aethercert
Firewalls

Automated certificate upload for Sophos Firewall

The Sophos Firewall package uploads each renewed certificate and key through the firewall's XML API under a fixed name.

The deployment steps defined in this package's manifest.

At a glance

Package
sophos-firewall-target 2.0.0
Compatibility
Sophos Firewall / XG Firewall >=17.0 <22.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
API username and password
Capabilities
Import certificate and key
Deployment steps
uploadCertificate
Rollback
None
Key usage
No requirement

What it does

An agent on your network sends the certificate and key to the Sophos Firewall API on the WebAdmin port (4444 by default), authenticating with an API user.

Rules and services that reference the certificate name use the uploaded certificate.

How it runs

  1. 01

    uploadCertificate

    Certificate and key are uploaded under the configured name.

What you configure

  • WebAdmin host and port (default 4444)
  • API username and password (stored encrypted)
  • Certificate name

Prerequisites

  • The API enabled under Backup & firmware > API
  • The agent's IP address on the API allow-list

Limitations

  • Selecting where the certificate is used is configured on the firewall.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Automate Sophos Firewall

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.