FreeCORE Home Install Demo Documentation

Update Security

Describes how FreeCORE updates are signed and verified.

FreeCORE operates its own update infrastructure. Systems and manual downloads use updates.freecore.org.

Every update manifest is cryptographically signed with the key for its train. The updater verifies that signature with the installed train certificate and refuses a manifest that does not verify. Each train certificate is issued by the FreeCORE Update CA; the CA and the FreeCORE train certificates ship with the system.

Verify the Update CA

The SHA-256 fingerprint of the FreeCORE Update CA is:

50:DF:7A:7C:49:44:58:AE:13:57:AE:90:E1:95:D0:01:53:FC:59:30:2E:50:7C:B4:E3:33:A2:FB:F6:E0:AD:08

An independent copy is published in the canonical Codeberg source repository as freecore-update-ca.pem. Its fingerprint can be calculated with:

openssl x509 -in freecore-update-ca.pem -noout -fingerprint -sha256

The 13.3 enrolment guide explains where this check fits in the move to FreeCORE. The enrolment script verifies that the stable-train certificate chains to this CA before installing that certificate on 13.3.

Rollback and Return

Updates install into a new boot environment. Selecting an earlier boot environment from System > Boot or the boot menu returns the operating system and the configuration stored with it. It does not rewind storage pools, user data, or every shared system dataset.

After an eligible in-place move from TrueNAS CORE 13.3, FreeCORE captures a persistent 13.3 return. It does not expire automatically. System > Update shows the origin boot environment, capture time, return availability, retained-space accounting, and the Return to 13.3 action.

The capture records the 13.3 origin boot environment together with recursive snapshots of the matching .system dataset and the complete active iocage tree. The return restores that captured set, activates the recorded origin boot environment, and reboots. The configuration stored with that boot environment returns with it. Unrelated user datasets are not rewound.

Returning is destructive to the captured areas: post-capture system state, jail and plugin changes, and data stored inside the iocage tree are discarded. Data that a jail or plugin stores in an unrelated user dataset is not restored.

There is no automatic expiry. The captured return persists until it is used, you select Remove Captured Return, or you explicitly forfeit it by confirming an incompatible pool-feature upgrade. The snapshot-space figure is a lower bound for space retained by the recorded snapshots. The pinned boot environment's deletion estimate is shown separately; it is not included in that lower bound.

Remove Captured Return destroys the recorded snapshots and releases the origin boot environment pin. It does not delete the boot environment. If cleanup is incomplete, the remaining state stays visible and Retry Cleanup tries the unfinished work again.

The action is also unavailable when the origin boot environment or a recorded snapshot is missing, or when the system dataset or active iocage dataset has moved since capture. An installer-ISO installation captures nothing because it has no 13.3 origin state. If the captured return is absent or unavailable, do not substitute manual activation of an old boot environment; restore through the backups made before the move instead.

See Move from TrueNAS CORE 13.3 for the preparation and enrolment procedure.

FreeCORE 15.0 systems use the FreeCORE-15.0-STABLE train. See Updating FreeCORE for how updates work.