jerryfudd Posted August 30, 2023 Posted August 30, 2023 Hi there, I am getting this message on the Smoothwall at this site: - The Guardian CA certificate will expire in 24 days. Click the button below to find out how to regenerate the certificate The show me how to guide, basically, just says do it. So, anyway, I can create a New Root CA, although the Root CA hasn't expired? Then I can download it, and push it out via GPO, and Workspace. How do I generate the ones labelled as Dynamic? Or do they self generate and that's why they are dynamic?
jerryfudd Posted August 30, 2023 Author Posted August 30, 2023 Do I even need to bother if the Root CA isn't actually expiring? Will the dynamic ones renew themselves?
jerryfudd Posted August 30, 2023 Author Posted August 30, 2023 I have the solution for this. Create a new root ca. Set the new one as default. Set the old as default - this will renew the dynamic certs. Delete the new root CA as it's no longer needed. 3
howartp Posted August 30, 2023 Posted August 30, 2023 I have the solution for this. Create a new root ca. Set the new one as default. Set the old as default - this will renew the dynamic certs. Delete the new root CA as it's no longer needed. Yep, that's what we do - sorry I didn't see your post earlier.
msi_school Posted August 31, 2023 Posted August 31, 2023 The warning does not update for 24 hours so once you have generated the cert it will still have the warning for the rest of the day.
giblet Posted March 27, 2024 Posted March 27, 2024 I have the solution for this. Create a new root ca. Set the new one as default. Set the old as default - this will renew the dynamic certs. Delete the new root CA as it's no longer needed. Thanks for this. I had the same warning and the 'Show me how' does not show you how.... Anyway that worked perfectly - thanks.
giblet Posted January 14 Posted January 14 Root CA needs updating but the above no longer works - when I set the Old Root CA back to default the old expiry dates remain the same. Does anyone have any ideas or do I just need to wait a day?
tom_newton Posted January 14 Posted January 14 The warning message (stupidly) takes a day to expire - so as long as your clients are happy then dont worry I just did this on my test box - and there are improvements coming (I did try to hack fix the warning message not clearing, but I failed!)
giblet Posted January 14 Posted January 14 (edited) Thanks Tom - I understand the warning will go - but the dates are not updating when I follow the above instructions, see screenshots: I create and set as default new 2026 Root CA as shown and expiry dates update. I then set the old Root CA as default and the dates revert back to expiring in shortly.... So I assume I cannot update the Root CA this way? I will have to create a new one i.e. 2026 one as above - roll it out to all InTune clients - check it installs then switch over to it once I'm sure all clients have received it? Is that correct or is there another quicker and easier way? Edited January 14 by giblet
tom_newton Posted January 14 Posted January 14 No those certs don't do anything until you tell the filter which one to use [on the guardian/https settings page] - but yes, create, then roll out, then tell the filter to use it
giblet Posted January 14 Posted January 14 So I do have to create new Root CA as I thought? It's only the 'Dynamic' certs that you can trick by doing the method below? Create a new root ca. Set the new one as default. Set the old as default - this will renew the dynamic certs. Delete the new root CA as it's no longer needed. 1
tom_newton Posted January 14 Posted January 14 That's what I did on my system, though I am a bit rusty with this
howartp Posted January 14 Posted January 14 If your root CA is expiring then yes you need a new one generating and deploying. The new/old switching routine renews your dynamic certs as you say, but it won't renew them past the expiry of their root. Those switching instructions possibly came from me at some point in the past - I know I've posted that solution with screenshots for someone on here - but my root CA and dynamic certs have different expiries hence why it works for me.
giblet Posted January 14 Posted January 14 Ok - well I've created a new Root CA Cert and sent it to all devices from InTune - hopefully they pick it up and then I'll switch over next week and make the new Root CA cert default in the Smothwall interface and everything will keep working... if not - I've got holiday coming up 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now