Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Renew SSL certificate for email on XG Firewall

So, 2 years ago a goDaddy SSL cert was added to XG and been used since that date.

It is now renewed with goDaddy and downloaded. I tried replacing existing one with new one, but it said a rule/policy was already using it. So I then added the certificate as new and it appears in the list with the one from 2 years ago.

However, when I go to the SMTP TLS section and click on drop down list to replace the current one with the new one, it does not show up in the list. There is

The Original one, Default, the XG cert and one other. But not the one I have added


Did I miss a step to get the new added one appearing in the lst?



This thread was automatically locked due to age.
Parents
  • How did you replace / upload the new one? It needs to have the private key. Or did you do a CSR? 

    __________________________________________________________________________________________________________________

  • When it was done first 2 years ago, I selected the .pem file and the .key file entered the password and the SSL upladed to the XG. Then within the configurartion of MTA Email TLS section I was able the select the named SSL cert


    Now that there is a new one (old one expires in 2 weeks), I tried to load the new cert to existing, but it said a rule was using it (Email TLS section). So, I then uploaded the new one with a new name. I selected the .pem and entered the password and it uploaded successfully. The .key files was not needed as i have read that the .key will already be uploaded to the XG


    Hope this helps

  • Likely you uploaded simply a PEM without Private Key. Why should the Key be present? Can you use CSR with GoDaddy? This should be much easier. 

    __________________________________________________________________________________________________________________

  • When I used the .key file, it said unrecognised format. Yet using the same .key file with the original .pem giving it a new name, it uploaded alright. Of course, that is just a duplicate of the one that will expire in 13 days.

    So, 2 years after the first cert was provided by goDaddy a new one is available to use and goDaddy provided just the .pem file. So, how should i use this .pem file to get it to upload to XG and be selectable to use?

    Many thanks

Reply
  • When I used the .key file, it said unrecognised format. Yet using the same .key file with the original .pem giving it a new name, it uploaded alright. Of course, that is just a duplicate of the one that will expire in 13 days.

    So, 2 years after the first cert was provided by goDaddy a new one is available to use and goDaddy provided just the .pem file. So, how should i use this .pem file to get it to upload to XG and be selectable to use?

    Many thanks

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?