Jump to content

Recommended Posts

Posted

I have raised a ticket with Smoothwall but I thought I would ask on here too.

 

Recently more and more links in emails that are genuine begin with "url****.sitename.com". **** is always a 4 digit number.

 

Smoothwall is blocking these with "The server's certificate did not match the domain name"

 

Is there an easy way to deal with these in Smoothwall?

Posted

I haven't tested this so not certain it will work - I'm also not a shark with regular expressions so..

 

In a custom category, create a regular expression in URL patterns to identify those URLs and put that in a do not filter policy - this will avoid certificate inspection for those URLs that trigger the cert ID mismatch. Once the URL is changed to the real one, filtering will kick in again.

Posted

If you use the cloud filter the links aren't blocked. I only know this as I'm currently testing the cloud filter.

 

Otherwise yes we're seeing a few instances of this here as well but I hadn't thought of logging a ticket.

Posted
I haven't tested this so not certain it will work - I'm also not a shark with regular expressions so..

 

In a custom category, create a regular expression in URL patterns to identify those URLs and put that in a do not filter policy - this will avoid certificate inspection for those URLs that trigger the cert ID mismatch. Once the URL is changed to the real one, filtering will kick in again.

 

Anyone with a Smoothall box able to let me know how to do this please?

Posted (edited)

It's definitely not Smoothwall related as we get the same via Sophos as I was doing this earlier in the week.

 

For example MediHealth Gold use Sendgrid, and to resolve the issue we've stuck:

^[A-Za-z0-9.-]*\.medigold-health\.com

Into the Don't Valid Certificate style area in Sophos. It seems to be the site URL you need to use rather than send grid to resolve it

 

Might be a nicer regex you could use, but that seems to work and haven't had much time to test it further this week - So if you just wanted to test it quickly as an example

 

Steve

Edited by Steve21
  • Thanks 1
Posted
It's definitely not Smoothwall related as we get the same via Sophos as I was doing this earlier in the week.

 

For example MediHealth Gold use Sendgrid, and to resolve the issue we've stuck:

^[A-Za-z0-9.-]*\.medigold-health\.com

Into the Don't Valid Certificate style area in Sophos. It seems to be the site URL you need to use rather than send grid to resolve it

 

Might be a nicer regex you could use, but that seems to work and haven't had much time to test it further this week - So if you just wanted to test it quickly as an example

 

Steve

 

I tried entering that pattern in the URL pattern section of a new category in Smoothwall substituting the domain name for one we received the email from but the validation failed.

Posted
Have been having the same problem with Pearson Newsletters. Have been back and forth blaming each other and until recently Pearson had said that they use SendGrid and I am awaiting for a reply from Pearson after they were going to get in contact with them to resolve the issue.
Posted

I raised a ticket with smoothwall but the answer I got back was to create a custom category with the domain name in it and then create a do not inspect policy on it.

I dont really want to have to do that with every single domain that is using sendgrid that we get emails from with links!

  • 4 weeks later...
Posted

Also been getting an influx of these.

 

One most recent was :

 

tracking.asdan.org.uk

 

In an email for a password reset, had to add it to the Bypass authentication Category.

Posted
I think these links are from services using SendGrid. There's an article about it here - https://support.sendgrid.com/hc/en-us/articles/10143238252571-Troubleshooting-ERR-CERT-COMMON-NAME-INVALID-Error-in-Links

 

We have a few of those and as described the certificate is invalid especially with link tracking enabled companies don't seem to be setting this up properly and (where we interact with them on a regular basis) ignore our emails asking them to fix it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...