Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall 21 daily letsencrypt request error

Apparently since the last firmware update my Sophos Home Firewall has been renewing my LetsEncrypt certificates daily, which has caused an error on LetsEncrypts end since I am basically flooding their service. This has resulted in all of the letsencrypt certs not being renewed and I have had to disable the function in order to let the clock reset. 

Has anyone else had this bug?



Edited TAGs
[edited by: Erick Jan at 3:24 AM (GMT -8) on 6 Jan 2025]
Parents
  • I have included a screenshot here to show what the problem is. ALL of my LE certificates are acting up, which is strange since this exact configuration worked fine with the UTM 9 and absolutely nothing has been changed since. 

  • Yes, unfortunately if you run into the rate limit issue, then all your certificates will be flagged on the UI, however that's not a valid error flag, all are usable, except the one with the type CSR, which is also the one causing the issue itself. It was the one that hit the rate limit due to the bug I've mentioned. You have to delete that CSR and wait at least one week before trying to recreate it, otherwise it will just reset the rate limit ban. The warning flag should disappear from the other certificates after the next refresh cycle, which happens randomly during the night, so you can expect them to disappear the day after you have removed the CSR.

Reply
  • Yes, unfortunately if you run into the rate limit issue, then all your certificates will be flagged on the UI, however that's not a valid error flag, all are usable, except the one with the type CSR, which is also the one causing the issue itself. It was the one that hit the rate limit due to the bug I've mentioned. You have to delete that CSR and wait at least one week before trying to recreate it, otherwise it will just reset the rate limit ban. The warning flag should disappear from the other certificates after the next refresh cycle, which happens randomly during the night, so you can expect them to disappear the day after you have removed the CSR.

Children
No Data