Manjaro is the worst of the most popular distros.
I thought this was an anniversary of a funny event that happened one time type of meme. But no. It has happened NINE TIMES, including today.
My first distro & my never again distro. Rest in piss, manjaro
Same here. I mean, Pop OS was technically my first, but I only used that for like 2 weeks and then switched to Manjaro.
This is literally why I stopped using Manjaro.
I’ve botched 2 Manjaro installs just doing a
pacman -Syuwhile their certs were expired and I ended up with an incomplete upgrade.Never once had this issue with EndeavorOS.
Look, I don’t want to call you a liar… so let’s say maybe you meant to say
pamacor got things wrong.Because:
- That’s not how
pacmanworks. If it hits a mirror with expired certs it just outputs a warning and uses another mirror. - On a fresh install Manjaro will compile an optical subset of mirrors for you based on location and response time. Those mirrors are spread around the world on different domains. It’s very unlikely that your list would include ONLY
mirrors.manjaro.organdmirrors2.manjaro.org. - But even if it did, and let’s say for the sake of argument there is a bug in pacman AND you got those mirrors… those two hosts are on a different certificate from manjaro.org (the website), are CNAME’d to
.rsc.cdn77.orghosts, get renewed automatically separately from the website cert, and have never been allowed to lapse afaik.
Maybe it wasn’t due to certs, but it still happened. That was enough for me to switch distros. I was much less experienced with Linux back then, so I wasn’t able to figure out how to get it working again.
So far I’ve daily-driven EndeavorOS, Mint, PopOS, and Kubuntu. None of them have broken themselves with an apt or pacman upgrade.
- That’s not how
Doesn’t happen with Antergos either.
I mean, I’ve gotten a NXDomain error ever since they shut down, but at least it’s not a certificate expiry!
Yep… Validation of my decision to cachyos after my last drive needed surgery.
some iconic duos in the Linux community: Arch and AUR malware, Ubuntu and bad updates, NixOS and community/team members leaving, Manjaro and failing to renew its cert.
AUR malware
Really, something like this ever happened lol?
I’m sure it has. The idea that it’s frequent is unhinged.
Wait…please tell me y’all heard of that crazy drama recently where there was tons of AUR packages getting infostealer malware added in.
They got a lot more cautious after that incident but… I’m less keen on the AUR now…
Edit: https://archlinux.org/news/active-aur-malicious-packages-incident/
Welcome to Linux, do you want the BenevolentDictatorOS, WeaponsManifaturerOS, MalwareOS or Debian?
Debian and shipping broken packages
Bruh what? I went to debian for server because of stability. It only updates like once a decade and still ships broken packages?
Its intended behavior from Debian team. because they ships a version of the software at the time and only backport security patches. So if the version they ship has bugs then those bugs stay for years. This generates quite a bit of noise for upstream projects but it is what it is.
you forgot the oldest of them all, Debian and the its museum, their repos
Ubuntu and bad updates
This is the only drama in your list I’m not familiar with already. What/when did they last break?

Recently, the nvidia-dkms driver updates wouldn’t build for 5.x series kernels, so if you hadn’t cleaned up old kernels, the update bombed out before updating the initrd filesystem, the system couldn’t boot without intervention. Thankfully, I noticed before trying to reboot my work desktop, and the solution was “apt autoremove && apt upgrade”.
But the install media for my desktop at home was 18.04, and it’s running 26.04 now. It has an AMD GPU, so it hasn’t had update problems.
If your playbooks don’t include an autoremove, you’re doing it wrong!
Or rather, lessons learned from when the default /boot partition was only like 100 MB.
deleted by creator
Again??? Again???
BINGO!
In fact I got a full 5x5 card of bingo because I wrote “Manjaro doesn’t renew its cert” in all of the boxes.
oh my god AGAIN?!
They gotta be trolling the entire linux userbase at this point.
deleted by creator
The certificate for manjaro.org was renewed only a few hours ago. Given Manjaros track record, they probably let the cert expire (again) and fixed it since the original screenshot was taken.
The screenshot seems to be taken at 1:50 utc, and the new certificate was valid from 00:18 utc. It is possible though that they just.enrolled the cert too late.
I like a distro with problems that I can relate to.
Bad memory/routines? We have to be related. Since that feels like me.
HOW THE FUCK DID THEY MANAGE IT AGAIN
Why set a reminder when an expiration will do the same job
They managed this again by not actually managing it… again.
They have embraced the meme
Why isn’t this an automated processs for them?
Why isn’t this an automated processs for them?
Because
manjaro.orgis controlled personally by Phil, the CEO of the company, who’s paranoid about letting anybody else handle it. And also can’t figure out how to renew automatically, apparently. People have to remind him on Discord. 🤦Everything else
*.manjaro.org(forums, mirrors etc.) is handled by different people and have never expired afaik.It’s literally just the main webpage that has this problem, everything else about the distro is never impacted.
Why isn’t it for everyone? How often I see this with, I mean, major actors is head shakingly baffling.
I work in tech for telco and the amount of people around me who have zero clue about x509/TLS/certificates in general is absolutely baffling
I work in a telco and I have no clue what you just said to me.
But in tech?
I wonder if they are still on an old cert system.
This came up last time the cert expired iirc.
Tl;dr one of the founders is holding up the infra not allowing any change. According to someone who worked on Manjaro, it was trivially easy to get this fixed, but that single person simply wouldn’t approve it. Last I checked they sent the founder an ultimatum: either hand over the project or see the staff walk. I suppose the staff walked.
I think you’re refering to this. The community appears to be in the process of setting up their own association and eventually the infrastructure and assets will be transferred to them. We’ll see how that shakes out.
Sad. With FOSS you have to be able to let go.
Manjaro once again demonstrating they’re not a serious distro/project, hahaha
At this point, it’s a tradition!
Holy shit this is so stupid I can’t defend them anymore 😂😂
The funniest thing about this is that it needs a single Bash script and a cronjob to solve (unless they got a REALLY bad hoster).
That bash script probably exists a bazillion times already… so even an LLM could spit it out for them.
Their organisational structure must be abhorrent for nobody to feel even remotely responsible for this.
Most web server have ACME support built-in nowadays, setup is a matter of minutes, no scripting required. This has been a solved problem for years, any sysadmin who can’t handle this basic task has no business running public-facing servers.
Yeah, caddy automatically renews certs by default, as does traefik as far as i can tell, and certbot installs a timer for this.
Nginx as well
Yeah sure but in significantly distributed environments I’m sure there’s more complexity to it than that
Sure but that’s a solved problem as well.
And if they can’t handle distributed systems, they’re the worst possible choice to maintain a distro - a massive distributed system of PCs
And my friends wonder why I recommend against Manjaro…
I jumped ship after 2 times. Such a shame because I loved the OS but this is the opposite of what I expect a distro to do.






















