Jump to content

Recommended Posts

Posted

So my smoothwall box has been warning me about the Guardian CA due to expire in 11 days.... so I have renewed, etc, get the HTTPS inercept to the new cert, cleared and restarted, and then deleted the old cert.

 

However I am still getting warnings about the Guardian CA certificate due to expire - even after a full reboot.

 

smoothwall-ca.PNG

 

As you can see by the image, they are all in date - so not sure why I'm still getting the warning.

 

Anyone any ideas - before I log a ticket with Smoothwall.

 

Cheers.

Posted
The check for the alert runs overnight so right after renewing, the alert will still show - as you also noticed, it's gone the following day. We are changing the check to run after a new CA has been set as well.
  • Thanks 1
  • 1 year later...
Posted
The check for the alert runs overnight so right after renewing, the alert will still show - as you also noticed, it's gone the following day. We are changing the check to run after a new CA has been set as well.

 

Hi,

 

My Guardian CA certificate expires soon.

 

Is it just a case of clicking "New Certificate"? Then "exporting" and replacing the one in my GPO that pushes this cert. out?

 

SmoothwallCert.JPG

 

Or do I click New Root CA?

 

It's not very clear what to do :/

Posted
Is it best to leave the new CA being deployed via GPO for a few days before making it default?

 

Yes, the new CA and the old wont clash so both can be installed at the same time. You can push out the new one and once ready, swap on the Smoothwall. The only issue is that the http://ip.or.hostname/getcert will present the old one until the CA is swapped in the UI.

Posted (edited)
Yes, the new CA and the old wont clash so both can be installed at the same time. You can push out the new one and once ready, swap on the Smoothwall. The only issue is that the http://ip.or.hostname/getcert will present the old one until the CA is swapped in the UI.

 

 

Hi,

I am a bit stuck on this one, I seem to have managed to create a new cert today but the ip/getmitm page is still defaulting to the old cert.

Do i need to change anything or will it correct itself?

 

I have tried selecting the new certificate I created but it is not showing.

 

 

UserInterface1.JPG

 

Any ideas?

 

TIA

Edited by JATSO
Posted
Hi,

I am a bit stuck on this one, I seem to have managed to create a new cert today but the ip/getmitm page is still defaulting to the old cert.

Do i need to change anything or will it correct itself?

 

I have tried selecting the new certificate I created but it is not showing.

 

 

[ATTACH=CONFIG]69521[/ATTACH]

 

Any ideas?

 

TIA

You need to create a new cert under the new CA for user-facing services (and I think the admin interface as well).

 

I generally include all the SANs for the local addresses and the internal IP(s) of the smoothwall as a catch all depending on how you've navigated to the interface.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...