This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

certificate issues

hi all

i have UTM9, and there is a problem with the host name in the web certificate setting

we changed the host name and didnt re-generate the certificate so we are having error when we try to access the  UTM web interface, saying "your connection is nit secure"

 

this is where we use the cert:

"

Used in these configurations:
Email Protection → SMTP → Advanced
Management → WebAdmin Settings → HTTPS Certificate

"

my question is:

1- if we re-generate by correcting the host name will this effect the production line? i mean is this gonna effect the network or anything live while applying the new setting?

2-is this going to fix the public access? like if i want to login to UTM from home will i still have the error message "This server could not prove that it is XXXX; its security certificate is from YYYY This may be caused by a misconfiguration or an attacker intercepting your connection."

3- will this fix the SMTP error too? 

 

FYI the cert said its valid till 2037

 

 

best



This thread was automatically locked due to age.
Parents
  • Thanks, Doug, that will be helpful to many people.

    Leo, to change the hostname, use the trick listed in The Zeroeth Rule in Rulz.

    Yes, this will change the underlying CA for all certificates.  If you're doing 'Decrypt and scan' in Web Filtering you will need to redistribute the new HTTPS CA to all users.

    Yes, this will cause you to have to distribute new SSL VPN Remote Access configurations because the UTM and the users will all have new certificates.  If you do the rename as suggested, first change the SSL VPN Protocol to UDP.

    Of course, you also can change the hostname separately for the VPN and for SMTP, but that's not a nice thing to do to the person that follows you.

    Cheers - BOb

  • is it better to do it at off work time? and make people logout and login again to their email app?

  • It only takes a few minutes to use that trick, so it depends on your situation and whether or not you have to worry about the following.

    If their email client is not web-based using HTTPS or you're not using 'Decrypt and Scan' in Web Filtering, then there should be no effect on that part.  Changing the Hostname only affects the banner that the SMTP Proxy sends when it relays your emails to external domains.

    It only affects VPNs and Remote Access if you're using certificate-based like Cisco, IPsec, SSL VPN and L2TP/IPsec with certificates.

    Cheers - Bob

Reply
  • It only takes a few minutes to use that trick, so it depends on your situation and whether or not you have to worry about the following.

    If their email client is not web-based using HTTPS or you're not using 'Decrypt and Scan' in Web Filtering, then there should be no effect on that part.  Changing the Hostname only affects the banner that the SMTP Proxy sends when it relays your emails to external domains.

    It only affects VPNs and Remote Access if you're using certificate-based like Cisco, IPsec, SSL VPN and L2TP/IPsec with certificates.

    Cheers - Bob

Children