• Root Certificate automatically included by WAF of Sophos Firewall?

    Markus Quirmbach
    Markus Quirmbach
    Hi everyone! We are using a Sophos XGS2300 (SFOS 19.0.1 MR-1). We uploaded a pfx-certificate to the WAF which specifically included only the webserver certificate itself and its intermediate certificate. But, when we check the site with a tool like…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Using factory SSL certificate for DPI/Filtering

    MHSWA
    MHSWA
    Hi All I've been using my XG210 now for a few years, but I've always had random issues with DPI/Web Filtering, around 10% or more of the time I have users who will see the self signed certificate wanting when going to a site they shouldn't be on then…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Cannot delete certificate - "Couldn't delete certificate. It's in use in an IPsec, L2TP, or SSL VPN connection."

    EdmundSackbauer
    EdmundSackbauer
    I am on 19.0.MR1 I have an uploaded certificate which is no longer needed. It was used in WAF rules, those were deleted a couple of weeks ago. However I cannot delete the certificate, I get the red box at the top with " Couldn't delete certificate…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Certificate / Certificate Authority Issue for delete and/or import

    Kay-Uwe Keser
    Kay-Uwe Keser
    Hello, I have a issue for validation the imported Lets Encrypt Certificate. I issued the certificate with certbot and uploaded it with le2xg.sh. That is working. Sophos XG 18.5.4 MR4 But the certificate is still marked as untrusted. I read some…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Uploaded Certificate in Sophos XG Firewall Showing Not trusted

    Elianshikira Ndossi
    Elianshikira Ndossi
    I uploaded the certificate in every format (.pem,.pfx,.Cer) but none of showing trusted and always showing RED (X) in trusted. Please assist me to fix on this issue at earliest. Please find the attached screenshot too. Thank You.
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • ApplianceCertificate incorrect object

    Alfonso Alfonso
    Alfonso Alfonso
    Hi as per the subject in the ApplianceCertificate certificate in the subject field I have incorrect values such as the email field, in which na@example.com is reported how can I correct this data? thank you Oggetto /C=NA/ST=NA/L=NA/O=NA/OU…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • I think that the API has a little bug inside

    Lev Anni
    Lev Anni
    Hi, Certificate list request ends up getting a TAR archive instead of API output. Request made is as following: <Get><Certificate><Filter key="Name" criteria="like">cert name</Filter></Certificate></Get> or <Get><Certificate></Certificate><…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • How to delete a certificate using API?

    Lev Anni
    Lev Anni
    Hi, Despite my positive feelings regarding Sophos products, API documentation is worst I have ever seen! It lacks very basic command explanations or examples, for example to delete the certificate it says that Name attribute is required BUT, it does…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Add/Update/Delete in API calls are great but... Where is Get?

    Lev Anni
    Lev Anni
    Hi, I'm trying to get list of uploaded certificates using API to determine if the upload process required. API doc show only Add/Update or Delete certificate. Where is option to get list of certificates or get certain certificate by its name for instance…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Purge SSL Certificates from cache

    P M1
    P M1
    Hello, I have a sophos xg appliance with https scanning enabled. The appliance seems to cache website's certs. Sometimes if the maintainers of website misconfigure SSL settings, a wrong certificate is served by the webserver and this gets cached…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • CAA Certificate "Copernicus UTM" expired silently - 1.2.3.4:9922. CAA Clients terminate

    LHerzog
    LHerzog
    The CAA certificate on our XG 18.5 MR4 has expired without any warning. Nice! So all our clients with CAA cannot authenticate against that firewall. How would Sophos resolve that issue withour recreating the ApplicanceCertificate? C:\OpenSSL…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • GoDaddy SSL Certificate for User Portal

    ChrisBacker1
    ChrisBacker1
    I have an SSL certificate from GoDaddy that I am trying to import into the XG 230 firewall. It wants the private key in a .key format which GoDaddy is only giving me a .crt format. The certificate key is in .p7b format which works just fine it appears…
    • Answered
    • over 8 years ago
    • Sophos Firewall
    • Discussions
  • Purging expired certs from Sophos XG

    JohnHilton
    JohnHilton
    Hi all, having a few issues with expired certs that are on the XG. (Google namly) I have deleted the certs from the XG using putty ssh in /var/certcache/ I am now having other domain with the same error (xg thinks the cert is expired when…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos XG: Cannot change WAF Certificate

    Patrick Wolfensberger
    Patrick Wolfensberger
    Hi there Last week, my wildcard certificate expired. No biggie. Got a new one, imported it into the firewall, everything ok. When I selected the new certificate in my WAF rules, I was able to save this configuration and expected the firewall to use…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Migrating from XG 310 to XGS 3100

    Jeff Duvall
    Jeff Duvall
    We will be migrating from the XG 310 to the XGS 3100 and I was wondering if the previously installed SSL client software would connect to the XGS3100 as it does currently to the XG310? Is there a client upgrade that needs to happen as well? Thanks.
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • XGS Latest firmware - Outdated Certificates

    tomrgsd
    tomrgsd
    We just recently upgraded from an XG to XGS firewall and having random issues with certificates. I've had to manually add updated ROOT and Intermediate CA certificates for Digicert and a Top Level DOD certificate among others. I have never had any issues…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS V19 Web Certificates and browser warning pages

    ADJ
    ADJ
    Hello, Starting to get a bit frustrated with the Sophos web certificates - think I am going around in circles. I have both the Default Appliance certificate and the Security SSL Certificate installed into the Trusted Certificates store on a Windows…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS V19 - Configuring SSL Certificate

    Hyegun
    Hyegun
    Hi Community So I am having trouble with configuring SSL certificate Currently I have a webserver hosted outside with a wildcard SSL Certificate Now I have webservers hosted on-premise that I want to upload the SSL Certificate too. If I revoke…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos SSL certificate published on Public for my server

    hery Hal
    hery Hal
    Dear expertise, i have one server currently put on DMZ behind sophos XG. currently using XG230 (SFOS 18.5.2 MR-2-Build380). this is server is running on apache and using an entrust SSL certificate configured on host. on XG we have several LAN created…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • XG450 Locally signed Certificate for LAN IP

    ywillie
    ywillie
    I've been trying to get locally signed Certificate to work for the firewall's LAN IP. Unfortunately with all effort i tried, microsoft edge still consider firewall's page as non-secured. However when switched to public ip instead, it works. Currently…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • SSL Certificate Distribution

    Manu_Mathew
    Manu_Mathew
    SSL Certificate Distribution – I just wanted to check that there is no way to add a link to the SSL certificate that clients need to install from the Sophos Sign In Page? The Smoothwall Sign In Page had a separate section which allowed you to download…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • PHP script for uploading Lets Encrypt certs is broken since 19.0 MR1

    EdmundSackbauer
    EdmundSackbauer
    Hi, I am using this script from user burton https://community.sophos.com/sophos-xg-firewall/f/discussions/129768/letsencrypt-api-update-script---dynamically-handles-multiple-certs-multiple-rules-including-re-grouping-of-policies-rules However since…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • The renewal of your Heartbeat intermediate certificate has failed

    ScHwAnG86
    ScHwAnG86
    My HA XGS136 cluster is experiencing this issue with heartbeats: I get an error alert in Sophos Central The renewal of your Heartbeat intermediate certificate has failed Looking in the heartbeat log I can see failures. tail /var/tslog/heartbeatd…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Pls help me filling out the Default CA for remote-access SSL VPN !?

    J Thai
    J Thai
    Hello, I am running Sophos XG (Home) 18.5.4 MR4 and about to set up a remote-access SSL VPN profile, but changing SSL VPN settings will just not work and settings keep reverting back to default. There have been at least 2 precedences to my knowledge…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • TLS handshake fatal alert: certificate unknown(46).

    ScHwAnG86
    ScHwAnG86
    Hi, I am seeing these errors in the log for some websites which tend to utilise tracking information, particularly those which utilise a CNAME record to point to another address. For example, the website t.myrenews.com.au is a CNAME that resolves…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
<>