Hi All,
I'm trying to setup the CAA to client pc's, however, when i run CAA it comes up with a message, "Could not validate the certificate, CAA will now close"
Please assist.
This thread was automatically locked due to age.
Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.
Hi All,
I'm trying to setup the CAA to client pc's, however, when i run CAA it comes up with a message, "Could not validate the certificate, CAA will now close"
Please assist.
Hi JanVan,
Could you verify that all the details are filled in the "Default" certificate authority in System | Certificate | Certificate Authority | Default? Fill up the details and re-download the client for a fresh installation.
Alongside, make sure MAC binding is not defined for the User definition, who is trying to authenticate from the client.
Hope that helps.
Sachin Gurung
Team Lead | Sophos Technical Support
Knowledge Base | @SophosSupport | Video tutorials
Remember to like a post. If a post (on a question thread) solves your question use the 'This helped me' link.
Unfortunately i'm still getting the same results. All the details were filled in the default certificate.
Hi JanVan,
Thanks for the update. Can you also, update me on the other steps I suggested you? If that doesn't help then, Regenerate Default CA and do not use the apostrophe in any fields.
Finally, please let us know what Firmware resides on the XG.
Thanks
Sachin Gurung
Team Lead | Sophos Technical Support
Knowledge Base | @SophosSupport | Video tutorials
Remember to like a post. If a post (on a question thread) solves your question use the 'This helped me' link.
Hi sachingurung,
Thanks for feedback. I tried all options you suggested and still no luck.
XG 105 (SFOS 16.05.2 MR-2)
Thanks.
Hi JanVan,
There is a bug with CAA and the solution is to regenerate the appliance CA and reinstall the client. If that doesn't work for you, then I worry that you will need to consult support to look into it.
The issue is reported in the bug ID NC-8138.
Thanks
Sachin Gurung
Team Lead | Sophos Technical Support
Knowledge Base | @SophosSupport | Video tutorials
Remember to like a post. If a post (on a question thread) solves your question use the 'This helped me' link.
Hi All,
I think i might have found the issue. The device is producing an invalid certificate, the year for the certificate is 2020.