Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Renew SSL certificate for email on XG Firewall

So, 2 years ago a goDaddy SSL cert was added to XG and been used since that date.

It is now renewed with goDaddy and downloaded. I tried replacing existing one with new one, but it said a rule/policy was already using it. So I then added the certificate as new and it appears in the list with the one from 2 years ago.

However, when I go to the SMTP TLS section and click on drop down list to replace the current one with the new one, it does not show up in the list. There is

The Original one, Default, the XG cert and one other. But not the one I have added


Did I miss a step to get the new added one appearing in the lst?



This thread was automatically locked due to age.
Parents Reply Children
  • I am looking at the CSR route and when I create the CSR and click on download, it only provides an option to download csr. In the documentation it says there sould be 3 files, csr, key + txt

  • This process was changed. It only provides a CSR. Then you get the signed pem and upload it to the firewall. 

  • So what about the .key file and using the passphrase?

    I am doing this on an XG105 v17.6.16 MR16

  • So, for the certificate to appear in Email, General, SMTP TLS Configuration, TLS Certificate drop down, the certificate has to be added with the .key file.

    As advised earlier, I do have the .key file and password.txt file from the certificate was added 2 years ago. Yest the orginal .key and passphrase does not work with new certificate (.pem). I have also checked as a test with the prginal certifcate using the .key file and password I have and it adds no problem. So I know the .key file and password are valid.

  • Yes, I can do that on the XG, but it does not generate a .key file only the .csr. As I understand it, without the .key file, one can not upload successfully to XG and then be seen to be able to select in Email section.

  • So the answer is:-

    The XG only generates a csr file now. Whereas in previous version it produced three files! Also, you can no longer use a previous private.key.

    For me, I am lucky to use goDaddy for SSL Certificate. What I now need to do is, cancel and get a refund on the new cert that was auto renewed and generated and purchase a new standard SSL and part of their process now is to provide the three files required.

    Hope this helps others.