SEC_ERROR_REUSED_ISSUER_AND_SERIAL error when using Decrypt HTTPS websites using SSL/TLS in EAP using Firefox

I am seeing this error intermittently when browsing in Firefox on a device with SSL/TLS decryption of HTTPS websites enabled. I have the ImportEnterpriseRoots setting enabled in Firefox to import the Sophos root CA. Browsing will work for a period of time and I can see looking at the certificate chain that the root CA is a Sophos one so HTTPS Interception is working. However, after period of time (usually a few hours) any sites I browse to will generate the following error SEC_ERROR_REUSED_ISSUER_AND_SERIAL. If I close and reopen all browser windows, I am able to successfully browse to the same sites again.

Googling this error points to articles that mention that deleting the certificates or CAs that cause the issue but this is not sustainable when we look to roll this out to 500 users. https://support.mozilla.org/en-US/kb/Certificate-contains-the-same-serial-number-as-another-certificate

Looking at the certificate authority in Windows for the Sophos Endpoint, it looks to be generated today. Is it a case that the certificate is not a static certificate but is one that changes regularly and could this be causing this issue?

Parents
  • We're experiencing this in our environment as well.

    Disabling "Internet" slider (under "Real Time Scanning") on the client after turning tamper protection off allows Firefox to load HTTPS sites correctly (after a few seconds delay for the change to take effect). Restoring the "Internet" slider brings the issue back.

    This does not affect Chrome.

    Version info:
    Core Agent - 2.20.13
    Endpoint Advanced - 10.8.11.4
    Sophos Intercept X - 2021.3.1.12

    Firefox - 101.0 (64-bit)

Reply
  • We're experiencing this in our environment as well.

    Disabling "Internet" slider (under "Real Time Scanning") on the client after turning tamper protection off allows Firefox to load HTTPS sites correctly (after a few seconds delay for the change to take effect). Restoring the "Internet" slider brings the issue back.

    This does not affect Chrome.

    Version info:
    Core Agent - 2.20.13
    Endpoint Advanced - 10.8.11.4
    Sophos Intercept X - 2021.3.1.12

    Firefox - 101.0 (64-bit)

Children