This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

certificate issues

hi all

i have UTM9, and there is a problem with the host name in the web certificate setting

we changed the host name and didnt re-generate the certificate so we are having error when we try to access the  UTM web interface, saying "your connection is nit secure"

 

this is where we use the cert:

"

Used in these configurations:
Email Protection → SMTP → Advanced
Management → WebAdmin Settings → HTTPS Certificate

"

my question is:

1- if we re-generate by correcting the host name will this effect the production line? i mean is this gonna effect the network or anything live while applying the new setting?

2-is this going to fix the public access? like if i want to login to UTM from home will i still have the error message "This server could not prove that it is XXXX; its security certificate is from YYYY This may be caused by a misconfiguration or an attacker intercepting your connection."

3- will this fix the SMTP error too? 

 

FYI the cert said its valid till 2037

 

 

best



This thread was automatically locked due to age.
Parents
  • Thanks, Doug, that will be helpful to many people.

    Leo, to change the hostname, use the trick listed in The Zeroeth Rule in Rulz.

    Yes, this will change the underlying CA for all certificates.  If you're doing 'Decrypt and scan' in Web Filtering you will need to redistribute the new HTTPS CA to all users.

    Yes, this will cause you to have to distribute new SSL VPN Remote Access configurations because the UTM and the users will all have new certificates.  If you do the rename as suggested, first change the SSL VPN Protocol to UDP.

    Of course, you also can change the hostname separately for the VPN and for SMTP, but that's not a nice thing to do to the person that follows you.

    Cheers - BOb

  • is it better to do it at off work time? and make people logout and login again to their email app?

  • It only takes a few minutes to use that trick, so it depends on your situation and whether or not you have to worry about the following.

    If their email client is not web-based using HTTPS or you're not using 'Decrypt and Scan' in Web Filtering, then there should be no effect on that part.  Changing the Hostname only affects the banner that the SMTP Proxy sends when it relays your emails to external domains.

    It only affects VPNs and Remote Access if you're using certificate-based like Cisco, IPsec, SSL VPN and L2TP/IPsec with certificates.

    Cheers - Bob

  • Bob...let me know if i am wrong 

     

    now i can generate a certificate request and send it to CA to get it signed then i can use it for my web interface, VPN, Remote access, SMTP and TLS....right ?

     

    FYI  we are hosting a web server locally and its serving our web site, also i found a godaddy certificate in the exchange server i think i can import it to the UTM and use it for the TLS?

  • Yes, and it appears that you've understood that the cert is used to negotiate TLS in the SMTP Proxy.

    Cheers - Bob

  • Bob one last question...do i have to have a "signed" certificate from CA for the VPN? if its self-signed will the browser show that error again? if i want to connect to a branch and brows the intranet for example 

  • I'm not sure what question you're asking, Leo.  Is this a question about accessing via site-to-site VPN or Remote Access?

    Cheers - Bob

  • i mean for accessing the web admin  interface  for the UTM from outside the company network or connect a remote user via VPN to the company network 

    in this case do i have to use a signed certificate by CA or self-signed one, and if i use the self signed will i still have the browser security warning ?

    thanks

  • You can use either CA.  I like to add the "MyUserName (User Netwrok)" object to 'Allowed Networks' so that I can get in via Remote Access.

    Cheers - Bob

Reply Children
No Data