• Lets encrypt renew fail

    EinMarco_DE
    EinMarco_DE
    Hi everyone, We're using the integrated Let's Encrypt feature in SFOS V21. We've noticed some strange behavior when it comes to renewing certificates. When the firewall attempts to renew the certificate, it fails with the message: "Reason for failure…
    • 3 hours ago
    • Sophos Firewall
    • Discussions
  • Unable to access captive portal using Lets Encrypt certificate

    Tyler VanDorn
    Tyler VanDorn
    Problem: When I go to the portals from my LAN zone I can get into all of them except the captive portal. Ports 4443 (user) , 4444 (admin) work. Port 8090 gives me an error in the browser: Firefox v133.0: PR_END_OF_FILE_ERROR Chrome v131.0.6778.87: ERR_CONNECTION_CLOSED…
    • Answered
    • 1 day ago
    • Sophos Firewall
    • Discussions
  • v21 Let's Encrypt Cert creation and renewal fails, whan NAT Rule for HTTP/HTTPS exists

    PCPCH
    PCPCH
    On one of our XGS-firewalls, we need a NAT rule for HTTP/HTTPS. On this firewall, it's not possible to create or renewal a Let's Encrypt Cert. We need to disable the NAT rule, then it works to create/renewal the certificate. But this can't be the…
    • 1 day ago
    • Sophos Firewall
    • Discussions
  • Lets Encypt failing

    Stuart James
    Stuart James
    Getting the following error requesting Lets Encypt certificate "type":"urn:ietf:params:acme:error:connection" "detail":"xx.xx.xx.xx: Fetching xxxxxxxxxxxx/.../mhmbdFphj1tfMCrRkrqqrp2CrgNY54ipSQeI66mcGFQ: Timeout during connect (likely…
    • Answered
    • 28 days ago
    • Sophos Firewall
    • Discussions
  • Sophos 21 Home Lets Encrypt Secondary Validation Fetch Timeout

    jarrod beebe
    jarrod beebe
    Certificate request fails with secondary validation time out. I can see in the web server protection log viewer that the well known url is being requested with the unique value. I also briefly see that the temporary waf rule is created. Only thing to…
    • Answered
    • 29 days ago
    • Sophos Firewall
    • Discussions
  • Sophos XG Home V21 GA Lets Encrypt Certs not shown for Administration

    Frank Jepsen
    Frank Jepsen
    I successfully obtained 5 certificates from Lets Encrypt with th new V21 feature. I can use these in my web application firewall rules and they work fine. But in "Administration/Admin console and end-user interaction" only an uploaded wildcard certificate…
    • Answered
    • 1 month ago
    • Sophos Firewall
    • Discussions
  • Update Certificates via API: Did I get it right?

    dtconnect
    dtconnect
    In 2018, Sophos integrated Let's Encrypt with their UTM series, leaving XG(S) users anticipating a similar feature. Many, including us, have turned to API solutions due to the lack of progress which is fine. However, the XG API feels less refined compared…
    • 8 months ago
    • Sophos Firewall
    • Discussions
  • Sophos XGS Lets Encrypt HTTP Challenge

    Fritz Otlinghaus
    Fritz Otlinghaus
    Hey everybody, as we could not find any working solution in the discussion forum that does the Lets encrypt Process on the Sophos itself, we setup a process to run the whole thing on the sophos firewall it self. Our blog post https://blog.helsinki…
    • Answered
    • 10 months ago
    • Sophos Firewall
    • Discussions
  • Automate replacement of Letsencrypt SSL on Sophos SFOS?

    jang430
    jang430
    I am currently using SFOS 19.5.1 MR-1-Build278. I am hosting Emby (similar to Plex, I used Plex as it is more popular) container on my Qnap NAS, being protected by WAF. I have my own domain name from Porkbun, and I was able to generate SSL (Letsencrypt…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Upload certificates using Powershell to automate Let's encrypt

    Martin Walter
    Martin Walter
    After reading quite a lot about the lack of support for Let's encrypt and studying the various solutions other people came up with I wanted to post my solution. Over the last couple of days I wrote a script to upload a certificate to the firewall, update…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • PHP script for uploading Lets Encrypt certificate not works

    Angel Vallvidrera
    Angel Vallvidrera
    Hi and sorry for my poor english, I'm triying to use the PHP script provide from user burton, but the scrip say this: CREATING TEMP CERT... <?xml version="1.0" encoding="UTF-8"?> <Response APIVersion="1800.1" IPS_CAT_VER="0"> <Login> <status>Authentication…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Lets encrypt certificate for guest portal on XG

    Regex
    Regex
    AVE! Im a home user and i was trying to test some CaprtivePortal things and I know how selfcerts are working so i decided to upload LE cert to XG and change it in <AdminAndUserSettings> I dont know why but devices(phones) still are getting ssl error…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Allow LetsEncrypt without DNAT

    Carlo
    Carlo
    Hello, is there any way to allow LE without manual enabling firewall and nat rules? I have couple of web servers on same port 443 and I would like to enable them to use LE for generating new and renewing certificates but I'm unable to find the way.…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Let's Encrypt broken - Certificate authority

    Mike Richter
    Mike Richter
    Hi .. Just wanted to list the steps I performed to finally validate LE Cert on XG 19.0.1 MR-1-Build365. I spent over a month trying to narrow down the issue and I might have read every article in this forum with no avail. I hope this helps. The steps…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • PHP script for uploading Lets Encrypt certs is broken since 19.0 MR1

    EdmundSackbauer
    EdmundSackbauer
    Hi, I am using this script from user burton https://community.sophos.com/sophos-xg-firewall/f/discussions/129768/letsencrypt-api-update-script---dynamically-handles-multiple-certs-multiple-rules-including-re-grouping-of-policies-rules However since…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Lets Encrypt auf der SOPHOS XG OS

    mucsav1977
    mucsav1977
    Hallo, Ich bekomme das irgendwie nicht hin wie bei der UTM OS mit dem Zertifikat. Also da gibt es auch kein Lets Encrypt wie bei der UTM OS. Kann mir jemand helfen?? Ich möchte gerne ein Offizielles Zertifikat auf meiner Sophos haben. Sie hat…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Sophos XG API / Lets Encrypt / PowerShell 7 / WAF Update

    nplm85
    nplm85
    Hopefully this can help others. I'm running the home licensed version and just recently moved to v19 I have a few WAF's that are configured externally this script is to do the following. Renew Multiple certificates that are already configured…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • LetsEncrypt Certs signed by R3 Intermediate cert not Trusted by Sophos XG after reinstalling CA certs.

    Optoisolated
    Optoisolated
    Hi, I recently went through and updated some of my older LetsEncrypt certs and when I imported them they were showing up as Untrusted. The rest I had were still trusted. Unsure as to why, I removed the LetsEncrypt R3 Intermediate and the ISRG Root X1…
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • LetsEncrypt Certificate not trusted by Spohos XG Firewall

    Posbis
    Posbis
    Hi folks If create a Lets Encrypt certificate (pfx, fullchain cert) and uploaded it to my freshly installed Sophos XG ( SFOS 18.5.1 MR-1-Build326). The certificate is uploaded but shows up as untrusted (red cross). The chain of the certificate…
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • Let's encrypt certificate woes - "Certificate authority: Invalid or not installed"

    h3ctic
    h3ctic
    Too many cooks and s omething has become messy with certificates on our XG and I need some help to get this sorted. (SFOS 18.0.5 MR-5-Build586) virtual Trying to upload a pfx-certificate generated by our certbot gives the dreaded red X. Mousing over…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • Let's Encrypt certificate renewal

    Mathias Mühlbacher
    Mathias Mühlbacher
    Hello everyone, is there an approach how to propper update the SSL certificates on Sophos XG (current version 18). I usually select my existing certificate and upload the new Let's encrypt SSL certificate so it overwrites it. After I refresh the…
    • Answered
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • Easy Home User LE Cert Renewals

    Gary Parr
    Gary Parr
    Hello all, I wanted to share my solution for easy certificate management. If you have a DNS service and a Windows machine, this may work for you. First, check out Certify The Web . This tool runs a service on your machine that manages your certificates…
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • Letsencrypt API Update Script - dynamically handles multiple certs, multiple rules, including re-grouping of policies rules

    burton
    burton
    I wanted a way to auto update my letsencrypt certificates for use on my XG firewall and WAF rules. I developed this script to handle multiple certificates, and to be as dynamic as possible. The approach I took to achieve this is the following: 1) Within…
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • automatically renew Let's encrypt SSL-certificates on XG using PowerShell

    Sven Ott
    Sven Ott
    I spent a few hours on this, so maybe my result helps someone in a similar situation. In my home-lab I'm running a KEMP ADC that publishes all my SSL-Services. Since KEMP does not support Let's encrypt out of the box but offers a PowerShell module for…
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • LetsEncrypt Functionality WAF

    MatthiasLang
    MatthiasLang
    Hello all at the moment I use Sophos UTM and WAF with LetsEncrypt. The funktion in UTM is running well and easy. In the near future I want to migrate to Sophos XG. My question is, is it planned in the near future to integrate LetsEncrypt in Sophos…
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
>