This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WEB Protection certificate expired message for lets encrypt certificates

Hello,

we use the sophos Web Protection with SSL scanning enabled. Since today afternoon we get a "certificate expired" message for websites secured with lets encrypt certificates.

i researched a bit and found out that today a root certificate of lets encrypt expired. i deleted the lets encrypt x3 and r3 CA certificates under Web Protection -> Filtering options->HTTPS CAs. And also deactivated the ISRG Root X1 certificate. Then restarted the Web Protection by toggling the Button under "Web Filtering". The issue still persists.

I also tried to clear the cache under Web Protection -> Filtering options->Misc. with no effect.

a website that is affected for example:https://letsencrypt.org/de/certificates/.org

other websites work quite well.

can someone help?



This thread was automatically locked due to age.
Parents
  • This was suggested in the German forum by user nfawcett:

    "To get SSL Decrypt and Scan working.  I had to disable the "Digital Signature Trust Co. DST Root CA X3" cert under Web Protection > Filtering Options > HTTPS CAs.  Then download the two certs "ISRG Root X1" and "Let’s Encrypt R3" from Chain of Trust - Let's Encrypt (letsencrypt.org) in PEM format.  Upload them to Web Protection > Filtering Options > HTTPS CAs.  Once I did this sites started working again."

    I tried this on our UTM and it did not work.  Sites are still being rejected for "certificate has expired"  Does the httpproxy daemon need to be restarted to enact changes in the CA list?

Reply
  • This was suggested in the German forum by user nfawcett:

    "To get SSL Decrypt and Scan working.  I had to disable the "Digital Signature Trust Co. DST Root CA X3" cert under Web Protection > Filtering Options > HTTPS CAs.  Then download the two certs "ISRG Root X1" and "Let’s Encrypt R3" from Chain of Trust - Let's Encrypt (letsencrypt.org) in PEM format.  Upload them to Web Protection > Filtering Options > HTTPS CAs.  Once I did this sites started working again."

    I tried this on our UTM and it did not work.  Sites are still being rejected for "certificate has expired"  Does the httpproxy daemon need to be restarted to enact changes in the CA list?

Children
No Data