<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Certificate Errors on Websites</title><link>https://community.sophos.com/web-appliance/f/discussions/94682/certificate-errors-on-websites</link><description>Hi all, for the past few months we have been having issues with several certificates on random websites. The end user basically sees a message saying that the site is insecure and asks them if they want to continue. It seems that if we bypass the Sophos</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Certificate Errors on Websites</title><link>https://community.sophos.com/thread/379052?ContentTypeID=1</link><pubDate>Tue, 17 Jul 2018 17:18:48 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3421b74e-9139-46a0-99ab-7653f45f36c8</guid><dc:creator>James Wood</dc:creator><description>&lt;p&gt;&lt;span class="x-hidden-focus"&gt;Hi David Ashcroft,&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;1. Were you able to access this websites before?&lt;/p&gt;
&lt;p&gt;2. Did you make any changes to the computer prior to this issue?&lt;/p&gt;
&lt;p&gt;Make sure that the Date and Time settings are correct.&lt;/p&gt;
&lt;p&gt;Some secure sites require the date and time match the date and time of the secure site. Sometimes, because of incorrect time, the certificates may show up as expired.&lt;/p&gt;
&lt;p&gt;Step 1:&lt;/p&gt;
&lt;p&gt;Set the Date/time correctly&lt;/p&gt;
&lt;p&gt;a. Just double-click on the time in the lower right corner on the Taskbar and set the time correctly.&lt;/p&gt;
&lt;p&gt;b. Be sure to check the time, month, date and the year. As soon as it is corrected, this will usually fix this issue.&lt;/p&gt;
&lt;p&gt;Step 2:&lt;/p&gt;
&lt;p&gt;You may even try to open the website in compatibility mode. Steps to follow:&lt;/p&gt;
&lt;p&gt;a. Put the URL link in the address bar&lt;/p&gt;
&lt;p&gt;b. Click on Compatibility tab beside the address bar&lt;/p&gt;
&lt;p&gt;Here is the link below for reference:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/windows/internet-explorer/features/easier.aspx" target="_blank" rel="noreferrer"&gt;http://www.microsoft.com/windows/internet-explorer/features/easier.aspx&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Also refer the below link for more information:&lt;/p&gt;
&lt;p&gt;Warning message when a user tries to connect to a secure Web site by using Internet Explorer 7: &amp;quot;There is a problem with this website&amp;#39;s security certificate&amp;quot;(It applies to IE8 as well)&lt;/p&gt;
&lt;p&gt;&lt;a href="http://support.microsoft.com/kb/931850" target="_blank" rel="noreferrer"&gt;http://support.microsoft.com/kb/931850&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Step 3:&lt;/p&gt;
&lt;p&gt;Reset internet explorer settings and check if it helps.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://support.microsoft.com/kb/923737" target="_blank" rel="noreferrer"&gt;http://support.microsoft.com/kb/923737&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class="x-hidden-focus"&gt;NOTE: The Reset Internet Explorer Settings feature might reset security settings or privacy settings that you added to the list of Trusted Sites. The Reset Internet Explorer Settings feature might also reset parental control settings. We recommend that you note these sites before you use the Reset Internet Explorer Settings feature &lt;a href="https://only4dummies.com/gmail-login/"&gt;&lt;span style="font-size:75%;"&gt;gmail login&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p class="x-hidden-focus"&gt;Hope this information is helpful.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Certificate Errors on Websites</title><link>https://community.sophos.com/thread/344043?ContentTypeID=1</link><pubDate>Fri, 11 Aug 2017 10:50:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:22332694-fb15-4679-b194-72731bf2adf5</guid><dc:creator>Red_Warrior</dc:creator><description>&lt;p&gt;Hi David,&lt;/p&gt;
&lt;p&gt;Both of those sites rank very well on ssllabs.. generally if your having issues with sites like (updates, or stores) the issue is not with the site itself, but more towards the back end servers. &amp;nbsp;Without https scanning the appliance will simply pass off that connection however there some cases &amp;nbsp;where you may need to make exclusions in your certificate validation.&lt;/p&gt;
&lt;p&gt;If you are not using certificate validation or https scanning, it could be the browser or other infrastructure rejecting the certificate.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In regards to pushing out the cert, if you are not using https scanning the only thing that would be good for is presenting dialogue boxes to users (block/war pages or policy violations) all of those pages are stored on an https server that uses that cert. &amp;nbsp;So without it, www.abc.com, policy violation .. applaince presents certificate to the client.. client clicks advanced, allow.. they would then get the &amp;quot;you have been blocked page&amp;quot;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Unfortunately the best way to troubleshoot these issues is wireshark/tcp dump.. or if you export the sophos_log to a syslog server you could search for rsn=1407 check out the full explanation of the sophos log here:&amp;nbsp;&lt;a href="http://wsa.sophos.com/docs/wsa/webhelp/index.html#swa/concepts/InterpretingLogFiles.html"&gt;wsa.sophos.com/.../index.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>