mdrabble Posted December 16, 2021 Posted December 16, 2021 So my smoothwall box has been warning me about the Guardian CA due to expire in 11 days.... so I have renewed, etc, get the HTTPS inercept to the new cert, cleared and restarted, and then deleted the old cert. However I am still getting warnings about the Guardian CA certificate due to expire - even after a full reboot. As you can see by the image, they are all in date - so not sure why I'm still getting the warning. Anyone any ideas - before I log a ticket with Smoothwall. Cheers.
BOOT Posted December 16, 2021 Posted December 16, 2021 Try making a new temporary Root CA, then switch to that and back again.
r0cketbev Posted December 16, 2021 Posted December 16, 2021 Leave it till tomorrow and it will go away. Had do this about 6 times last month. 1
mdrabble Posted December 17, 2021 Author Posted December 17, 2021 Logged in this morning and all fine :-)
ibpalle Posted December 17, 2021 Posted December 17, 2021 The check for the alert runs overnight so right after renewing, the alert will still show - as you also noticed, it's gone the following day. We are changing the check to run after a new CA has been set as well. 1
kennysarmy Posted July 11, 2023 Posted July 11, 2023 The check for the alert runs overnight so right after renewing, the alert will still show - as you also noticed, it's gone the following day. We are changing the check to run after a new CA has been set as well. Hi, My Guardian CA certificate expires soon. Is it just a case of clicking "New Certificate"? Then "exporting" and replacing the one in my GPO that pushes this cert. out? Or do I click New Root CA? It's not very clear what to do :/
ibpalle Posted July 11, 2023 Posted July 11, 2023 It's not very clear what to do :/ The button below the notification takes you to this KB which shows you step by step what to do: https://kb.smoothwall.com/hc/en-us/articles/360002833340
kennysarmy Posted July 11, 2023 Posted July 11, 2023 The button below the notification takes you to this KB which shows you step by step what to do: https://kb.smoothwall.com/hc/en-us/articles/360002833340 OK. Is it best to leave the new CA being deployed via GPO for a few days before making it default?
ibpalle Posted July 11, 2023 Posted July 11, 2023 Is it best to leave the new CA being deployed via GPO for a few days before making it default? Yes, the new CA and the old wont clash so both can be installed at the same time. You can push out the new one and once ready, swap on the Smoothwall. The only issue is that the http://ip.or.hostname/getcert will present the old one until the CA is swapped in the UI.
JATSO Posted July 17, 2023 Posted July 17, 2023 (edited) Yes, the new CA and the old wont clash so both can be installed at the same time. You can push out the new one and once ready, swap on the Smoothwall. The only issue is that the http://ip.or.hostname/getcert will present the old one until the CA is swapped in the UI. Hi, I am a bit stuck on this one, I seem to have managed to create a new cert today but the ip/getmitm page is still defaulting to the old cert. Do i need to change anything or will it correct itself? I have tried selecting the new certificate I created but it is not showing. Any ideas? TIA Edited July 17, 2023 by JATSO
ChrisC Posted July 17, 2023 Posted July 17, 2023 Hi, I am a bit stuck on this one, I seem to have managed to create a new cert today but the ip/getmitm page is still defaulting to the old cert. Do i need to change anything or will it correct itself? I have tried selecting the new certificate I created but it is not showing. [ATTACH=CONFIG]69521[/ATTACH] Any ideas? TIAYou need to create a new cert under the new CA for user-facing services (and I think the admin interface as well). I generally include all the SANs for the local addresses and the internal IP(s) of the smoothwall as a catch all depending on how you've navigated to the interface.
ibpalle Posted July 18, 2023 Posted July 18, 2023 Hi all A KB on how to create a new CA is located here: https://kb.smoothwall.com/hc/en-us/articles/360002833340 Once the new CA is created, it won't be referenced on the smoothwall/getcert(getmitm) page until the new CA is set as the default. 1
kennysarmy Posted July 20, 2023 Posted July 20, 2023 I've done the switch over to the new Certificate, but the warning is still showing on the Smoothwall, will login tomorrow and see if it's cleared :/
tdk1069 Posted July 20, 2023 Posted July 20, 2023 I got impatient waiting and ran this http://www.edugeek.net/forums/internet-related-filtering-firewall/223524-smoothwall-root-ca-renewal.html#post1915066 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now