<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SSL/TLS inspection shows wrong certificate type</title><link>https://community.sophos.com/sophos-xg-firewall/sfos-v18-early-access-program/f/feedback-and-issues/118034/ssl-tls-inspection-shows-wrong-certificate-type</link><description>Hi all, 
 
 maybe this is a bug, or i am just doing things wrong. 
 I create and imported a new test certificate authority with openssl with secp384r1 for testing the new SSL/TLS inspection with using an ec certificate for re-encryption. 
 The gui itself</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: SSL/TLS inspection shows wrong certificate type</title><link>https://community.sophos.com/thread/427727?ContentTypeID=1</link><pubDate>Tue, 04 Feb 2020 15:39:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:fc30e199-46a0-4f10-a07e-e85ab28304df</guid><dc:creator>Michael Dunn</dc:creator><description>&lt;p&gt;Confirmed there is a bug.&lt;/p&gt;
&lt;p&gt;EC CAs that contain all fields show up as (EC).&lt;/p&gt;
&lt;p&gt;EC CAs that are missing some fields/extensions are valid, but show us as (RSA).&lt;/p&gt;
&lt;p&gt;Will be fixed post-GA.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: SSL/TLS inspection shows wrong certificate type</title><link>https://community.sophos.com/thread/427186?ContentTypeID=1</link><pubDate>Wed, 29 Jan 2020 22:30:39 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b1857fba-0a89-44aa-8508-5dc91bc7d566</guid><dc:creator>Michael Dunn</dc:creator><description>&lt;p&gt;We just tested with a similarly built CA and did not have this problem.&lt;/p&gt;
&lt;p&gt;Is is possible for you to send me in a private message: the PEM, Key, and passphrase so we can try your exact CA?&lt;/p&gt;
&lt;p&gt;You could even create a new one with the same steps if you are concerned with send me a your real CA.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In case it is not a CA problem, but configuration, if you open a support tunnel (diagnostics, support access) I can have a quick look at your box rather than asking for a bunch of screenshots.&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>