Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Howto add wildcard Comodo SSL certificate

Hi,

 

I have a wildcard certificate from Comodo, so i received a package with a certificate.crt / certificate.key and certificate.p7b files. Since its a wildcard i figured i would not have to create a CSR from the XG device. I did add a certificate but it gave me a red cross. So i read some forum posts about getting the Comodo root certificate and install that one first. I did this. Then i added my own certicicate.pem (i concerted it to pem) with my certificate.key file. It still gives me the red cross.

What am i doing wrong?


Regards,

Peter



This thread was automatically locked due to age.
Parents
  • When you move your mouse over the red cross, what extra information do you see?

    If it says "Expected Issuer ....CN=..." it means you uploaded a wrong Comodo Root CA certificate.

    Download the "expected" CA certificate from the Comodo website

  • Hi 2ServeErik,

     

    I did that, this is the output:

    Then i downloaded this cert from Comodo website, file: comodorsadomainvalidationsecureserverca.crt

    When i try to import it i get:

    So then i ran out of ideas..

  • On my Sophos XG I also have a Comodo wildcard with the same CA as in your first screenshot.
    I deleted this "Comodo RSA...CA" certificate and a red cross appeared next to my wildcard.

    I downloaded the file "comodorsadomainvalidationsecureserverca.crt" from the Comodo website and changed (renamed) the file extension to "comodorsadomainvalidationsecureserverca.pem". Then uploaded it to Certificate Authorities in my Sophos XG. On the certificates tab my red cross was gone!

    So it should work for you to.

    Try this:

    1.delete your wildcard certificate

    2. find the "already existing" CA certificate in the Certificate Authorities Tab and delete that as well

    3.change the extension of the downloaded "comodorsadomainvalidationsecureserverca.crt" file to .pem and upload it again: Name = Comodo and choose .pem as the Certificate File Format

    4.add your certificate and wildcard again (try to use the .p7b file you received from Comodo then there's no need to upload your private key separately

    Good luck

  • Thanks, your trick worked, but i had the wrong certificate. When i googled on: "comodo rsa domain validation secure server ca download" 

    i used this link: https://support.comodo.com/index.php?/Knowledgebase/Article/View/970/108/intermediate-2-sha-2-comodo-rsa-domain-validation-secure-server-ca

    But this is the wrong certificate. When i got this one: https://static.kinamo.be/crt/comodo/comodorsadvsecureca.crt it all went fine.

     

    Thanks again!

  • Hello Guys,

    I have the same problem but with Kerio mail server certtificate.

    The client has .crt and .key files but cannot upload neither certificate nor CA.

    And again same red cross.

    After a while an admin generated .pem certificate file from his browser and now I had this situation:

    and I cannot use it neither for IMAPS nor for SMTPS connection(in/out).

    The issuer is expected but I cannot upload .pem file in CAs.

    Any help? Please ? :)

    Maybe just renaming will help?

Reply
  • Hello Guys,

    I have the same problem but with Kerio mail server certtificate.

    The client has .crt and .key files but cannot upload neither certificate nor CA.

    And again same red cross.

    After a while an admin generated .pem certificate file from his browser and now I had this situation:

    and I cannot use it neither for IMAPS nor for SMTPS connection(in/out).

    The issuer is expected but I cannot upload .pem file in CAs.

    Any help? Please ? :)

    Maybe just renaming will help?

Children