Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL Inspection (imported list of Root CA/Intermediate CA)

Hello

I'm wondering how Sophos XG validates the certificate chain (web surfing ssl inspection). We use web policies with "block invalid certificates" on a new installed sophos XG for a customer. Normally, we don't see a lot of blocked websites due to invalid certificates or untrusted CAs. 

but on that firewall, we had some issues in the last days.

Scenario: browsing a website was not possible due to "SSL error: unable to get local issuer certificate"

when we import the intermediate issuer CA cert to trusted CA list, it works. The root CA was already in the list. In my understanding it should already work if the Root CA is in the list without adding all intermediate issuer CAs to this list. But in that case it didn't work.

Question:

1. does sophos trust any intermediate CAs signed by a root ca if this root ca is in the list of trusted Certificate Authorities?

2. is there an update mechanism for the trusted CA list on sophos XG firewalls or is it a manual task to update the list (I know, its a controverse topic to update a trusted CA list automatically)

thanks

Michael



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hey Michael, Interesting query! 

    As far as I know, the Certificate chain has to be entirely defined on the XG. While validating the certificate XG looks for the entire chain. I can say from the context of importing signed certificates into XG. While importing those signed certificates into XG, the certificate won’t be considered valid unless Root and Intermediate CA both are available on the Firewall.

    So it could be the reason behind XG rejecting because the intermediate certificate isn't present.

  • That is excactly how it works as far as I know.
    If it can't be changed, Sophos should be better at updating the intermediate root CAs issued by the root CAs.

Reply Children
No Data