Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to update Appliance certificate.

I'm trying to update our Certificate on the Firewall, but it says it is in use by VPN, which is true. How do I update it then. I tried choosing the localappliance certificate as a temporary holder to try an update, but when I do that, it says you must enter a Network IP Address. I have everything filled in. I'm just trying to update the certificate that expires in 4 days. Below is what I get when I try to update the certificate.  Any help is appreciated. 

Model: Sophos XGS

Active Firmware: 19.0.1 MR-1-Build365



This thread was automatically locked due to age.
Parents Reply
  • That corrected the issue about the network IP address, but now it says I can't update the certificate because it is in use for the admin port settings. 
    Why Can't I just update the certificate and everything that uses it use the updated certificate get updated by the system. If it already knows what I'm using it for, let me update it and then Sophos update everywhere it needs that is currently using it.

Children
  • Well that is architectural design, as of now you navigate  to Administration > Admin and user settings > Admin console and end-user interaction, here you can select you can select temporary holder and check again.



    Apart from this, another workaround is to use API, with the following steps below:

    1. Install a new certificate
    2. For each object type where a certificate may be used:
      1. get current settings (which is based on XML)
      2. modify XML so it refers to the new certificate
      3. post new settings
    3. Delete old certificate

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.