This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Adding a Windows Server CA to the CA List

Hi All

I am new to XG and having certificate issues.

I want to be able to add my own Windows Server Certificate Authority to the XG.  The Windows CA is the root for my environment.  I have used the Windows Server CA web admin to download the CA certificate, however I cannot get the XG to accept the certificate no matter what option I use. I get this error "Certificate Authority could not be uploaded". 

I am also having trouble importing commercial host certificates (DigiCert), including certificates that used a CSR created on the XG.  I have tried to update their CA certificates but have the same issue as with the Windows CA.

I have tried all manner of certificate formats, without luck.  It is like the whole certificate service is broken, or I don't have the correct rights to perform certificate functions.  All the different certificates I have tried all import into Windows and Linux hosts are appear to work fine.

I am using version XG 16.01.0 running in Hyper-V.

Can anyone please advise.

Thanks in advance

 



This thread was automatically locked due to age.
Parents
  • Another issue I just resolved trying to do this, be sure that the CA is in DER (binary-encoded) format, not CER (Base64 encoded, the way most certs come from support pages for public CAs!). CER encoding will give the same mysterious "Certificate Authority could not be uploaded".

     

    Sophos, maybe add CER support to the CA import option?

Reply
  • Another issue I just resolved trying to do this, be sure that the CA is in DER (binary-encoded) format, not CER (Base64 encoded, the way most certs come from support pages for public CAs!). CER encoding will give the same mysterious "Certificate Authority could not be uploaded".

     

    Sophos, maybe add CER support to the CA import option?

Children
No Data