Software-update: pfSense CE 2.9.0

pfSense logoVersie 2.9.0 van de Community Edition van pfSense is uitgekomen. Dit pakket is gebaseerd op het besturingssysteem FreeBSD en richt zich op router- en firewalltaken. Het is verkrijgbaar in de gratis Community Edition en een betaalde Plus-uitvoering, die voorheen als Factory Edition werd aangeboden. Het is in 2004 begonnen als een afsplitsing van m0n0wall vanwege verschillende visies bij de ontwikkelaars en in de loop van de jaren uitgegroeid tot een router- en firewallpakket dat in zowel kleine als zeer grote omgevingen kan worden ingezet. Voor meer informatie verwijzen we naar deze pagina. In deze uitgave zijn de volgende veranderingen en verbeteringen aangebracht:

SSH Algorithms

This release includes several changes to algorithms for the SSH daemon for key exchange, encryption, and message authentication. These changes increase security by including post-quantum key exchange algorithms and by removing older and weaker algorithms.

TLS Certificate Strength

The version of OpenSSL in this release further tightens certificate requirements and removes support for certain weak properties. For example, if a TLS server certificate for a service such as the GUI has a weak key (<2048 bits), the service may fail with an error such as “key too small”. This version of pfSense software checks the GUI certificate during the upgrade process and will re-generate a new GUI certificate if the current certificate is invalid, expired, or weak.

TLS Certificate Auto-Renew

This version of pfSense software can automatically renew TLS server certificates which are self-signed or signed by an internal CA stored in the pfSense software configuration. Automatic renewal is a per-certificate option, and pfSense software automatically enables this option for the GUI certificate when possible. When automatically renewing a certificate, pfSense software uses the latest strict security options to ensure the certificate meets current standards.

Endpoint-independent Port Restricted Cone Outbound NAT

This version includes partial experimental support for “Port Restricted Cone” endpoint-independent outbound NAT. “Port Restricted Cone” NAT mappings attempt to preserve port and external address mappings for clients when speaking to multiple remote hosts, but in a dynamic way that does not rely on static port NAT. This helps avoid issues with multiple local clients using the same source port to the same remote host.

Security Updates

This Release software includes critical security updates for WireGuard (CVE-2026-58085), as well as fixes for the following security fixes:

Security and errata fixes were merged from FreeBSD, including fixes for vulnerabilities discovered in OpenSSL and the DHCP client, and base system packages were updated to address various upstream security issues.

Operating System and Base Component Updates

Numerous systems were updated, including:

  • Base OS updated to FreeBSD 16-CURRENT
  • OpenSSL upgraded to 3.5.7
  • OpenSSH upgraded to 10.3p1
  • PHP updated to 8.5.7
Hardware Errata

Certain hardware with a specific firmware problem, including some Celeron J devices, may encounter a kernel panic when attempting to boot pfSense CE software version 2.9.0. To avoid this panic on that hardware, set a loader tunable for hint.acpi_spmc.0.disabled=1 in /boot/loader.conf.local before upgrading to disable the driver that has an issue on that hardware. See Managing Loader Tunables for information on how to edit or create that file.

Release Notes

Release Notes for pfSense CE 2.9.0-RELEASE are available for a more comprehensive list of new features, bug fixes, and other changes in this release.

pfSense Community Edition

Versienummer 2.9.0
Releasestatus Final
Besturingssystemen BSD
Website Netgate
Download https://www.pfsense.org/download
Licentietype Voorwaarden (GNU/BSD/etc.)

Door Bart van Klaveren

Downloads en Best Buy Guide

21-08-2026 • 16:30

0

Submitter: paul2406

Bron: Netgate

Update-historie

Reacties

Sorteer op:

Weergave:

Er zijn nog geen reacties geplaatst


Om te kunnen reageren moet je ingelogd zijn