This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Signing Certificate loses chain when imported

I've just set up Decrypt and Scan for HTTP traffic on a UTM 9.509-3 box, and I'm having some trouble with the certificate that the UTM uses to sign the response back to the client.

Under Web Protection -> Filtering Options -> HTTPS CAs -> Verification CAs, I've successfully imported the public certificate of my Active Directory Intermediate Certificate Authority.  As I understand, that means the UTM trusts any certificate signed by that CA now.

I've then used the same Intermediate CA to generate a Subordinate Certificate authority certificate, exported it in PKCS#12 format along with the Private key, and uploaded it to the UTM under Web Protection -> Filtering Options -> HTTPS CAs -> Signing CA.  All seems to work OK, so far so good.

However, now when browsing HTTPS sites, the certificate generated by the UTM doesn't have any chain attached to it, so the client thinks it's an untrusted certificate.

 

Have I missed something in the configuration?



This thread was automatically locked due to age.
Parents
  • Hi Gary - first I've seen you here - welcome to the UTM Community!

    I don't think using an intermediate CA or a Subordinate CA works with the UTM Proxy.  You might want to open a case with Sophos Support to ask that question - please come back here and confirm or refute my comments here.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi Gary - first I've seen you here - welcome to the UTM Community!

    I don't think using an intermediate CA or a Subordinate CA works with the UTM Proxy.  You might want to open a case with Sophos Support to ask that question - please come back here and confirm or refute my comments here.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data