Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
My domain is: nwdw-kpl-fw01.nw-drywall.com
I ran this command: None - Script embedded in Sophos Firewall
It produced this output: Result is successful.
My web server is (include version): Sophos Firewall V21 (unknown web server but likely some Tomcat variant)
The operating system my web server runs on is (include version): Sophos Firewall Operating System (hardened Linux)
My hosting provider, if applicable, is: N/A
I can login to a root shell on my machine (yes or no, or I don't know): Yes, but applications are stripped.
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot): this fails in the firewall's Linux shell.
Sophos Firewall v21 introduced automatic certificate renewals with Let's Encrypt. The functionality is hidden behind their WebUI.
Issue, the ASV, when performing a PCI scan is seeing 2 failures.
Certificate #0 CN=nwdw-kpl-fw01.nw-drywall.com ISSUER:_CN=E5,O=Let's_Encrypt,C=US self signed certificate in certificate chain
Certificate #2 CN=ISRG_Root_X2,O=Internet_Security_Research_Group,C=US is a self signed certificate
I see these certificates are part of the hierarchy. Are they indeed self signed or is there something missing in the chain? Might this be a Let's Encrypt issue, a Sophos issue (maybe missing a cert in the chain), or is the Authorized Scanning Vendor producing a false positive?
I can engage Sophos support if there are missing intermediate certificates in the chain, but in speaking with their initial line of support, I would need some information to back up the request otherwise they don't know what to do. If it's the ASV, what evidence might I supply to them that it's a false positive on their end?