Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote Access VPN - IPSEC with Certificate - connection export .scx file invalid - SFOS 19.5

Remote Access VPN IPSEC with Authentication type certificate does still lead to invalid connection .scx file on SFOS 19.5.0 GA-Build197 and SFOS 19.5.1 MR-1-Build278 if the "Company Name" in the Certificate does contain Whitespaces.

There are some Bug Reports like NC-85383 and NC-95633 whitch are listed as "resoled issues" at the release notes: https://docs.sophos.com/releasenotes/index.html?productGroupID=nsg&productID=xg&versionID=19.5

Looks like the same Problem is reported for older Firmware Versions:  IPSEC Remote Access .scx file invalid 


CA Settings

No "German" Umlaute / "Special" Characters but Whitespaces in Company Name Organization Name.

Certificate Settings


Content of xxx.scx:

cannot open file /tmp/root_cert.txt at /scripts/vpn/ipsec/generateJSONVPNClientConf.pl line 331.



This thread was automatically locked due to age.
Parents
  • If I remove the Whitespaces in "Company Name" for the Certificate, the .scx file is generated correctly.

    Please fix the BUG!

  • We tried to reproduce the issue on the SFOS 19.5.1 MR-1-Build278, we are not hitting the issue.

  • Thanks for your Feedback.

    Whitespaces are at the Organization Name not Company Name, I`ve edited my post.

    Certificate details looks like this:

    Country name: Germany
    State: XYZ
    Locality name: Somewhere
    Organization Name: The Example Company GmbH
    Organization unit name: IT
    Common Name: xyz.example.com
    Email address: somebody@example.com

    DNS names: xyz.example.com

    If I change Organization Name to "TheExampleCompanyGmbH", it works.

    Did you test with a "new" Config on SFOS 19.5? Maybe it only happens with config upgraded from older Version? I believe we startet with the Firewall around SFOS 17 and updated at least to every Mayor MR Release.

  • Just to be sure: Do you have special characters somewhere? Because in Germany, you can easily do something like "Köln" or "München" as a City or street. 

    __________________________________________________________________________________________________________________

Reply
  • Just to be sure: Do you have special characters somewhere? Because in Germany, you can easily do something like "Köln" or "München" as a City or street. 

    __________________________________________________________________________________________________________________

Children
No Data