This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG: Cannot change WAF Certificate

Hi there

Last week, my wildcard certificate expired. No biggie. Got a new one, imported it into the firewall, everything ok. When I selected the new certificate in my WAF rules, I was able to save this configuration and expected the firewall to use this certificate from now on. But no. No matter what I configure, I still get the old, now expired certificate.

SFOS 19.0.0 GA-Build317

Any hints?

Regards, Patrick



This thread was automatically locked due to age.
Parents Reply Children
  • There is nothing unusual going on in the Live Log. It all works fine, just using the wrong certificate. 

    I was able to change the SMTP TLS certificate though as well as the web certificate used for the management webpage of the firewall. So the certificate can be used by the firewall, just not by the WAF. No matter which WAF rule I try to change, even ones using completely different certificates (Let's Encrypt), I'm not able to make the change in certificate appear on the browser-side of things. 

    Here an example of a WAF rule: 

    I get presented with the expired certificate, which is still in the Firewall certificate tab, but cannot be selected anymore in WAF rules. 

    even though I used the new one in the rule which is valid until 2023

    And I cannot delete the expired certificate, because it claims to be still used somewhere...



  • The CSC log in debug mode should give you some clue as where the certificate might be being used.

    To put csc in debug mode run from the advanced Shell (5>3)

    #csc custom debug

    Then try deleting the certificate from the GUI.

    Stop debugging

    #csc custom debug

    And then grep for the following "delete_certificate"

    # less /log/csc.log | grep "delete_certificate"

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 

    Log a Support Case | Sophos Service Guide
    Best Practices – Support Case


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • I tried something else: There was a deactivated WAF-Rule which was still using the expired certificate. I changed this certificate and within seconds after saving the config of that disabled WAF-rule, everything was up and running with the new certificate. I didn't change anything else...

    No idea why, but apparently removing the old certificate from all possible rules did the trick... 

  • Hi Patrick, 

    Is your disabled WAF rule placed higher than other WAF rules in your Firewall rules list? 

    Does your disabled WAF rule show as enabled or disabled in the Firewall rules list (can you share a screenshot)?