<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Lets Encrypt DST Root CA X3 Issue</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/130417/lets-encrypt-dst-root-ca-x3-issue</link><description>Please read this article to fix Web Proxy issues that come up today with some LetsEncrypt sites: 
 https://support.sophos.com/support/s/article/KB-000042993?language=en_US 
 Delete the expired CA from the CA store on the XG. 
 Solved our issues. 
 
 You</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Lets Encrypt DST Root CA X3 Issue</title><link>https://community.sophos.com/thread/479141?ContentTypeID=1</link><pubDate>Fri, 01 Oct 2021 08:20:00 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:57016c73-c9cd-484a-b47f-b9753eebf9b2</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Hotfixes are not easy nor quick to develop as they require many Q&amp;amp;A processes to be involved. Also HF will mess up build numbers and backup/restore process etc.&amp;nbsp; Therefore this is not a good solution for such a change.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;You could remove this CA by using Central Management. Simply remove the DST CA in your group and the Change will be pushed to all firewalls.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>