Thanks for the workaround... this bug is driving me nuts too. Killing filterdns fixed the issue, at least temporarily for me. After a couple updates, it'll fail again.

No shit. Browsers do not trust MITM certificates by default? Shocking news!

That's not his problem. His browser trusts his "attack" cert perfectly fine. The PFSense OS doesn't trust the cert.

I'm too lazy to dig into what certs PFSense trusts, but likely akamiahd is using a Certificate Authority not trusted by PFSense. I'm not sure what PFSense's policy is on keeping the root certs up to date, but changes are made to that list all the time. You should be able to obtain that root cert and add it into your trusted store yourself.

