Jaan Posted September 2, 2022 Posted September 2, 2022 starting today, all our users are unable to access their Gmail accounts. The error relates to the mail.google.com cert date has expired, Sophos XG cert still valid I have confirmed the HTTPS cert we push out to our users is still valid which it is. Somethings expired today, just not sure how i fix it. Here's some screens, any ideas?
Jaan Posted September 2, 2022 Author Posted September 2, 2022 UPDATE: I've added mail.google.com to our https cert exceptions which fixes the issue. I'm still confused why it stopped working though?
ibpalle Posted September 2, 2022 Posted September 2, 2022 Says certificate is valid until the 2nd. Could mean that once 2nd Sept comes round it's invalid. Since the message says date is invalid, that could be the case.
PaddyNewman Posted September 2, 2022 Posted September 2, 2022 Not according to your post, it expires today? 2 years 3 month certificate length, that is 800 days on the dot, which sounds like a manually made cert.
Jaan Posted September 5, 2022 Author Posted September 5, 2022 Here's my deployed https: certs for my XG. only affecting Google services. lots of issues this morning still
PaddyNewman Posted September 5, 2022 Posted September 5, 2022 Does Sophos have a cache of certs it's faked up, might be worth clearing that if so?
Jaan Posted September 5, 2022 Author Posted September 5, 2022 Does Sophos have a cache of certs it's faked up, might be worth clearing that if so? good call!...... however i can't find the cache for the life of me.
Jaan Posted September 5, 2022 Author Posted September 5, 2022 I've powered down our XG and cold booted it again (can't find where they have put the clear cache buton in the GUI). However i still have the issue. if i type www.google.com into chrome i get a invalid cert (expired), however if i type www.google.es it works fine.
lmrogers Posted September 5, 2022 Posted September 5, 2022 I believe I've had similar issue before https://community.sophos.com/sophos-xg-firewall/f/discussions/102313/https-scanning-where-is-the-certificate-cache-for-external-websites The solution was on that thread, needed to SSH into the firewall and use the advanced shell.
Jaan Posted September 5, 2022 Author Posted September 5, 2022 I believe I've had similar issue before https://community.sophos.com/sophos-xg-firewall/f/discussions/102313/https-scanning-where-is-the-certificate-cache-for-external-websites The solution was on that thread, needed to SSH into the firewall and use the advanced shell. can i do this directly on the XG? don't suppose you have any links to instructions on the commands i need to run do you? Never have to do this before. thanks
PaddyNewman Posted September 5, 2022 Posted September 5, 2022 Looks to be just SSHing to the XG Chose »5. Device Management Chose »3. Advanced Shell Identified the certificate(s) in /var/certcache/ and removed the cached files (if its just a Linux box, then ls | grep google and find the right one, rm name-of-file) Then went to Protect > Web in the Web Management Interface an clicked Apply on »HTTPS Decryption and Scanning« without changing any setting there 1
PaddyNewman Posted September 5, 2022 Posted September 5, 2022 Weird that its not configured to mark expiring/expired certs and purge... cached certs are a quick way of faking and saving the hassle on each inspection, but I'd have expected it to have a TTL or similar to mark it for deletion. Oh well
Jaan Posted September 5, 2022 Author Posted September 5, 2022 Weird that its not configured to mark expiring/expired certs and purge... cached certs are a quick way of faking and saving the hassle on each inspection, but I'd have expected it to have a TTL or similar to mark it for deletion. Oh well being able to do it in the Sophos gui with having to ssh would also be helpful!
PaddyNewman Posted September 5, 2022 Posted September 5, 2022 Ideally, fully automatic and nothing needed by the end-user, I imagine everyone has plenty other important tasks! Might be a good feature request to Sophos? I have no contacts within Sophos, however I imagine its as simple as a 'Clear cached certificates' button that simply runs a service/command to clear the folder.
Jaan Posted September 6, 2022 Author Posted September 6, 2022 Ideally, fully automatic and nothing needed by the end-user, I imagine everyone has plenty other important tasks! Might be a good feature request to Sophos? I have no contacts within Sophos, however I imagine its as simple as a 'Clear cached certificates' button that simply runs a service/command to clear the folder. with regards to "clearing the folder" i've had acouple more domains today with the same error...... might be best to just purge the lot! If i just rm * in that directory, i assume it just contains certs?
Wave9_Lee Posted September 6, 2022 Posted September 6, 2022 There's a fix for this in the next SFOS update - probably September. As the current fix requires clearing out files via CLI, its best to get qualified help - All Sophos licences come with access to Sophos Support to do this, or Wave 9 customers can drop us a note and we'll do it for you. 1
Jaan Posted September 6, 2022 Author Posted September 6, 2022 There's a fix for this in the next SFOS update - probably September. As the current fix requires clearing out files via CLI, its best to get qualified help - All Sophos licences come with access to Sophos Support to do this, or Wave 9 customers can drop us a note and we'll do it for you. Awesome thanks lee
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now