Sophos XG - Lets Encrypt broken - Certificate authority: Invalid or not installed

After the latest DST X3 certificate issue. All of my Let's encrypt certificats is not being validated correctly on my Sophos XG. Everything updated to latest version.

I've tried to remove the Let's Encrypt R3 certificates. Re-upload the new ones. Followed all guides available. But still my issue persists.

All my iOS devices accessing WAF sites from the outside, still pukes saying the certificate is expired on 29th september. Even though I've reissued completely new certificates and removed everything i could finde delated to DST...

What on earth is going on?



Added TAGs
[edited by: emmosophos at 10:27 PM (GMT -7) on 12 Oct 2021]
Parents
  • We are facing on all devices the same issue since all created certificates after 1. October !Finally the solution was on our tool win-acme to choose Elliptic Curve key instead of RSA ! After importing the pfx certificate - all untrusted certificates get green ! I am still not able to generate any RSA key based cert on Lets encrypt which will work in Sophos XG or XGS ! I hope that will help someone also ! 

    Funny is that the chain of CA is the same !

    Expert-Zone.Net IT Consulting
    Neuenhofer Weg 23 • D-52074 Aachen

  • Hi I have same issue certifciate is not trusted in sophos but SSLABS check is ok, webserver certificate is bounded but i'm unable to add certificate to admin iterface but other thing are working. Weird Slight smile

Reply Children