• Sophos - Certificate authority: Invalid or not installed

    André Besteiro
    André Besteiro
    Good afternoon, When we accessed Sophos through the browser, we got an insecure certificate alert. We imported a new certificate into Sophos (the same used on our website), but the following message appears in the certificates menu: Certificate…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Model:SFV1C4 - how to import a certificate for my remote access VPN?

    Geir Otto Olsen
    Geir Otto Olsen
    I have tried to go to Certificate, and import it there, but it is not Trusted. . Certificate authority: Invalid or not installed Issuer /C=GB/ST=Greater Manchester/L=Salford/O=Sectigo Limited/CN=Sectigo RSA Domain Validation Secure Server CA What…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • 500 error when Importing TLS certs using the API

    Elliana Perry
    Elliana Perry
    I am investigating importing our TLS certificates using the SFOS API but running into an error that I am struggling to understand. The request XML: <? xml version "1.0" encoding "UTF-8" ?> < Request APIVersion "1905.1" > <!-- API Authentication…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Add Windows Server Self-Sign Cert as trusted?

    Quallensaft
    Quallensaft
    What is the way to whitelist and add a self-sign cert (Windows Server) on the firewall? Of course I can import the certificate under certificates but its is still not valid (red cross). e.g. Exchange server is using a self-cert for SMTP SSL/TLS connection…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Sectigo RSA Domain Validation Secure Server CA removed?

    Quallensaft
    Quallensaft
    Hallo, any reason why the (build-in) CA cert from Sectigo RSA Domain Validation Secure Server CA was removed the last days? Is that normal or a bug, pattern updates? Anyone else has this CA on the firewall? Had to add it again manual by hand to work again…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Query validity period of the installed certificates on SFOS

    Steppenwolf
    Steppenwolf
    Hej together, does anyone know a way to monitor the installed certificates on the Sophos Firewall. Especially the expiration date would be interesting. I have not found a way via SNMP, SYSLOG or API. I would like to query this from our central monitoring…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • ssl ceritificate error

    satyabrata bastia
    satyabrata bastia
    Hi, we are using sophos-xg-210,self generated Certificate used but in monitoring its showing no secure protocol available so please help us to find out where is issue.
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • "The operation will take time to complete.." when adding new certificates

    Pedro Calvo
    Pedro Calvo
    Good day to you all When I add a new certificate or certificate authority, always get the next message: "The operation will take time to complete. The status can be viewed from the Log viewer page" New certificates never appear. I found nothig…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Firewall RMA. How can reconnect RED device

    Luc_GLLM
    Luc_GLLM
    Hi, I have a defective XGS2100, an RMA has been opened and a new product will be sent back to me. When it arrives I will do a configuration restore starting from the backup of the faulty one, but two questions arise: 1) I have 5 RED20 devices connected…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS Certifikates: Certificate authority: Invalid or not installed

    encar
    encar
    Hello, I want to replace an SG firewall with an XGS. I donwloaded the wildcard certificate (.pem) and the certificate of the CA from the SG and uploaded them on the XGS. Though the the wildcard certicicate doesn't trust the CA. How can i solve this…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Enabling HTTPS on Enterprise Applications

    Srikrishna Pothukuchi
    Srikrishna Pothukuchi
    Hi, We have one VMWare server protected by this Sophos firewall. All our enterprise web applications are hosted on this server. Now, after accessing these enterprise applications, even though they are passing through the firewall, we are getting…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Comodo Certificates

    Mark Smith7
    Mark Smith7
    Hi I cant find anything recent on this in the forums. Im looking to purchase a wildcard certificate for securing several things. Are there any issues i need to be aware of using either a comodo positivessl (cheaper) or essentialssl? I would…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XGS: Public SSL Certificate for user/admin portal

    Rimfire
    Rimfire
    XGS 136 and 19.x firmware. Didn't find universal info how to generate proper CSR and how to import the public SSL Certificate to XGS For Request / Subject name attributes: Common name: domain name or FQDN including the host name? For Request / Subject…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Problem with a FAKE SSL certificate Sophos is creating!

    Science-Rite CBD
    Science-Rite CBD
    Hello, Is there a SSL expert in the house? I was on a PUBLIC WiFi AP yesterday and was shocked to find out my websites SSL from DigiCert was not used. In fact, the WiFi said that my SSL Certificate is coming from Sophos. Below I will display what…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Where are all the places in XG firewall to install Go Daddy SSL certificate for Exchange email server?

    Sean Rome
    Sean Rome
    Greetings everyone! This is my first time installing a renewed SSL certificate for our email server in our new XGS firewall. Where are all the places the new certificate needs to go? I've uploaded it in certificates. Applied it in email general…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • In XG firewall where are all the places you install a renewed SSL certificate for an email server?

    Sean Rome
    Sean Rome
    Greetings everyone, In XG firewall, I need to install and configure a renewed SSL certificate from Go Daddy. We have an Exchange server on premise. I've uploaded it into certificates. Applied it in firewall HTTPS OWA SMTP rule. Applied it in email…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • The user opens the outlook prompt certificate alarm

    Hongbo Xia
    Hongbo Xia
    Our customer recently updated the windows system patch. After the update, open the Outlook client, and always pop up a certificate warning. As shown in the figure below, please help analyze the cause of this problem, whether it is related to XG Firewall…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Automate replacement of Letsencrypt SSL on Sophos SFOS?

    jang430
    jang430
    I am currently using SFOS 19.5.1 MR-1-Build278. I am hosting Emby (similar to Plex, I used Plex as it is more popular) container on my Qnap NAS, being protected by WAF. I have my own domain name from Porkbun, and I was able to generate SSL (Letsencrypt…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG CA and latest macOS break web sites

    rfcat_vk
    rfcat_vk
    Hi foks, I am running v19.5.1 on the XG and macOS13.3 on the mac book pro and mc air. A couple of sites no longer work and the default is https even though I enter hrttp.If I use a hotspot the issue is not observed. I have a mac mini in which the…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • expired Root CA "DigiCert SHA2 Secure Server CA"

    LHerzog
    LHerzog
    Noticed some issues today with some popular SSL sites (linkedin, live, . These issues existed for some days but no one complained. The traffic was scanned by TLS/DPI engine and the servers had certificates issued by "DigiCert SHA2 Secure Server CA"…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Uploaded Certificate in Sophos XG Firewall Showing Not trusted

    Sacombank Cambodia itsupport_sc
    Sacombank Cambodia itsupport_sc
    I uploaded the certificate in every format (.pem,.pfx,.Cer) but none of showing trusted and always showing RED (X) in trusted for certificate issued from Digicert website. Please assist me to fix on this issue at earliest. Please find the attached screenshot…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Your connection is not Private

    tstan
    tstan
    Hi, purchased an XGS2100 to replace our SG230 for our Public WiFi connection. The device is not on a domain and has its own internet connection. It is only used for members of the public to get access to the internet on their own personal devices…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Invalid Certificate

    Kharl Levinn laniton
    Kharl Levinn laniton
    I have been using SG135 UTM for 5 years and I decided to upgrade to XGS136. Just like in the UTM, I want the web admin certificate to be valid. I have made a locally signed self-certificate, installed and trusted but I'm still having issues above. I have…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • XG 19.5.0 GA ....Can only download TLS/SSL ApplianceCertificate as .PEM format, not CER, DER or pkcs#12

    alan weir
    alan weir
    Using XG 19.5.0 GA. I can only download the ApplianceCertificate as a *PEM. file. I am certain it was letting me choose the other formats once before. Now the only file format it allows to download is default.pem and appliancecertificate.pem which cannot…
    • Answered
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • Purge SSL Certs from cache using Frontend

    P M1
    P M1
    Continuing on the discussion below: community.sophos.com/.../507230 Is there an easy way to do this from front end? This has become a common occurrence now, with the latest incident involving Google's certs. The given workaround requires usage…
    • over 1 year ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<>