py311-Jinja2 py311-dnspython py311-ldap3 py311-netaddr py311-requests py311-sqlite3 py311-ujson py311-vici radvd rrdtool samplicator strongswan sudo syslog-ng unbound wpa_supplicant zip beep py311-duckdb py311-numpy py311-pandas suricata Updating database digests format: .......... done Checking integrity... done (0 conflicting) The following package(s) are locked and may not be removed: brotli curl expat git indexinfo libffi libidn2 liblz4 libnghttp2 libpsl libunistring mpdecimal openssl p5-Error pcre2 perl5 pkg python311 readline zstd Nothing to do. Installing pkg-1.19.2_5... the most recent version of pkg-1.19.2_5 is already installed Installing ca_root_nss-3.104... Extracting ca_root_nss-3.104: ..... done ===== Message from ca_root_nss-3.104: -- FreeBSD does not, and can not warrant that the certification authorities whose certificates are included in this package have in any way been audited for trustworthiness or RFC 3647 compliance. Assessment and verification of trust is the complete responsibility of the system administrator. This package installs symlinks to support root certificate discovery for software that either uses other cryptographic libraries than OpenSSL, or use OpenSSL but do not follow recommended practice. If you prefer to do this manually, replace the following symlinks with either an empty file or your site-local certificate bundle. * /etc/ssl/cert.pem * /usr/local/etc/ssl/cert.pem * /usr/local/openssl/cert.pem Installing choparp-20150613_1... Extracting choparp-20150613_1: ...... done Installing cpustats-0.1... Extracting cpustats-0.1: . done Installing dhcp6c-20241008... Extracting dhcp6c-20241008: ........ done Installing dhcrelay-1.0... Extracting dhcrelay-1.0: ....... done Installing dnsmasq-2.90_4,1... `-- Installing nettle-3.10.1... | `-- Installing gmp-6.3.0... | `-- Extracting gmp-6.3.0: .......... done `-- Extracting nettle-3.10.1: .......... done Extracting dnsmasq-2.90_4,1: .......... done ===== Message from dnsmasq-2.90_4,1: -- To enable dnsmasq, edit /usr/local/etc/dnsmasq.conf and set dnsmasq_enable="YES" in /etc/rc.conf[.local] Further options and actions are documented inside /usr/local/etc/rc.d/dnsmasq SECURITY RECOMMENDATION ~~~~~~~~~~~~~~~~~~~~~~~ It is recommended to enable the wpad-related options at the end of the configuration file (you may need to copy them from the example file to yours) to fix CERT Vulnerability VU#598349. Installing dpinger-3.3... Extracting dpinger-3.3: .... done Installing expiretable-0.6_3... Extracting expiretable-0.6_3: ... done Installing filterlog-0.7_1... Extracting filterlog-0.7_1: .... done Installing flock-2.37.2_1... Extracting flock-2.37.2_1: ...... done Installing flowd-0.9.1_5... ===> Creating groups Creating group '_flowd' with gid '542' ===> Creating users Creating user '_flowd' with uid '542' Extracting flowd-0.9.1_5: .......... done Installing hostapd-2.11_1... Extracting hostapd-2.11_1: ....... done ===== Message from hostapd-2.11_1: -- Add the following to /etc/rc.conf to use the ports version instead of the base version: hostapd_program="/usr/local/sbin/hostapd" Installing ifinfo-13.0_1... Extracting ifinfo-13.0_1: .... done Installing iftop-1.0.p4_1... Extracting iftop-1.0.p4_1: ..... done Installing isc-dhcp44-server-4.4.3P1_2... ===> Creating groups Creating group 'dhcpd' with gid '136' ===> Creating users Creating user 'dhcpd' with uid '136' Extracting isc-dhcp44-server-4.4.3P1_2: .......... done ===== Message from isc-dhcp44-server-4.4.3P1_2: -- **** To setup dhcpd, please edit /usr/local/etc/dhcpd.conf. **** This port installs the dhcp daemon, but doesn't invoke dhcpd by default. If you want to invoke dhcpd at startup, add these lines to /etc/rc.conf: dhcpd_enable="YES" # dhcpd enabled? dhcpd_flags="-q" # command option(s) dhcpd_conf="/usr/local/etc/dhcpd.conf" # configuration file dhcpd_ifaces="" # ethernet interface(s) dhcpd_withumask="022" # file creation mask **** If compiled with paranoia support (the default), the following rc.conf options are also supported: dhcpd_chuser_enable="YES" # runs w/o privileges? dhcpd_withuser="dhcpd" # user name to run as dhcpd_withgroup="dhcpd" # group name to run as dhcpd_chroot_enable="YES" # runs chrooted? dhcpd_devfs_enable="YES" # use devfs if available? dhcpd_rootdir="/var/db/dhcpd" # directory to run in dhcpd_includedir="" # directory with config- files to include **** WARNING: never edit the chrooted or jailed dhcpd.conf file but /usr/local/etc/dhcpd.conf instead which is always copied where needed upon startup. Installing kea-2.6.1_2... `-- Installing log4cplus-2.1.2... `-- Extracting log4cplus-2.1.2: .......... done `-- Installing boost-libs-1.86.0_1... | `-- Installing icu-74.2_1,1... | `-- Extracting icu-74.2_1,1: .......... done `-- Extracting boost-libs-1.86.0_1: .......... done Extracting kea-2.6.1_2: .......... done ===== Message from boost-libs-1.86.0_1: -- You have built the Boost library with thread support. Don't forget to add -pthread to your linker options when linking your code. Installing lighttpd-1.4.76_1... ===> Creating groups Using existing group 'www' ===> Creating users Using existing user 'www' Extracting lighttpd-1.4.76_1: .......... done Installing monit-5.34.3... Extracting monit-5.34.3: ....... done ===== Message from monit-5.34.3: -- USAGE: To enable monit you need to add monit_enable="YES" to rc.conf file. Before running monit you have to configure monitrc file. There is example configuration file monitrc.sample. /usr/local/etc/monitrc.sample Installing mpd5-5.9_18... Extracting mpd5-5.9_18: .......... done Installing ntp-4.2.8p18_1... `-- Installing libevent-2.1.12... `-- Extracting libevent-2.1.12: .......... done `-- Installing libedit-3.1.20240808,1... `-- Extracting libedit-3.1.20240808,1: .......... done Extracting ntp-4.2.8p18_1: .......... done ===== Message from ntp-4.2.8p18_1: -- Please add ntpd_program="/usr/local/sbin/ntpd" ntpdate_program="/usr/local/sbin/ntpdate" to your /etc/rc.conf or run sysrc ntpd_program="/usr/local/sbin/ntpd" sysrc ntpdate_program="/usr/local/sbin/ntpdate" to enable ntp from ports/packages instead of base ntp. Installing openssh-portable-9.9.p1_1,1... `-- Installing libfido2-1.15.0... | `-- Installing libcbor-0.11.0... | | `-- Installing libcjson-1.7.18_2... | | `-- Extracting libcjson-1.7.18_2: .......... done | `-- Extracting libcbor-0.11.0: .......... done `-- Extracting libfido2-1.15.0: .......... done `-- Installing ldns-1.8.4... `-- Extracting ldns-1.8.4: .......... done Extracting openssh-portable-9.9.p1_1,1: .......... done ===== Message from openssh-portable-9.9.p1_1,1: -- To enable this port, add openssh_enable="YES" in your rc.conf. To prevent conflict with openssh in the base system add sshd_enable="NO" in your rc.conf. Also you can configure openssh at another TCP port (via sshd_config 'Port' and 'Listen' options or via 'openssh_flags' variable in rc.conf) and run it in same time with base sshd. 'PermitRootLogin no' is the default for the OpenSSH port. This now matches the PermitRootLogin configuration of OpenSSH in the base system. Please be aware of this when upgrading your OpenSSH port, and if truly necessary, re-enable remote root login by readjusting this option in your sshd_config. Users are encouraged to create single-purpose users with ssh keys, disable Password authentication by setting 'PasswordAuthentication no' and 'ChallengeResponseAuthentication no', and to define very narrow sudo privileges instead of using root for automated tasks. Installing openvpn-2.6.12... `-- Installing pkcs11-helper-1.29.0_3... `-- Extracting pkcs11-helper-1.29.0_3: .......... done `-- Installing easy-rsa-3.2.1_1,1... `-- Extracting easy-rsa-3.2.1_1,1: .......... done `-- Installing lzo2-2.10_1... `-- Extracting lzo2-2.10_1: .......... done ===> Creating groups Creating group 'openvpn' with gid '301' ===> Creating users Creating user 'openvpn' with uid '301' Extracting openvpn-2.6.12: .......... done ===== Message from easy-rsa-3.2.1_1,1: -- NOTE: easyrsa will require you to initialize a PKI upon first use. ONLY for the very first run for a new PKI, do something such as this, assuming you will have its data in $HOME/my_new_pki: easyrsa --pki-dir=$HOME/my_new_pki init-pki # DANGEROUS - DESTROYS ~/my_new_pki See /usr/local/share/doc/easy-rsa/README.quickstart.md for further information. An on-line help is available, you can run: easyrsa help # for help on commands easyrsa help options # for help on options ===== Message from openvpn-2.6.12: -- Edit /etc/rc.conf[.local] to start OpenVPN automatically at system startup. See /usr/local/etc/rc.d/openvpn for details. Connect to VPN server as a client with this command to include the client.up/down scripts in the initialization: openvpn-client .ovpn For compatibility notes when interoperating with older OpenVPN versions, please see Note that OpenVPN does not officially support LibreSSL. Note that OpenVPN configures a separate user and group "openvpn", which should be used instead of the NFS user "nobody" when an unprivileged user account is desired. You may want to add user openvpn and group openvpn when creating your configuration files, the example configuration shows this only as comments. Installing opnsense-installer-24.7... `-- Installing cpdup-1.22_1... `-- Extracting cpdup-1.22_1: ..... done Extracting opnsense-installer-24.7: .......... done Installing opnsense-lang-24.7.8... Extracting opnsense-lang-24.7.8: .......... done Installing opnsense-update-24.7.12... `-- Installing libucl-0.9.2... `-- Extracting libucl-0.9.2: .......... done Extracting opnsense-update-24.7.12: .......... done Installing pam_opnsense-24.1... Extracting pam_opnsense-24.1: ........ done Installing pftop-0.10_1... `-- Installing libpfctl-0.15... `-- Extracting libpfctl-0.15: ...... done Extracting pftop-0.10_1: ..... done Installing php82-ctype-8.2.27... `-- Installing php82-8.2.27... | `-- Installing libxml2-2.11.9... | `-- Extracting libxml2-2.11.9: .......... done | `-- Installing libargon2-20190702_1... | `-- Extracting libargon2-20190702_1: .......... done `-- Extracting php82-8.2.27: .......... done Extracting php82-ctype-8.2.27: ........ done ===== Message from php82-ctype-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-ctype.ini.sample Installing php82-curl-8.2.27... Extracting php82-curl-8.2.27: .......... done ===== Message from php82-curl-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-curl.ini.sample Installing php82-dom-8.2.27... Extracting php82-dom-8.2.27: .......... done ===== Message from php82-dom-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-dom.ini.sample Installing php82-filter-8.2.27... Extracting php82-filter-8.2.27: ......... done ===== Message from php82-filter-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-filter.ini.sample Installing php82-gettext-8.2.27... `-- Installing gettext-runtime-0.23.1... `-- Extracting gettext-runtime-0.23.1: .......... done Extracting php82-gettext-8.2.27: ........ done ===== Message from php82-gettext-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-gettext.ini.sample Installing php82-google-api-php-client-2.4.0... Extracting php82-google-api-php-client-2.4.0: .......... done Installing php82-ldap-8.2.27... `-- Installing openldap26-client-2.6.9... | `-- Installing cyrus-sasl-gssapi-2.1.28... | | `-- Installing krb5-1.21.3... | | `-- Extracting krb5-1.21.3: .......... done | | `-- Installing cyrus-sasl-2.1.28_5... *** Added group `cyrus' (id 60) *** Added user `cyrus' (id 60) | | `-- Extracting cyrus-sasl-2.1.28_5: .......... done | `-- Extracting cyrus-sasl-gssapi-2.1.28: .......... done `-- Extracting openldap26-client-2.6.9: .......... done Extracting php82-ldap-8.2.27: ........ done ===== Message from cyrus-sasl-2.1.28_5: -- You can use sasldb2 for authentication, to add users use: saslpasswd2 -c username If you want to enable SMTP AUTH with the system Sendmail, read Sendmail.README NOTE: This port has been compiled with a default pwcheck_method of auxprop. If you want to authenticate your user by /etc/passwd, PAM or LDAP, install ports/security/cyrus-sasl2-saslauthd and set sasl_pwcheck_method to saslauthd after installing the Cyrus-IMAPd 2.X port. You should also check the /usr/local/lib/sasl2/*.conf files for the correct pwcheck_method. If you want to use GSSAPI mechanism, install ports/security/cyrus-sasl2-gssapi. If you want to use SRP mechanism, install ports/security/cyrus-sasl2-srp. If you want to use LDAP auxprop plugin, install ports/security/cyrus-sasl2-ldapdb. ===== Message from openldap26-client-2.6.9: -- The OpenLDAP client package has been successfully installed. Edit /usr/local/etc/openldap/ldap.conf to change the system-wide client defaults. Try `man ldap.conf' and visit the OpenLDAP FAQ-O-Matic at http://www.OpenLDAP.org/faq/index.cgi?file=3 for more information. ===== Message from php82-ldap-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-ldap.ini.sample Installing php82-pcntl-8.2.27... Extracting php82-pcntl-8.2.27: ......... done ===== Message from php82-pcntl-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-pcntl.ini.sample Installing php82-pdo-8.2.27... Extracting php82-pdo-8.2.27: .......... done ===== Message from php82-pdo-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-pdo.ini.sample Installing php82-pear-Crypt_CHAP-1.5.0_1... `-- Installing php82-pecl-mcrypt-1.0.7... | `-- Installing libmcrypt-2.5.8_4... | `-- Extracting libmcrypt-2.5.8_4: .......... done | `-- Installing libltdl-2.5.4... | `-- Extracting libltdl-2.5.4: .......... done `-- Extracting php82-pecl-mcrypt-1.0.7: ........ done `-- Installing php82-pear-1.10.13... | `-- Installing php82-xml-8.2.27... | `-- Extracting php82-xml-8.2.27: ......... done | `-- Installing php82-zlib-8.2.27... | `-- Extracting php82-zlib-8.2.27: ........ done `-- Extracting php82-pear-1.10.13: .......... done Extracting php82-pear-Crypt_CHAP-1.5.0_1: ...... done install ok: channel://pear.php.net/Crypt_CHAP-1.5.0 ===== Message from php82-pecl-mcrypt-1.0.7: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-mcrypt.ini.sample ===== Message from php82-xml-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-xml.ini.sample ===== Message from php82-zlib-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-zlib.ini.sample Installing php82-pecl-radius-1.4.0b1_2... Extracting php82-pecl-radius-1.4.0b1_2: .......... done ===== Message from php82-pecl-radius-1.4.0b1_2: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-radius.ini.sample Installing php82-phalcon-5.8.0... `-- Installing php82-session-8.2.27... `-- Extracting php82-session-8.2.27: .......... done `-- Installing php82-mbstring-8.2.27... | `-- Installing oniguruma-6.9.10... | `-- Extracting oniguruma-6.9.10: .......... done `-- Extracting php82-mbstring-8.2.27: .......... done Extracting php82-phalcon-5.8.0: ........ done ===== Message from php82-session-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-18-session.ini.sample ===== Message from php82-mbstring-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-mbstring.ini.sample ===== Message from php82-phalcon-5.8.0: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-30-phalcon.ini.sample Installing php82-phpseclib-3.0.42... Extracting php82-phpseclib-3.0.42: ......... done Installing php82-session-8.2.27... the most recent version of php82-session-8.2.27 is already installed Installing php82-simplexml-8.2.27... Extracting php82-simplexml-8.2.27: ......... done ===== Message from php82-simplexml-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-simplexml.ini.sample Installing php82-sockets-8.2.27... Extracting php82-sockets-8.2.27: .......... done ===== Message from php82-sockets-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-sockets.ini.sample Installing php82-sqlite3-8.2.27... `-- Installing sqlite3-3.46.1,1... `-- Extracting sqlite3-3.46.1,1: .......... done Extracting php82-sqlite3-8.2.27: ......... done ===== Message from php82-sqlite3-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-sqlite3.ini.sample Installing php82-xml-8.2.27... the most recent version of php82-xml-8.2.27 is already installed Installing php82-zlib-8.2.27... the most recent version of php82-zlib-8.2.27 is already installed Installing pkg-1.19.2_5... the most recent version of pkg-1.19.2_5 is already installed Installing py311-Jinja2-3.1.4... `-- Installing py311-markupsafe-2.1.5_1... `-- Extracting py311-markupsafe-2.1.5_1: .......... done `-- Installing py311-Babel-2.16.0... | `-- Installing py311-setuptools-63.1.0_1... | `-- Extracting py311-setuptools-63.1.0_1: .......... done `-- Extracting py311-Babel-2.16.0: .......... done Extracting py311-Jinja2-3.1.4: .......... done Installing py311-dnspython-2.7.0,1... `-- Installing py311-httpx-0.28.1... | `-- Installing py311-httpcore-1.0.7... | | `-- Installing py311-h2-4.1.0... | | `-- Installing py311-hyperframe-6.0.0... | | `-- Extracting py311-hyperframe-6.0.0: .......... done | | `-- Installing py311-hpack-4.0.0... | | `-- Extracting py311-hpack-4.0.0: .......... done | | `-- Extracting py311-h2-4.1.0: .......... done | | `-- Installing py311-certifi-2024.12.14... | | `-- Extracting py311-certifi-2024.12.14: .......... done | | `-- Installing py311-h11-0.14.0... | | `-- Extracting py311-h11-0.14.0: .......... done | | `-- Installing py311-anyio-4.7.0... | | `-- Installing py311-truststore-0.10.0... | | `-- Extracting py311-truststore-0.10.0: .......... done | | `-- Installing py311-idna-3.10... | | `-- Extracting py311-idna-3.10: .......... done | | `-- Installing py311-typing-extensions-4.12.2... | | `-- Extracting py311-typing-extensions-4.12.2: .......... done | | `-- Installing py311-sniffio-1.3.1... | | `-- Extracting py311-sniffio-1.3.1: .......... done | | `-- Extracting py311-anyio-4.7.0: .......... done | `-- Extracting py311-httpcore-1.0.7: .......... done | `-- Installing py311-socksio-1.0.0_1... | `-- Extracting py311-socksio-1.0.0_1: .......... done `-- Extracting py311-httpx-0.28.1: .......... done `-- Installing py311-aioquic-1.2.0... | `-- Installing py311-pylsqpack-0.3.18... | `-- Extracting py311-pylsqpack-0.3.18: .......... done | `-- Installing py311-service-identity-24.2.0... | | `-- Installing py311-cryptography-42.0.8_5,1... | | `-- Installing py311-cffi-1.17.1... | | | `-- Installing py311-pycparser-2.22... | | | `-- Extracting py311-pycparser-2.22: .......... done | | `-- Extracting py311-cffi-1.17.1: .......... done | | `-- Extracting py311-cryptography-42.0.8_5,1: .......... done | | `-- Installing py311-pyasn1-modules-0.4.0... | | `-- Installing py311-pyasn1-0.6.0... | | `-- Extracting py311-pyasn1-0.6.0: .......... done | | `-- Extracting py311-pyasn1-modules-0.4.0: .......... done | | `-- Installing py311-attrs-24.3.0... | | `-- Extracting py311-attrs-24.3.0: .......... done | `-- Extracting py311-service-identity-24.2.0: .......... done | `-- Installing py311-openssl-24.1.0,1... | `-- Extracting py311-openssl-24.1.0,1: .......... done `-- Extracting py311-aioquic-1.2.0: .......... done `-- Installing py311-trio-0.28.0... | `-- Installing py311-sortedcontainers-2.4.0... | `-- Extracting py311-sortedcontainers-2.4.0: .......... done | `-- Installing py311-outcome-1.3.0_1... | `-- Extracting py311-outcome-1.3.0_1: .......... done | `-- Installing py311-async_generator-1.10... | `-- Extracting py311-async_generator-1.10: .......... done `-- Extracting py311-trio-0.28.0: .......... done Extracting py311-dnspython-2.7.0,1: .......... done Installing py311-ldap3-2.9.1... Extracting py311-ldap3-2.9.1: .......... done Installing py311-netaddr-1.3.0... Extracting py311-netaddr-1.3.0: .......... done Installing py311-requests-2.32.3... `-- Installing py311-charset-normalizer-3.4.1_1... `-- Extracting py311-charset-normalizer-3.4.1_1: .......... done `-- Installing py311-urllib3-1.26.20,1... | `-- Installing py311-pysocks-1.7.1_1... | `-- Extracting py311-pysocks-1.7.1_1: .......... done `-- Extracting py311-urllib3-1.26.20,1: .......... done Extracting py311-requests-2.32.3: .......... done ===== Message from py311-urllib3-1.26.20,1: -- Since version 1.25 HTTPS connections are now verified by default which is done via "cert_reqs = 'CERT_REQUIRED'". While certificate verification can be disabled via "cert_reqs = 'CERT_NONE'", it's highly recommended to leave it on. Various consumers of net/py-urllib3 already have implemented routines that either explicitly enable or disable HTTPS certificate verification (e.g. via configuration settings, CLI arguments, etc.). Yet it may happen that there are still some consumers which don't explicitly enable/disable certificate verification for HTTPS connections which could then lead to errors (as is often the case with self-signed certificates). In case of an error one should try first to temporarily disable certificate verification of the problematic urllib3 consumer to see if that approach will remedy the issue. Installing py311-sqlite3-3.11.11_7... Extracting py311-sqlite3-3.11.11_7: ........ done Installing py311-ujson-5.10.0... Extracting py311-ujson-5.10.0: ......... done Installing py311-vici-5.9.11... Extracting py311-vici-5.9.11: .......... done Installing radvd-2.19_4... Extracting radvd-2.19_4: .......... done Installing rrdtool-1.9.0... `-- Installing glib-2.80.5_1,2... | `-- Installing py311-packaging-24.2... | `-- Extracting py311-packaging-24.2: .......... done | `-- Installing libiconv-1.17_1... | `-- Extracting libiconv-1.17_1: .......... done `-- Extracting glib-2.80.5_1,2: .......... done Extracting rrdtool-1.9.0: .......... done Compiling glib schemas No schema files found: doing nothing. Generating GIO modules cache Installing samplicator-1.3.8.r1_1... Extracting samplicator-1.3.8.r1_1: ..... done Installing strongswan-5.9.14... Extracting strongswan-5.9.14: .......... done ===== Message from strongswan-5.9.14: -- The default strongSwan configuration interface have been updated to vici since version 5.9.2_1. To use the stroke interface by default either compile the port without the vici option or set 'strongswan_interface="stroke"' in your rc.conf file. Installing sudo-1.9.16p2... Extracting sudo-1.9.16p2: .......... done Installing syslog-ng-4.8.1_3... `-- Installing e2fsprogs-libuuid-1.47.1... `-- Extracting e2fsprogs-libuuid-1.47.1: .......... done `-- Installing json-c-0.18... `-- Extracting json-c-0.18: .......... done `-- Installing ivykis-0.43.2... `-- Extracting ivykis-0.43.2: .......... done Extracting syslog-ng-4.8.1_3: .......... done ===== Message from syslog-ng-4.8.1_3: -- syslog-ng is now installed! To replace FreeBSD's standard syslogd (/usr/sbin/syslogd), complete these steps: 1. Create a configuration file named /usr/local/etc/syslog-ng.conf (a sample named syslog-ng.conf.sample has been included in /usr/local/etc). Note that this is a change in 2.0.2 version, previous ones put the config file in /usr/local/etc/syslog-ng/syslog-ng.conf, so if this is an update move that file in the right place 2. Configure syslog-ng to start automatically by adding the following to /etc/rc.conf: syslog_ng_enable="YES" 3. Prevent the standard FreeBSD syslogd from starting automatically by adding a line to the end of your /etc/rc.conf file that reads: syslogd_enable="NO" 4. Shut down the standard FreeBSD syslogd: kill `cat /var/run/syslog.pid` 5. Start syslog-ng: /usr/local/etc/rc.d/syslog-ng start Installing unbound-1.22.0_1... `-- Installing libsodium-1.0.19... `-- Extracting libsodium-1.0.19: .......... done ===> Creating groups Using existing group 'unbound' ===> Creating users Using existing user 'unbound' Extracting unbound-1.22.0_1: .......... done Installing wpa_supplicant-2.11_2... Extracting wpa_supplicant-2.11_2: ....... done ===== Message from wpa_supplicant-2.11_2: -- To use the ports version of WPA Supplicant instead of the base, add: wpa_supplicant_program="/usr/local/sbin/wpa_supplicant" to /etc/rc.conf Installing zip-3.0_4... Extracting zip-3.0_4: .......... done Installing beep-1.0_2... Extracting beep-1.0_2: ..... done ===== Message from beep-1.0_2: -- Speaker sound support: ====================== For PC speaker sound to work you need to be in the operator group and need r/w permissions to /dev/speaker device. Load kernel module: # kldload speaker Add a user to operator group: % pw groupmod operator -m jerry Uncomment the following lines in /etc/devfs.rules file (create it if it doesn't exist): # Allow members of group operator to cat things to the speaker [speaker=10] add path 'speaker' mode 0660 group operator To load these new rules add the following to /etc/rc.conf: devfs_speaker_ruleset="speaker" Then restart devfs to load the new rules: % /etc/rc.d/devfs restart Installing py311-duckdb-1.1.3... `-- Installing py311-pandas-2.1.4,1... | `-- Installing py311-numpy-1.26.4_2,1... | `-- Extracting py311-numpy-1.26.4_2,1: .......... done | `-- Installing py311-numexpr-2.10.2... | `-- Extracting py311-numexpr-2.10.2: .......... done | `-- Installing py311-bottleneck-1.3.8_1... | `-- Extracting py311-bottleneck-1.3.8_1: .......... done | `-- Installing py311-tzdata-2024.2... | `-- Extracting py311-tzdata-2024.2: .......... done | `-- Installing py311-pytz-2024.2,1... | `-- Extracting py311-pytz-2024.2,1: .......... done | `-- Installing py311-python-dateutil-2.9.0... | | `-- Installing py311-six-1.17.0... | | `-- Extracting py311-six-1.17.0: .......... done | `-- Extracting py311-python-dateutil-2.9.0: .......... done `-- Extracting py311-pandas-2.1.4,1: .......... done Extracting py311-duckdb-1.1.3: .......... done ===== Message from py311-pandas-2.1.4,1: -- Install math/py-statsmodels to enable parts of pandas.stats. Install devel/py-xarray to enable the to_xarray() function. Installing py311-numpy-1.26.4_2,1... the most recent version of py311-numpy-1.26.4_2,1 is already installed Installing py311-pandas-2.1.4,1... the most recent version of py311-pandas-2.1.4,1 is already installed Installing suricata-7.0.8... `-- Installing libyaml-0.2.5... `-- Extracting libyaml-0.2.5: ......... done `-- Installing nss-3.107... | `-- Installing nspr-4.36... | `-- Extracting nspr-4.36: .......... done `-- Extracting nss-3.107: .......... done `-- Installing libnet-1.3,1... `-- Extracting libnet-1.3,1: .......... done `-- Installing py311-pyyaml-6.0.1... `-- Extracting py311-pyyaml-6.0.1: .......... done `-- Installing jansson-2.14... `-- Extracting jansson-2.14: .......... done `-- Installing hyperscan-5.4.2... `-- Extracting hyperscan-5.4.2: .......... done Extracting suricata-7.0.8: .......... done ===== Message from suricata-7.0.8: -- If you want to run Suricata in IDS mode, add to /etc/rc.conf: suricata_enable="YES" suricata_interface="" NOTE: Declaring suricata_interface is MANDATORY for Suricata in IDS Mode. However, if you want to run Suricata in Inline IPS Mode in divert(4) mode, add to /etc/rc.conf: suricata_enable="YES" suricata_divertport="8000" NOTE: Suricata won't start in IDS mode without an interface configured. Therefore if you omit suricata_interface from rc.conf, FreeBSD's rc.d/suricata will automatically try to start Suricata in IPS Mode (on divert port 8000, by default). Alternatively, if you want to run Suricata in Inline IPS Mode in high-speed netmap(4) mode, add to /etc/rc.conf: suricata_enable="YES" suricata_netmap="YES" NOTE: Suricata requires additional interface settings in the configuration file to run in netmap(4) mode. RULES: Suricata IDS/IPS Engine comes without rules by default. You should add rules by yourself and set an updating strategy. To do so, please visit: http://www.openinfosecfoundation.org/documentation/rules.html http://www.openinfosecfoundation.org/documentation/emerging-threats.html You may want to try BPF in zerocopy mode to test performance improvements: sysctl -w net.bpf.zerocopy_enable=1 Don't forget to add net.bpf.zerocopy_enable=1 to /etc/sysctl.conf >>> Staging files for opnsense-24.7.11_14... done >>> Generated version info for opnsense-24.7.11_14: { "product_abi": "24.7", "product_arch": "amd64", "product_conflicts": "os-firewall os-firewall-devel os-wireguard os-wireguard-devel os-wireguard-go os-wireguard-go-devel", "product_copyright_owner": "Deciso B.V.", "product_copyright_url": "https://www.deciso.com/", "product_copyright_years": "2014-2025", "product_email": "project@opnsense.org", "product_hash": "a675e29e2", "product_id": "opnsense", "product_name": "OPNsense", "product_nickname": "Thriving Tiger", "product_series": "24.7", "product_tier": "1", "product_version": "24.7.11_14", "product_website": "https://opnsense.org/" } >>> Generating metadata for opnsense-24.7.11_14... done >>> Packaging files for opnsense-24.7.11_14: file sizes/checksums [2262]: .......... done packing files [2262]: .......... done packing directories [0]: . done Creating repository in /usr/obj/usr/tools/config/24.7/amd64/.pkg-new/: .......... done Packing files for repository: .... done >>> Removing packages set >>> Creating package mirror set for 25.1.b_165-amd64... done -rw-r--r-- 1 root wheel 971M Jan 10 14:30 packages-25.1.b_165-amd64.tar >>> WARNING: The build provided additional info. >>> Rebuilt version 24.7.11_14 for opnsense 60.38 real 48.87 user 17.39 sys