Sophos XG - Lets Encrypt broken - Certificate authority: Invalid or not installed

After the latest DST X3 certificate issue. All of my Let's encrypt certificats is not being validated correctly on my Sophos XG. Everything updated to latest version.

I've tried to remove the Let's Encrypt R3 certificates. Re-upload the new ones. Followed all guides available. But still my issue persists.

All my iOS devices accessing WAF sites from the outside, still pukes saying the certificate is expired on 29th september. Even though I've reissued completely new certificates and removed everything i could finde delated to DST...

What on earth is going on?

Added TAGs
[edited by: emmosophos at 10:27 PM (GMT -7) on 12 Oct 2021]
Parents Reply
  • I had exactly the same behavior on my XG125. The behavior only occured when the certificate is created as pfx from Windows. If the certificate is created under Linux with Certbot, the certificate is still not trusted during import, but the expired branch is not delivered by the XG and the clients can access the servers through WAF.