maintainer-feedback requested: [Bug 294656] ports-mgmt/pkg pkg audit fails to validate certificate

From: <bugzilla-noreply_at_freebsd.org>
Date: Mon, 20 Apr 2026 01:05:45 UTC
Bugzilla Automation <bugzilla@FreeBSD.org> has asked freebsd-pkg (Nobody)
<pkg@FreeBSD.org> for maintainer-feedback:
Bug 294656: ports-mgmt/pkg pkg audit fails to validate certificate
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294656



--- Description ---
Since pkg 2.7.4, might be earlier, but definitely not with 2.6, I started
getting
the following complains:

solo% sudo pkg audit -F 						      ~
Certificate verification failed for /C=US/O=Let's Encrypt/CN=E7
10300F0108000000:error:0A000086:SSL
routines:tls_post_process_server_certificate:certificate verify
failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /C=US/O=Let's Encrypt/CN=E7
10300F0108000000:error:0A000086:SSL
routines:tls_post_process_server_certificate:certificate verify
failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
Certificate verification failed for /C=US/O=Let's Encrypt/CN=E7
10300F0108000000:error:0A000086:SSL
routines:tls_post_process_server_certificate:certificate verify
failed:/usr/src/crypto/openssl/ssl/statem/statem_clnt.c:1890:
pkg: https://vuxml.freebsd.org/freebsd/vuln.xml.xz: Authentication error
pkg: cannot fetch vulnxml file

Not sure what changed with the system, base is stable/15 with between week and
month
old (this happens on all my machines).