Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ApplianceCertificate incorrect object

Hi as per the subject in the ApplianceCertificate certificate in the subject field I have incorrect values such as the email field, in which na@example.com is reported how can I correct this data?
thank you

Oggetto /C=NA/ST=NA/L=NA/O=NA/OU=NA/CN=Appliance_Certificate_wIeWkRT1DDjv5M9/emailAddress=na@example.com
Autorità emittente /C=IT/ST=IT/L=Salerno/O=dg/OU=OU/CN=Sophos_CA_C01001C77777HJ15/emailAddress=*******@gmail.com
Scopo
Certificate purposes:
SSL client : Yes
SSL client CA : No
SSL server : Yes
SSL server CA : No
Netscape SSL server : Yes
Netscape SSL server CA : No
S/MIME signing : Yes
S/MIME signing CA : No
S/MIME encryption : Yes
S/MIME encryption CA : No
CRL signing : Yes
CRL signing CA : No
Any Purpose : Yes
Any Purpose CA : Yes
OCSP helper : Yes
OCSP helper CA : No
Time Stamp signing : No
Time Stamp signing CA : No


This thread was automatically locked due to age.
Parents
  • Hello Alfanso,

    Greetings,

    You need to update those information under System -> Certificate -> Certificate Authority -> Default CA. 

    Once you change the Default CA, you need to relogin and if you are using the SSL VPN. It will break the connection and you will need to import the configuration. 

    Mayur Makvana
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • hello MayurMakvana,
    thanks for answering me, but
    I have already done what you suggested but the data remains the same.

    Oggetto /C=NA/ST=NA/L=NA/O=NA/OU=NA/CN=Appliance_Certificate_wIeWkRT1DDjv5M9/emailAddress=na@example.com
    Autorità emittente /C=IT/ST=IT/L=Salerno/O=dg/OU=OU/CN=Sophos_CA_C0************3Q9HJ15/emailAddress=************@gmail.com
    Scopo
    Certificate purposes:
    SSL client : Yes
    SSL client CA : No
    SSL server : Yes
    SSL server CA : No
    Netscape SSL server : Yes
    Netscape SSL server CA : No
    S/MIME signing : Yes
    S/MIME signing CA : No
    S/MIME encryption : Yes
    S/MIME encryption CA : No
    CRL signing : Yes
    CRL signing CA : No
    Any Purpose : Yes
    Any Purpose CA : Yes
    OCSP helper : Yes
    OCSP helper CA : No
    Time Stamp signing : No
    Time Stamp signing CA : No
Reply
  • hello MayurMakvana,
    thanks for answering me, but
    I have already done what you suggested but the data remains the same.

    Oggetto /C=NA/ST=NA/L=NA/O=NA/OU=NA/CN=Appliance_Certificate_wIeWkRT1DDjv5M9/emailAddress=na@example.com
    Autorità emittente /C=IT/ST=IT/L=Salerno/O=dg/OU=OU/CN=Sophos_CA_C0************3Q9HJ15/emailAddress=************@gmail.com
    Scopo
    Certificate purposes:
    SSL client : Yes
    SSL client CA : No
    SSL server : Yes
    SSL server CA : No
    Netscape SSL server : Yes
    Netscape SSL server CA : No
    S/MIME signing : Yes
    S/MIME signing CA : No
    S/MIME encryption : Yes
    S/MIME encryption CA : No
    CRL signing : Yes
    CRL signing CA : No
    Any Purpose : Yes
    Any Purpose CA : Yes
    OCSP helper : Yes
    OCSP helper CA : No
    Time Stamp signing : No
    Time Stamp signing CA : No
Children
  • Hello Alfonso,

    Greetings!

    If you are referring to the subject line wherein na@example.com is set. I am working on it to find that out and update you!

    If you are referring to the issuer field, you may try below:

    You may add the CSC service in debugging with the help of the below from the advanced shell:

    csc custom debug

    Later, collect below logs:

    cd /log

    tail -f applog.log csc.log

    Update the default CA details and review the logs. It may give us clue whether the opcode for the certificate authority regeneration failing or executing successfully!

    If opcode fails, better to raise the support ticket to investigate it further.

    Mayur Makvana
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • I ran the commands he sent me, I attach the log

    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: logger: applog                
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: do_log_to_file: length=38     
    INFO      Oct 21 13:04:27Z  [apiInterface:17296]: ACTION: CALL createJson       
    INFO      Oct 21 13:04:27Z  [apiInterface:17296]: ACTION: CALL validateJson     
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: logger: applog                
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: do_log_to_file: length=86     
    INFO      Oct 21 13:04:27Z  [apiInterface:17296]: ACTION: CALL handleDeleteReque
    st                                                                              
    INFO      Oct 21 13:04:27Z  [apiInterface:17296]: ACTION: CALL replyIfErrorAtVal
    idation                                                                         
    INFO      Oct 21 13:04:27Z  [apiInterface:17296]: ACTION: CALL getOldObject     
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: do_prep_query: PREPSTMT with A
    RGS: select opcode,opcodetype,perlpackagename from tblcrevent where mode=?      
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: get_txid:Transaction ID: 23117
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: do_prep_query: PREPSTMT: 'sele
    ct opcode,opcodetype,perlpackagename from tblcrevent where mode=?'              
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: logger: applog                
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: do_log_to_file: length=149    
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: execute_action: DYNACODE varia
    ble:opcodename                                                                  
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: execute_action: DYNACODE opcod
    e:generate_certificate_authority                                                
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: do_ao: OPCODE generate_certifi
    cate_authority                                                                  
    DEBUG     Oct 21 13:04:27Z  [apiInterface:17296]: do_ao: OPCODE generate_certifi
    cate_authority CONTENT-TYPE:json, BODY_LEN:747                                  
    DEBUG     Oct 21 13:04:27Z  [listener:1305]: ln_recvfrom: fd '115.TCP.INET.auxil
    ary': 849 bytes are read by listener                                            
    DEBUG     Oct 21 13:04:27Z  [listener:1305]: register_request_inet: request from
     port '0'                                                                       
    INFO      Oct 21 13:04:27Z  [listener:1305]: Assigning free worker 17355        
    DEBUG     Oct 21 13:04:27Z  [listener:1305]: assign_to_busy_queue: assigning wor
    ker 17355                                                                       
    DEBUG     Oct 21 13:04:27Z  [listener:1305]: send_data_to_sockpair: listener has
     send 799 bytes to sockpair worker 17355                                        
    DEBUG     Oct 21 13:04:27Z  [worker:17355]: read_packet: read() 799 bytes from l
    istener                                                                         
    DEBUG     Oct 21 13:04:27Z  [worker:17355]: # OPCODE Called: 'generate_certifica
    te_authority'                                                                   
    MESSAGE   Oct 21 13:04:27Z  [worker:17355]: {"request":{"method":"opcode","name"
    :"generate_certificate_authority","version":"1.14","type":"json","length":747,"d
    ata":{ "currentlyloggedinuserip": "192.168.1.17", "transactionid": "344", "keyle
    ngth": "2048", "___serverip": "192.168.1.1", "objectID": "1", "commonname": "SOP
    HOS_CA_qCgZ1h********JMD", "state": "CZ\/IT", "___cmenabled": 0, "digest": "sha256
    ", "___cmrequest": 0, "countryname": "IT", "___username": "admin", "___serverpor
    t": 4444, "___meta": { "sessionType": 1 }, "ouname": "OU", "APIVersion": "1900.1
    ", "Event": "ADD", "uploadcaname": "Default", "crlid": "1", "mode": 357, "emaila
    ddress": "*****@gmail.com", "currentlyloggedinuserid": 3, "oname
    ": "********** SRL", "cryptotype": "rsa", "___component": "GUI", "___serv
    erprotocol": "HTTP", "isprivate": "y", "locality": "LAMEZIA TERME", "Entity": "s
    elfsignedcertificateauthority" }}}                                              
    DEBUG     Oct 21 13:04:27Z  [worker:17355]: ### insert_uuid: hdr: len=747 conten
    t=0 method=0 name=generate_certificate_authority                                
    DEBUG     Oct 21 13:04:27Z  [worker:17355]: ### insert_uuid: skipping uuid inser
    tion                                                                            
    DEBUG     Oct 21 13:04:27Z  [worker:17355]: ### insert_uuid: uuid insert