Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Adding Certificates

Good day. I would like to ask for your assistance about adding an updated certificate to publish my webserver. When I try to add a certificate, It  will not show up on my Business application rule>>>> Https Certificate Entries. I uploaded the .dem file or the .cer file but it wont show up.

Thank you so much.

Regards,

Daryll



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi, Thanks for reaching out to Sophos Community.

    Make sure that you're importing the certificate with the Private-key. Certificates uploaded (PEM or CER or DER) without private keys could appear valid (if the intermediate and root CA are present) but you can't use the certificates without private-key with WAF Business application rules. 

    A private key is usually generated along with CSR and then CA uses the CSR and gives you the signed certificate. 

    For example, Importing a certificate without a private key is shown as valid but isn't available to use in WAF rule






  • Hi Davesh,

    Good day. I already solved the issue. I downloaded the ssl certificates files (PEM, CER and PK7) files and converted it to make it a .PFX.

    After that to produce  a .key format which is required for the Sophos XG, I use an Open SSL program.

    It is now working.

    Thank you all for the advise.

    Daryll

  • FormerMember
    +1 FormerMember in reply to dimebagdaryll

    Glad to hear :) 

    For future reference, Ensure to generate/save the private key while generating the CSR. It'll make the rest of the process easier.

    You can either use a Certificate + Priv Key combo or just convert to PKCS12 as you did.

Reply
  • FormerMember
    +1 FormerMember in reply to dimebagdaryll

    Glad to hear :) 

    For future reference, Ensure to generate/save the private key while generating the CSR. It'll make the rest of the process easier.

    You can either use a Certificate + Priv Key combo or just convert to PKCS12 as you did.

Children