Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Problem with NET::ERR_CERT_AUTHORITY_INVALID still present?

Hi,

I have ONE of 3 new installs of XGS-126 having long known problem with Sophos CA certificates on some popular URL addresses. For example, users cannot download Google Chrome:

I guess problem is HSTS, where browser detects MITM, which is Sophos box. 

I already disabled microapps in console, recreated CA certificate, restarted Tomcat service...but beside this being ridiculous after so many years, it still does not work. Went through dozens of forums and threads here, but cannot find a solution.

Any idea, hint? Please & thanx!



Added TAGs
[edited by: Raphael Alganes at 1:49 AM (GMT -7) on 4 Jul 2024]
Parents
  • UPDATE - SOLVED: 

    As it turned out after examining firewall logs, it was "DEFAULT" WEB POLICY, which is blocking unwanted freeware, clasifying Google Chrome as unwanted app. Changing WEB POLICY in firewall rule to something else, for example "Default Workplace Policy" resolved the issue.

    Maybe Sophos could put some effort into resolving the behavior in such a way, that it would be clear to user and administrator whet's going on, instead of just letting HSTS do it's job. In technical equivalent it would be like, nevermind brake failure, let it just hit the wall, it is designed to absorb impact.

Reply
  • UPDATE - SOLVED: 

    As it turned out after examining firewall logs, it was "DEFAULT" WEB POLICY, which is blocking unwanted freeware, clasifying Google Chrome as unwanted app. Changing WEB POLICY in firewall rule to something else, for example "Default Workplace Policy" resolved the issue.

    Maybe Sophos could put some effort into resolving the behavior in such a way, that it would be clear to user and administrator whet's going on, instead of just letting HSTS do it's job. In technical equivalent it would be like, nevermind brake failure, let it just hit the wall, it is designed to absorb impact.

Children