Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Validate Server Certificate

Hey guys, reaching out for some much-needed help. Have read similar posts but nothing makes sense to me in them.

I have purchased a certificate as well as created a local active directory certificate server. (All Witchcraft to me)

Have installed them on the sophos XG firewall under Certificates. All working well it appears.

I go to:

Configure -> Authentication -> Servers and set up my SSL/TLS connection to active directory.

Select Test Connection and all is good. 

However, when I select Validate server Certificate I get:

What is the firewall doing here, which server is down or unreachable? Is it my Root CA server that is in active directory? Or is it the domain controller? (CA is install on a Domain Member, not on the domain controller)

Note: Firewalls are not active on the Windows Domain Controller and Domain Members. 

All active directory servers and workstation are on the local network. I don't think I am restricting anything on the local network. Or is there a predefined rule that does?

What am I missing here? Any advice would be greatly appreciated. 

Thankyou. 



This thread was automatically locked due to age.
Parents
  • Hello  ,

    Thank you for reaching out to the community, please refer the following article - Sophos Firewall: A Quick Guide for LDAPS/AD Integration With Windows Server 2022/2019/2012… 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Thanks for your prompt response. Unfortunately, it doesn't answer my questions. ldp.exe seems to be superseded as well. Can't find it anywhere. Regardless going through the documentation steps as best I could I concluded my setup is working.

    However as mentions above, my "Validate Server Certificate" fails. 

    "What is the firewall doing here, which server is down or unreachable? Is it my Root CA server that is in active directory? Or is it the domain controller? (CA is install on a Domain Member, not on the domain controller)"

    Some insight into this would be greatly appreciated.

  • And what if you untick the option "validate server certificate." and then click on the  test connection ?

    To check further we can enable the access_server service in debug enable the option "validate server certificate." and check the logs.
    On the CLI, select option 5. Device Management, then option 3. Advanced Shell

    1.) To enable/disable debug: service access_server:debug -ds nosync
    2.) To check debug logs: tail -f access_server.log  .........................................[Perform the connection test and fetch the results in the logs] 

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Thanks again for the prompt reply. 

    Question: And what if you untick the option "validate server certificate." and then click on the  test connection ?

    Answer: I get the Green, Device - AD server connectivity test successful

    I can authenticate through Active directory fine.

    Thanks, I will try what you suggested above tonight and see how I go and report back.

    Much appreciated.

Reply
  • Thanks again for the prompt reply. 

    Question: And what if you untick the option "validate server certificate." and then click on the  test connection ?

    Answer: I get the Green, Device - AD server connectivity test successful

    I can authenticate through Active directory fine.

    Thanks, I will try what you suggested above tonight and see how I go and report back.

    Much appreciated.

Children
No Data