This thread goes back 3 years and there are other posts about this same issue from 5 years ago. Looks to me like they have no intention of ever fixing it.
Too bad...
Aren't there many other users having this problem? - I gues not
How do other people use they own certificates then?? - I gues they don't...
I think the point is, while it is a shortcoming of the product, it is just not that hard (in many cases) to concatenate the certs together to create a cert with the full chain and import that into Sophos. I have seen some have a lot of issues with it, and I have no idea what causes it. However, using a free certificate (startcom IIRC) I had to do this and it was pretty straightforward at the time. I've since switched (6 months or so) to Let's Encrypt certs and it is also working fine, no concatenation needed. So, YMMV.
darrellr said:... it is just not that hard (in many cases) to concatenate the certs together to create a cert with the full chain and import that into Sophos. ...
Yeah, so I did this, but it did't work. Although Sonos did import all of the certificates.
I also had Let's Encrypt, but same there. YMMV indeed.
Too bad you can only fix this by loggin into the terminal as root and edit some files.
Just for now I use a PC, so the certificate is working. Only on Android (and other mobiles) I have the problem.
Luckely I also have a free Cloudflare account, so Cloudflares provides a certificate that is working ;-)
(and since Cloudflare dous recognise the certificate, it is truely safe)
Importing did work for me.
It imported the certificate and all 3 CA certificates.
Unfortunatly the Sonos Webinterface is only handing out one certificate to the clients, accordingly to Sonos staff the problem is in there. Sonos should give the certificate with root chain, but it dousn't. (as you can see if you look at the proposed fix in one of the many threaths)
I did not have to do anything special to get LetsEncrypt work. With the startcom cert, firefox complained about the missing cert, but IE and Chrome filled in the gap in the background just fine. You do have to be careful with concatenating and I had to use a linux console to get it done properly. I could not make Windows work, nor could I copy/paste. But it really wasn't difficult. Maybe I just got lucky.
Just wanted to give a quick shout out to PaTmaN93 for investigating and posting these full set of instructions. I followed them, adjusting some things slightly as I did everything from a Windows workstation. It took me a few tries, and at one point I even locked myself out of a UTM (had to restore from backup), but eventually I got it to work. I verified that the change even works through a restart. Excellent work PaTmaN93! It's people like you that make forums work as well as they do.
One piece of advice...always have a backup of your UTM before making changes! Luckily I'm studious about this, and was able to restore the UTM I locked myself out of. Sure I could have always rebuilt it from scratch. But why?
-------------------------------
Interesting [in-ter-uh-sting, -truh-sting, -tuh-res-ting]
A word typically used by IT technicians to describe an issue they didn't expect, or never encountered, and don't know how to fix.