Sophos Firewall v22 EAP is now available! Click here to learn more.

Lets Encrypt ACME web server is running even though all has been removed?

XGS3300 (SFOS 21.5.0 GA-Build171)

Created a Lets Encrypt cert 1 month ago but didn't need it and removed everything (including the LE cert).
There is only a NAT rule with 1 service left on that interface without any cert, virtual webserver or HTTP/S configured.

Now a HTTPS website (ACME?) on this site still running and reachable on WAN and also using (the removed!) LE cert.



Not really cool because this site is also listed now on Shodan & Co as running webserver and there is no way to ged rid of this via GUI. Bug?



edited tags
[edited by: Erick Jan at 2:39 AM (GMT -7) on 26 Aug 2025]