Jump to content

Recommended Posts

Posted

I've renewed the Root CA on our smoothwall for Https inspection, set it as the default CA and set the cert to be used for the various services, but the GUI display the message '

The Guardian CA certificate has expired. Click the button below to find out how to regenerate the certificate' all the time when logged in. I've cleared all the old certificates, rebooted and only have the brand new root CA showing (along with the dynamic ones created), which expires in 2023 but the message won't clear





Is there something I've missed? I've not logged this with smoothwall as its taking too long to get a response these days.

Posted

Is anything wrong on the browsing side? Does HTTPS inspection and blockpages for HTTPS pages still work fine? If so, it would mean the new CA is in use and working, just the message is duff which could be a bug.

 

If the new CA is not set top be used by HTTPS inspection, try to make sure by going to guardian - https inspection - settings and select the new top level CA you created to replace the new one as the one to use for HTTPS inspection. Don't use the automatically generated one for now and see if that makes the message disappear.

 

Also, there is a KB for the steps required to create and use a new CA located here: https://kb.smoothwall.com/hc/en-us/articles/360002833340

Posted
System > Preferences > User Interface.

 

Make sure the current cert is whats set in the admin UI bit

Yeah - that's all OK - it uses the new CA for all https services. Its weird as its not the first time I've renewed a smoothwall cert, just this time its convinced itself its still expired!

Posted
Yes, In think somethings wrong with the check that removes the alert. Just saw this on another system. I'll see if I can test and bug it.
Posted (edited)

Just a question - was the CA created and set today? If so, the alert should be gone by tomorrow - the check only happens once a day. You can force the check by running

 

# /modules/guardian3/etc/actions/crondailyrandom/0090trigger_certificate_exp_warning

 

On the CLI

Edited by ibpalle
  • Thanks 1
Posted
Just a question - was the CA created and set today? If so, the alert should be gone by tomorrow - the check only happens once a day. You can force the check by running

 

# /modules/guardian3/etc/actions/crondailyrandom/0090trigger_certificate_exp_warning

 

On the CLI

 

Yup - it was created yesterday and the message has now gone today - I assumed the message would clear once the new valid CA was created

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...