Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Upload Certificate - Certificate could not be generated

When I try and upload a certificate to our firewall I am getting the below error. I've tried this in Chrome, Edge and Firefox 

The response shown in the browser in dev mode is below:

{"transactionID":"23415539","status":500,"message":"Message.CertEditGenerateFailed","entity":{"map":{"hextimestamp":"A","___serverport":4444,"certformat":"pkcs12","certfile":"/sdisk/upload/88ee5337-512e-4a00-9777-400cf381dcef.pfx","___component":"GUI","type":"u","transactionid":"23415539","uploadcertpassword":"xxxxxx","mode":359,"certop":"u","uploadcertname":"dc","currentlyloggedinuserid":70,"APIVersion":"2000.1","___serverprotocol":"HTTP","certificatename":"dc","isdefault":"n","___username":"xxxx","___meta":{"map":{"sessionType":1}},"___serverip":"127.0.0.1","currentlyloggedinuserip":"192.168.212.54"}},"redirectionURL":""}

I found the following old post, but changing browser made no difference. SFOS 18.0.5 MR 5 - Certificate Could Not Be Generated - Discussions - Sophos Firewall - Sophos Community

We are currently running SFOS 20.0.0 GA-Build222

Does anyone have any suggestions how this might be resolved?

Since the certificate has expired RADIUS auth used by the SSL Remote Access VPN has started failing with the below event log on the RADIUS server:

Reason:AADSTS700027: The certificate with identifier used to sign the client assertion is expired on application. [Reason - The key used is expired., Thumbprint of key used by client: '887E03AB21B9E330A43476EB25713B55FD1B32C4', Found key 'Start=01/04/2023 16:44:51, End=01/03/2025 16:44:51'

The expiry date of the certificate I am trying to replace is similar, but not the same. The SSL VPN is now set to use the appliance certificate, but still does work, so I am hoping this is related and will work once the certificate is updated.



Added TAGs
[edited by: Raphael Alganes at 1:26 PM (GMT -8) on 6 Jan 2025]
Parents
  • This seems to have been caused by two separate issues.

    As a last ditch effort we rebooted the XGS136 and it didn't finish booting back up. We were unable to log into either XGS136 (we have two in HA) and had no internet access. After half an hour we turned it off and back on and when it started backup the status light was red. It did fail over at that point and we got internet access back and could connect to the admin page on the second XGS136. On the other device I was able to upload the certificate with no issue so I wonder if the problem was caused by a hardware issue?

    The failed device we turned off for 30 minutes then back on. It is now showing green on the status light now it has booted up. HA is showing healthy as well, but I'm not confident in the device that failed anymore.

    The issue logged on the RADIUS server was the same as this problem, which we have now resolved TenantID certificate, for VPN MFA expired. How renew? - Microsoft Q&A

Reply
  • This seems to have been caused by two separate issues.

    As a last ditch effort we rebooted the XGS136 and it didn't finish booting back up. We were unable to log into either XGS136 (we have two in HA) and had no internet access. After half an hour we turned it off and back on and when it started backup the status light was red. It did fail over at that point and we got internet access back and could connect to the admin page on the second XGS136. On the other device I was able to upload the certificate with no issue so I wonder if the problem was caused by a hardware issue?

    The failed device we turned off for 30 minutes then back on. It is now showing green on the status light now it has booted up. HA is showing healthy as well, but I'm not confident in the device that failed anymore.

    The issue logged on the RADIUS server was the same as this problem, which we have now resolved TenantID certificate, for VPN MFA expired. How renew? - Microsoft Q&A

Children
No Data