Workaround for SonicOS 7.0.1-XXXX
Â
The suggested workaround below is for customers using SonicOS 7.0.1-XXXX firmware and are not willing/unable to upgrade to the firmware version 7.3.1-XXX and above.
Customers must switch to custom DPI SSL Certificate due to the expiry date (15th-Jan-2026 ) of the default DPI SSL Certificate.
Â
Options for customers who choose to replace the expired Default SonicWall DPI-SSL CA certificate:
- Customers cannot request a DPI-SSL CA certificate from a commercial certificate authority.
- Commercial certificate authorities will not issue certificates with Certificate Signing or Certificate Re-signing authority.
- Customers can create certificates from a private Certificate Authority Server.
- Customers choose to implement their own Certificate Authority servers, such as a Microsoft Certificate Authority Server or an OpenSSL CA server.
- Customers may choose to replace the SonicWall self-signed HTTPS management certificate with a certificates issued by their own Certificate Authority server.
 Note:Â
Customer will have to use strong hash for the certificate.
Customers must also look after maintainance and Protection of the Server CA - Customers may also choose to replace the default SonicWall DPI-SSL CA certificate, the replacement CA certificate must have Certificate Signing or Certificate Re-signing authority
Â
Generating a Certificate Enrollment Request (CER)Â
Â
- Navigate to Device | Settings | Certificates and click New signing Request.

 NOTE: A minimum of SHA256 and 2048 bits is required and SonicWall recommends use of strong hash for the certificate.
- Complete the Generate Certificate Signing Request form and select Generate.
Export the pending Certificate Enrollment Request (CER)
Â
- Navigate to Device | Settings | Certificates and select your certificate pending request Configure button.
- Click Export in your Export Certificate Request Popup.

- Open the export file with notepad for temporary storage

Go to Microsoft CA Server and request a certificate
Â
- Request a certificate.
- Submit and advanced certificate request.

- Click advanced certificate request.

Request a certificate that has re-signing capability and here we are using the "Subordinate Certification Authority" template as an example
Â
- Paste Certificate Enrollment Request text (from your WordPad file) into the Saved Request box.
- In the Certificate Template drop down menu, select the Subordinate Certification Authority template.
- A Subordinate CA template has certificate re-signing capability.
- Do Not use the Web Server template (This template cannot do re-signing).
- Click Submit.

Â
Â
Download from the Microsoft CA Server and save to a local file
Â
- Select the option Download certificate chain.
- Save the certificate (the file’s default name is certnew.p7b, rename if needed as seen in the image).

- Download certificate

- Install this certificate in the Trusted root certificate of the computers ( local network ) by following the steps below:
For Chrome/Edge/IE:Â
- Double clicks on the downloaded certificate
- Select Install Certificate
- Choose whether to install for the current user or the local machine
- Select "Place all certificates in the following store"
- Browse and select Trusted Root Certification Authoritiestab
- ClickFinish. The Certificate Import Wizard will guide you through importing the certificate.
      
 Â
Firefox:
- Enter in the URL:Â about:preferences#privacy
- Scroll Down under Certificatesand click View Certificates
- Click Import
- Select the downloaded certificate
- Select "Trust this CA to identify web sites" and "Trust this CA to identify email users"
- Click OK
       
Â
Mac:
Double-click the certificate file, select Keychain menu, click X509 Anchors, and then click OK. Enter the system username and password and click OK.
Â
Further, you can follow the KB below to know about other methods of distributing the sonicwall DPI SSL Certificate:
https://www.sonicwall.com/support/knowledge-base/various-methods-to-distribute-sonicwall-dpi-ssl-certificate/kA1VN0000000OX50AM\
Â
Complete the certificate enrollment on SonicWall by uploading the newly issued certificate chain
Â
- Navigate to Device | Settings | Certificates and select Import.
- Browse to CA certificate chain file.
- Select file
- Upload file.

- Firewall will promt for a restart.

Â
- After rebooting we should be seeing the CSR as Validated, with the intermediate certificate and CA certificate:

Â
View the imported certificate under DPI-SSL | Client SSL
Â
- The newly installed CA certificate is available for DPI-SSL services.

- Once the DPI SSL client has been enabled and we have selected the imported certificate as DPI SSL client certificate. It should be visible when we try to access any website

Â
Â