Sheridan Posted August 31, 2021 Posted August 31, 2021 I've renewed the Root CA on our smoothwall for Https inspection, set it as the default CA and set the cert to be used for the various services, but the GUI display the message 'The Guardian CA certificate has expired. Click the button below to find out how to regenerate the certificate' all the time when logged in. I've cleared all the old certificates, rebooted and only have the brand new root CA showing (along with the dynamic ones created), which expires in 2023 but the message won't clear Is there something I've missed? I've not logged this with smoothwall as its taking too long to get a response these days.
DGardiner Posted August 31, 2021 Posted August 31, 2021 Have you installed the new root ca on the client
ibpalle Posted August 31, 2021 Posted August 31, 2021 Is anything wrong on the browsing side? Does HTTPS inspection and blockpages for HTTPS pages still work fine? If so, it would mean the new CA is in use and working, just the message is duff which could be a bug. If the new CA is not set top be used by HTTPS inspection, try to make sure by going to guardian - https inspection - settings and select the new top level CA you created to replace the new one as the one to use for HTTPS inspection. Don't use the automatically generated one for now and see if that makes the message disappear. Also, there is a KB for the steps required to create and use a new CA located here: https://kb.smoothwall.com/hc/en-us/articles/360002833340
Sheridan Posted August 31, 2021 Author Posted August 31, 2021 Its installed on the client, and seems to be ok in https inspection - just the web gui shows the error all the time
DGardiner Posted August 31, 2021 Posted August 31, 2021 System > Preferences > User Interface. Make sure the current cert is whats set in the admin UI bit 1
Sheridan Posted August 31, 2021 Author Posted August 31, 2021 System > Preferences > User Interface. Make sure the current cert is whats set in the admin UI bit Yeah - that's all OK - it uses the new CA for all https services. Its weird as its not the first time I've renewed a smoothwall cert, just this time its convinced itself its still expired!
ibpalle Posted August 31, 2021 Posted August 31, 2021 Yes, In think somethings wrong with the check that removes the alert. Just saw this on another system. I'll see if I can test and bug it.
ibpalle Posted August 31, 2021 Posted August 31, 2021 (edited) Just a question - was the CA created and set today? If so, the alert should be gone by tomorrow - the check only happens once a day. You can force the check by running # /modules/guardian3/etc/actions/crondailyrandom/0090trigger_certificate_exp_warning On the CLI Edited August 31, 2021 by ibpalle 1
Sheridan Posted September 1, 2021 Author Posted September 1, 2021 Just a question - was the CA created and set today? If so, the alert should be gone by tomorrow - the check only happens once a day. You can force the check by running # /modules/guardian3/etc/actions/crondailyrandom/0090trigger_certificate_exp_warning On the CLI Yup - it was created yesterday and the message has now gone today - I assumed the message would clear once the new valid CA was created
ibpalle Posted September 1, 2021 Posted September 1, 2021 Yes, so did I. The check will be changed to also run after a replacement of the HTTPS inspection certificate is noticed. 2
jmak Posted September 1, 2021 Posted September 1, 2021 Every time I see this thread title I misread it as root canal [emoji15] 1
caffrey Posted September 2, 2021 Posted September 2, 2021 Every time I see this thread title I misread it as root canal [emoji15] Not just me then
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now