Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFOS V18 breaks the Pocket Guide for using Digital Certificates in IPSEC VPN connections

i've noticed that in SFOS  V18 downloaded certs are now in CRT instead of PEM format. Strangely enough when you upload certificates into a V18 appliance it doesn't expect a CRT file. Additional work needs to be done with converters before it can be used. This is troublesome if you have many IPSEC site to site connections  on V18 appliances. and it doesn't quite follow this guide either https://www.sophos.com/en-us/medialibrary/PDFs/documentation/SophosFirewall/Pocket-Guides/Establish-Site-to-Site-VPN-Connection-using-Digital-Certificates_2.pdf

It would be good if V18 cert download  behavior matches v17.



This thread was automatically locked due to age.
Parents Reply
  • Ok. Thanks for the clarification. And yes I am downloading self signed certs as per the guide. Do hope Sophos can standardize the behavior to avoid confusion. Also just got an email which basically is telling people XG is coming to an end in a few more years.... Product lifecycle seems to be getting shorter and shorter which I assume ultimately is to boost sales under the guise of providing more performance and security .

Children