Hello,
is there a way to import my own self signed CA into the XG Firewall to use it as the default CA and delete de standard Sophos CA?
Thank you
Harald
This thread was automatically locked due to age.
Harald,
You cannot change the default CA. The appliance ssl certificate is a "special" certificate that decrypt and encrypt the https traffic on the fly in order to keep the https connection with the original https site unbroken.
So in order to avoid the certificate error page, import the CA inside your browser.
Regards
Hello lferrara.
I'm not using the https decrypt feature.
I' just want to import my own CA and my own VPN Server Certificate because I have multiple users out there and I don't want to change all the existing configurations.
I'm using a self signed Root CA with a self generated VPN Certificate with multiple Intermediate certificates in between.
So I'm guessing, I' staying with my running configuration and do not switch to Sophos when that's not possible.
Thank you anyway for your answer.
Kind Regards
Harald
Hello lferrara.
I'm not using the https decrypt feature.
I' just want to import my own CA and my own VPN Server Certificate because I have multiple users out there and I don't want to change all the existing configurations.
I'm using a self signed Root CA with a self generated VPN Certificate with multiple Intermediate certificates in between.
So I'm guessing, I' staying with my running configuration and do not switch to Sophos when that's not possible.
Thank you anyway for your answer.
Kind Regards
Harald
lferrara,
ok thank you.
I will try that.
Are Intermediate certifactes supported as well?
I mean, is the complete chain served to the openvpn server?
Because on UTM there was only the server certifiacte used and the log was full with broken chain messages, because the root CA was not known by the server, although I imported the Root CA as verifiy CA.
Thank you
Harald