Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

LetsEncrypt Certificate not trusted by Spohos XG Firewall

Hi folks

If create a Lets Encrypt certificate (pfx, fullchain cert) and uploaded it to my freshly installed Sophos XG (SFOS 18.5.1 MR-1-Build326).

The certificate is uploaded but shows up as untrusted (red cross). 

The chain of the certificate is: ISRG Root X1 -> R3 -> My Certificate

I search the CA Certs for R3 and it only shows two not related R3 certificates. It does not show an R3 only CA certificate.

I tried to upload the R3 CA certificate from the LetsEncrypt web site but Sophos XG tells me that there is already a certificate.

Can anybody help ? What am I doing wrong ?

Regards,

Oliver



This thread was automatically locked due to age.
Parents Reply
  • How can we check if this hotfix has been applied? I have the same issue and have tried all the workarounds here. I found another thread which suggested the DST certificate file might still in be the 

    /conf/certificates/cacerts/
    directory, but it's not.

    I have the same symptoms where I am able to use the certificate for web servers without the browser returning errors for those sites but cannot use it as the appliance certificate because the XG marks it untrusted.

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?