fiza Posted January 26, 2024 Posted January 26, 2024 I have raised a ticket with Smoothwall but I thought I would ask on here too. Recently more and more links in emails that are genuine begin with "url****.sitename.com". **** is always a 4 digit number. Smoothwall is blocking these with "The server's certificate did not match the domain name" Is there an easy way to deal with these in Smoothwall?
ovenchips Posted January 26, 2024 Posted January 26, 2024 Following - we've been running into the same issue here as of recent.
ibpalle Posted January 26, 2024 Posted January 26, 2024 I haven't tested this so not certain it will work - I'm also not a shark with regular expressions so.. In a custom category, create a regular expression in URL patterns to identify those URLs and put that in a do not filter policy - this will avoid certificate inspection for those URLs that trigger the cert ID mismatch. Once the URL is changed to the real one, filtering will kick in again.
bknaggs Posted January 26, 2024 Posted January 26, 2024 If you use the cloud filter the links aren't blocked. I only know this as I'm currently testing the cloud filter. Otherwise yes we're seeing a few instances of this here as well but I hadn't thought of logging a ticket.
5tu Posted January 26, 2024 Posted January 26, 2024 I think these links are from services using SendGrid. There's an article about it here - https://support.sendgrid.com/hc/en-us/articles/10143238252571-Troubleshooting-ERR-CERT-COMMON-NAME-INVALID-Error-in-Links
synaesthesia Posted January 26, 2024 Posted January 26, 2024 So they're not correctly using SSL and this is our or smoothwalls issue because?
fiza Posted January 26, 2024 Author Posted January 26, 2024 I haven't tested this so not certain it will work - I'm also not a shark with regular expressions so.. In a custom category, create a regular expression in URL patterns to identify those URLs and put that in a do not filter policy - this will avoid certificate inspection for those URLs that trigger the cert ID mismatch. Once the URL is changed to the real one, filtering will kick in again. Anyone with a Smoothall box able to let me know how to do this please?
Steve21 Posted January 27, 2024 Posted January 27, 2024 (edited) It's definitely not Smoothwall related as we get the same via Sophos as I was doing this earlier in the week. For example MediHealth Gold use Sendgrid, and to resolve the issue we've stuck: ^[A-Za-z0-9.-]*\.medigold-health\.com Into the Don't Valid Certificate style area in Sophos. It seems to be the site URL you need to use rather than send grid to resolve it Might be a nicer regex you could use, but that seems to work and haven't had much time to test it further this week - So if you just wanted to test it quickly as an example Steve Edited January 27, 2024 by Steve21 1
fiza Posted January 29, 2024 Author Posted January 29, 2024 It's definitely not Smoothwall related as we get the same via Sophos as I was doing this earlier in the week. For example MediHealth Gold use Sendgrid, and to resolve the issue we've stuck: ^[A-Za-z0-9.-]*\.medigold-health\.com Into the Don't Valid Certificate style area in Sophos. It seems to be the site URL you need to use rather than send grid to resolve it Might be a nicer regex you could use, but that seems to work and haven't had much time to test it further this week - So if you just wanted to test it quickly as an example Steve I tried entering that pattern in the URL pattern section of a new category in Smoothwall substituting the domain name for one we received the email from but the validation failed.
rossibIT Posted January 29, 2024 Posted January 29, 2024 Have been having the same problem with Pearson Newsletters. Have been back and forth blaming each other and until recently Pearson had said that they use SendGrid and I am awaiting for a reply from Pearson after they were going to get in contact with them to resolve the issue.
fiza Posted January 31, 2024 Author Posted January 31, 2024 I raised a ticket with smoothwall but the answer I got back was to create a custom category with the domain name in it and then create a do not inspect policy on it. I dont really want to have to do that with every single domain that is using sendgrid that we get emails from with links!
2097 Posted February 28, 2024 Posted February 28, 2024 Also been getting an influx of these. One most recent was : tracking.asdan.org.uk In an email for a password reset, had to add it to the Bypass authentication Category.
robintech Posted February 28, 2024 Posted February 28, 2024 I think these links are from services using SendGrid. There's an article about it here - https://support.sendgrid.com/hc/en-us/articles/10143238252571-Troubleshooting-ERR-CERT-COMMON-NAME-INVALID-Error-in-Links We have a few of those and as described the certificate is invalid especially with link tracking enabled companies don't seem to be setting this up properly and (where we interact with them on a regular basis) ignore our emails asking them to fix it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now