Jump to content

Recommended Posts

Posted

starting today, all our users are unable to access their Gmail accounts.

 

The error relates to the mail.google.com cert date has expired, Sophos XG cert still valid

 

I have confirmed the HTTPS cert we push out to our users is still valid which it is.

 

Somethings expired today, just not sure how i fix it. Here's some screens, any ideas?

 

1.0.PNG

 

1.JPG

 

2.JPG

Posted
UPDATE: I've added mail.google.com to our https cert exceptions which fixes the issue. I'm still confused why it stopped working though?
Posted
Says certificate is valid until the 2nd. Could mean that once 2nd Sept comes round it's invalid. Since the message says date is invalid, that could be the case.
Posted
Does Sophos have a cache of certs it's faked up, might be worth clearing that if so?

 

good call!...... however i can't find the cache for the life of me.

Posted

I've powered down our XG and cold booted it again (can't find where they have put the clear cache buton in the GUI).

 

However i still have the issue.

 

if i type

www.google.com

into chrome i get a invalid cert (expired), however if i type

www.google.es

it works fine.

 

:rolleyes:

Posted
I believe I've had similar issue before

 

https://community.sophos.com/sophos-xg-firewall/f/discussions/102313/https-scanning-where-is-the-certificate-cache-for-external-websites

 

The solution was on that thread, needed to SSH into the firewall and use the advanced shell.

 

can i do this directly on the XG?

 

don't suppose you have any links to instructions on the commands i need to run do you? Never have to do this before.

 

thanks

Posted

Looks to be just

  • SSHing to the XG
  • Chose »5. Device Management
  • Chose »3. Advanced Shell
  • Identified the certificate(s) in /var/certcache/ and removed the cached files (if its just a Linux box, then ls | grep google and find the right one, rm name-of-file)
  • Then went to Protect > Web in the Web Management Interface an clicked Apply on »HTTPS Decryption and Scanning« without changing any setting there

  • Thanks 1
Posted
Weird that its not configured to mark expiring/expired certs and purge... cached certs are a quick way of faking and saving the hassle on each inspection, but I'd have expected it to have a TTL or similar to mark it for deletion. Oh well :)
Posted
Weird that its not configured to mark expiring/expired certs and purge... cached certs are a quick way of faking and saving the hassle on each inspection, but I'd have expected it to have a TTL or similar to mark it for deletion. Oh well :)

 

being able to do it in the Sophos gui with having to ssh would also be helpful!

Posted

Ideally, fully automatic and nothing needed by the end-user, I imagine everyone has plenty other important tasks!

 

Might be a good feature request to Sophos? I have no contacts within Sophos, however I imagine its as simple as a 'Clear cached certificates' button that simply runs a service/command to clear the folder.

Posted
Ideally, fully automatic and nothing needed by the end-user, I imagine everyone has plenty other important tasks!

 

Might be a good feature request to Sophos? I have no contacts within Sophos, however I imagine its as simple as a 'Clear cached certificates' button that simply runs a service/command to clear the folder.

 

with regards to "clearing the folder" i've had acouple more domains today with the same error...... might be best to just purge the lot!

 

If i just rm * in that directory, i assume it just contains certs?

Posted
There's a fix for this in the next SFOS update - probably September. As the current fix requires clearing out files via CLI, its best to get qualified help - All Sophos licences come with access to Sophos Support to do this, or Wave 9 customers can drop us a note and we'll do it for you.
  • Thanks 1
Posted
There's a fix for this in the next SFOS update - probably September. As the current fix requires clearing out files via CLI, its best to get qualified help - All Sophos licences come with access to Sophos Support to do this, or Wave 9 customers can drop us a note and we'll do it for you.

 

Awesome thanks lee

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...