Jump to content

Recommended Posts

Posted

Hi there, I am getting this message on the Smoothwall at this site: -

 

The Guardian CA certificate will expire in 24 days. Click the button below to find out how to regenerate the certificate



 

The show me how to guide, basically, just says do it.

 

So, anyway, I can create a New Root CA, although the Root CA hasn't expired? Then I can download it, and push it out via GPO, and Workspace.

 

How do I generate the ones labelled as Dynamic? Or do they self generate and that's why they are dynamic?

 

Screenshot 2023-08-30 142734.png

Posted

I have the solution for this.

 

Create a new root ca.

 

Set the new one as default.

 

Set the old as default - this will renew the dynamic certs.

 

Delete the new root CA as it's no longer needed.

  • Thanks 3
Posted
I have the solution for this.

 

Create a new root ca.

 

Set the new one as default.

 

Set the old as default - this will renew the dynamic certs.

 

Delete the new root CA as it's no longer needed.

 

Yep, that's what we do - sorry I didn't see your post earlier.

  • 6 months later...
Posted
I have the solution for this.

 

Create a new root ca.

 

Set the new one as default.

 

Set the old as default - this will renew the dynamic certs.

 

Delete the new root CA as it's no longer needed.

 

Thanks for this. I had the same warning and the 'Show me how' does not show you how....

 

 

Anyway that worked perfectly - thanks.

  • 1 year later...
Posted

Root CA needs updating but the above no longer works - when I set the Old Root CA back to default the old expiry dates remain the same.  Does anyone have any ideas or do I just need to wait a day?

Posted

The warning message (stupidly) takes a day to expire - so as long as your clients are happy then dont worry

 

I just did this on my test box - and there are improvements coming (I did try to hack fix the warning message not clearing, but I failed!)

Posted (edited)

Thanks Tom - I understand the warning will go - but the dates are not updating when I follow the above instructions, see screenshots:

 

I create and set as default new 2026 Root CA as shown and expiry dates update.

 

1.thumb.PNG.3c6923aeff2b16827a74eff5f3b844f3.PNG

 

I then set the old Root CA as default and the dates revert back to expiring in shortly....

 

2.thumb.PNG.5f3a8ca2bdb4d449d65e9c519bd88c47.PNG

 

So I assume I cannot update the Root CA this way? 

 

I will have to create a new one i.e. 2026 one as above - roll it out to all InTune clients - check it installs then switch over to it once I'm sure all clients have received it?

 

Is that correct or is there another quicker and easier way?

Edited by giblet
Posted

No those certs don't do anything until you tell the filter which one to use [on the guardian/https settings page] - but yes, create, then roll out, then tell the filter to use it

Posted

So I do have to create new Root CA as I thought?  It's only the 'Dynamic' certs that you can trick by doing the method below?

 

Create a new root ca.

 

Set the new one as default.

 

Set the old as default - this will renew the dynamic certs.

 

Delete the new root CA as it's no longer needed.

  • Like 1
Posted

If your root CA is expiring then yes you need a new one generating and deploying.

 

The new/old switching routine renews your dynamic certs as you say, but it won't renew them past the expiry of their root.

 

Those switching instructions possibly came from me at some point in the past - I know I've posted that solution with screenshots for someone on here - but my root CA and dynamic certs have different expiries hence why it works for me.

Posted

Ok  - well I've created a new Root CA Cert and sent it to all devices from InTune - hopefully they pick it up and then I'll switch over next week and make the new Root CA cert default in the Smothwall interface and everything will keep working...  if not - I've got holiday coming up :)

  • Haha 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...