This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Certificate could not be verified only while https is scanning

When scanning https for any local IP I am receiving a stop/block: The URL/Site has a valid SSL Cert and I can access the site without https scanning active. The firewall Rules are allowing. Unable to determine why the STOP is occurring when scanning https. I have been running https scanning without issue until this event.

Running : SFVH (SFOS 17.5.7 MR-7)

Message:

Stop!
This website is a security risk
Access to this website has been blocked because the website cannot prove its identity.
Return to previous page


Reason for blocking this site
The issuer of this website's certificate could not be verified. This could mean that the website is not configured correctly.

About this request
URL: https://mypti.com/
Certificate details:
Valid From: Oct 1 14:23:51 2018 GMT
Valid To: Nov 21 20:29:01 2020 GMT
Serial Number: 45:14:a3:e4:5d:4d:16:8a
Subject: jurisdictionC=US, jurisdictionST=Florida, businessCategory=Private Organization, serialNumber=P08000006680, C=US, ST=Florida, L=Deerfield Beach, O=People's Trust Insurance Company, CN=mypti.com
Issuer: C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com
Inc./OU=certs.godaddy.com/.../CN=Go Daddy Secure Certificate Authority - G2

SSL error: unable to get local issuer certificate



This thread was automatically locked due to age.
Parents Reply
  • SOPHOS support ticket #9065237 request showed the Web site's CA chain for the SSL cert was improperly built so the top level CA certs from GoDaddy were not linked to allow XGFW to properly validate the SSL cert as most web browsers can. I uploaded the particular chained CA Cert from GoDaddy into my XGFW CA and the https scanning works without error.

    In case anyone else runs across an error similar....

Children