This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to fix error: "Following domain(s) will not be covered by selected HTTPS certificate."

I am trying to get my ActiveSync setup to work across my Sophos XG 18.5.3 MR-3 install.

I follow the recipe found at https://support.sophos.com/support/s/article/KB-000040209?language=en_US

When I try to save the firewall rule mentioned towards the bottom of the article I get an error:

"Following domain(s) will not be covered by selected HTTPS certificate 'My Mail Cert':

1. mail.mcginnie.plus.com"

This would seem to defeat the entire point of the access rule. So I tried creating another certificate using a CSR with some extra SANs, but get the same sort of result - the error denies that the addresses I want encrypted will work properly.

I can see there is one reference to this sort of error here (https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/129866/automated-certificate-renewals-with-waf-and-cloudflare) where this error is suggested to be ignored.

My setup isn't working - is that because of this error or the recipe is incomplete?

Regards,

    Paul McGinnie



This thread was automatically locked due to age.
Parents Reply
  • The CN=mail.mcginnie.plus.com and Subject Alternative name list has both autodiscover.mcginnie.plus.com and mail.mcginnie.plus.com present (and others). I do not use wildcards - just a list of explicit SANs.

    Having loaded this cert in response to a CSR, and selecting it in the relevant dropdown in the firewall rule specification, then the "Domains" field prepopulated with "mail.mcginnie.plus.com".

    A strange observation is that if I select the Certificate I use for the internal web interface (for which I have a  long list of SANs as possible aliases) then I get a long list of "Domains"

    Regards,

         Paul McGinnie

Children
No Data