This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Root Certificate automatically included by WAF of Sophos Firewall?

Hi everyone!

We are using a Sophos XGS2300 (SFOS 19.0.1 MR-1).

We uploaded a pfx-certificate to the WAF which specifically included only the webserver certificate itself and its intermediate certificate.

But, when we check the site with a tool like https://www.ssllabs.com/ssltest/ we see that the server (e.g. the Sophos Firewall) also sends the root certificate. Which is not what we want and which we don't see when we check sites like microsoft.com.

Are we correct to assume that this is done by the XGS? Is that intentional? Is there a way to circumvent this?

Thanks!

Best regards,

  Markus



This thread was automatically locked due to age.

Top Replies

  • Hi Markus,

    Yes, it is intentional. If a certificate is signed by a valid root CA that is part of the CA package available to XG (which should be the case in most scenarios) then WAF will always return the full certificate chain.

    This is the expected behavior, returning a partial chain is flagged by most test tools as a potential security vulnerability, and thus an automatic PCI scan failure.

    At the moment there is no option to influence this behavior.

    I understand the concern about the added latency, however, the impact in real life should be negligible on today's hardware.

    Regards,

    Attila Kovacs

    Jump to answer
Parents
  • Is the CA from the certifcate path availabe on your FW?

    I, f.i. had to upload the CA of my Let's Encrypt certificates.

     
    SFVH (SFOS 19.5.1 MR-1-Build278)  - Last (re)boot on Februari 20 2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
  • And SSL Labs shows ISRG Root X1 as the CA, not my Sohos FW.

     
    SFVH (SFOS 19.5.1 MR-1-Build278)  - Last (re)boot on Februari 20 2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
  • Hi, thanks for the input.
    Yes, the CA is already available in the FW. The certificate in question is a "normal", bought certificate from a certificate retailer. The CA is a globally known root CA. It's not a Let's Encrypt certificate.

Reply Children
No Data