E2Guardian - SSL intercept with EXPIRED CA cert.

151 views
Skip to first unread message

Fabricio Guzzy

unread,
Dec 5, 2024, 1:08:55 PM12/5/24
to e2guardian
Folks, 
Today all my firewalls got the same problem. 
While using the SSL intercept, E2G is generating a CA with expired date - 05-DEC-2024 13:35:51 GMT
It seems it's something hardcoded to E2G.

Whatever the CA i use to intercept, it's always the same error.

Any idea?

Fabricio.

Orion Poplawski

unread,
Dec 5, 2024, 2:17:01 PM12/5/24
to e2gua...@googlegroups.com
We hit this as well. You need to update generatedcertstart in
e2guardian.conf.

--
Orion Poplawski
he/him/his - surely the least important thing about me
IT Systems Manager 720-772-5637
NWRA, Boulder/CoRA Office FAX: 303-415-9702
3380 Mitchell Lane or...@nwra.com
Boulder, CO 80301 https://www.nwra.com/

Roman Marukhin

unread,
Dec 5, 2024, 2:24:44 PM12/5/24
to e2guardian
Hello Fabricio,

you probably need to fix the below parameters the e2guardian.conf file

```
#Generated cert start time (in unix time) - optional
# defaults to 1417872951 = 6th Dec 2014
# generatedcertstart = 1417872951

#Generated cert end time (in unix time) - optional
# defaults to generatedcertstart + 10 years
#genratedcertend =
# generatedcertstart =
```

With best regards,
Roman M
Message has been deleted

Fabricio Guzzy

unread,
Dec 6, 2024, 8:58:46 AM12/6/24
to e2guardian
Thanks guys! 
That did the trick!

I also changed the source code on my side and recompiled it.

Thanks
Fabricio

Message has been deleted

Remco B

unread,
Dec 9, 2024, 4:55:03 AM12/9/24
to e2guardian
You're a life saver!

Mr Red

unread,
Dec 10, 2024, 3:16:05 AM12/10/24
to e2guardian
how to using/configure this, because i dont understand in this configuration

Mr Red

unread,
Dec 10, 2024, 3:18:37 AM12/10/24
to e2guardian
Screenshot from 2024-12-10 16-18-13.png

Mr Red

unread,
Dec 10, 2024, 3:23:48 AM12/10/24
to e2guardian
can anyone give me command for configuration generate ssl certificate? because i need your help

Mr Red

unread,
Dec 10, 2024, 3:35:42 AM12/10/24
to e2guardian
i try , but same error in browserScreenshot from 2024-12-10 16-34-44.png

On Friday, 6 December 2024 at 02:08:55 UTC+8 Fabricio Guzzy wrote:

Mr Red

unread,
Dec 10, 2024, 7:49:42 AM12/10/24
to e2guardian
#Generated cert start time (in unix time) - optional
# defaults to 1417872951 = 6th Dec 2014
generatedcertstart = 1702070400


#Generated cert end time (in unix time) - optional
# defaults to generatedcertstart + 10 years
generatedcertend = 1702166800
# generatedcertstart =
 is that true configuration? if i mistake please correct this and help me, thanks

On Friday, 6 December 2024 at 03:24:44 UTC+8 Roman Marukhin wrote:
Reply all
Reply to author
Forward
0 new messages