This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Bug Report - Email Proxy - General Settings - POP / IMAP TLS Configuration

SFVH (SFOS 17.1.3 MR-3) and previous version

TLS configuration does not honor certificate setting.  always uses built-in Sophos Appliance CA certificate regardless of TLS Certificate selection.  The default certificate causes validation error since it is not root trusted.



This thread was automatically locked due to age.
Parents
  • Where did you take this screenshot? And which CA is "Sophos_CA"? Did you upload it and how did you create it? 

  • The second image is a screenshot of the certificate view from windows 10 mail when it complains that the certificate is not trusted.  The description shows that Sophos is using the default CA certificate for email inspection that is created when installing the firewall firmware instead of the Sophos_CA that I selected. Sophos_CA is the subordinate CA certificate that I generated from my certificate authority and installed on Sophos.  The Sophos_CA certificate works fine for deep packet inspection on https traffic through Sophos.

Reply
  • The second image is a screenshot of the certificate view from windows 10 mail when it complains that the certificate is not trusted.  The description shows that Sophos is using the default CA certificate for email inspection that is created when installing the firewall firmware instead of the Sophos_CA that I selected. Sophos_CA is the subordinate CA certificate that I generated from my certificate authority and installed on Sophos.  The Sophos_CA certificate works fine for deep packet inspection on https traffic through Sophos.

Children
No Data