This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

expiration warning Proxy-CA after renew

After we renew the Proxy CA cert on every day the admin receive an email with an expiration warning of the old certificate. 
We can download the right certificate from the UTM for the clients (http_proxy_signing_ca.cer).

Reboot not helps.

It is only a cosmetical bug? How can we resolve this?

 

Thanks Heiko



This thread was automatically locked due to age.
  • Hi, Heiko, and welcome to the UTM Community!

    At least one other person has reported this here, so I suspect it's a bug.  Before 9.5, there were no such warnings.  If you examine the Proxy CA, I think you'll see that it expires in 2038.

    A support ticket would not be inappropriate.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    thank you for reply and your answer. Expiration after the renewal is in 2020. Because the customer didn't have a Support contract, we cannot open a Service request. Had called to Sophos Germany already. I think, we have to wait.

    Kind regards Heiko

  • Definitely a bug, i have the same issue on several UTMs

    Sophos UTM 9.3 Certified Engineer
    Sophos UTM 9.3 Certified Architect
    Sophos XG v.15 Certified Engineer
    Sophos XG v.17 Certified Engineer
    Sophos XG v.17 Certified Architect

  • Thanks Kenneth,

    many thanks for your answer.

    if it is a cosmetical bug only, it's not a big problem. The CA expiration time will be in about 14 days. Question is, what really will happens. The Proxy will works fine after this date or not.

     

    Cheers Heiko

  • Mine is in 30 days, I don't think it will matter i my case since i don't do any SSL MITM/intercepting in the webproxy. I do only use HTTPS URL Filtering

    Sophos UTM 9.3 Certified Engineer
    Sophos UTM 9.3 Certified Architect
    Sophos XG v.15 Certified Engineer
    Sophos XG v.17 Certified Engineer
    Sophos XG v.17 Certified Architect

  • Just to be clear, guys, we're talking about the Proxy CA ("Signing CA") downloaded from the 'HTTPS CAs' tab in 'Web Filtering >> Filtering Options' - right?

    I can't believe that doesn't show 2038...

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Yes, we are talking about the Proxy CA and it is valid for three years from time of creation.

     

    I have the same behaviour on several machines (getting expiration warnings after having recreated the CA).

     

    I belive it's cosmetical but a bug.

     

    BR,

    Michael

  • Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Try to create a new one...

    Guess your certificate has been created with 6.x or 7.x. Things changed since...

    BR,

    Michael

  • Generated in 2012 with 8.3, but I see that the behavior has changed - interesting!

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA