This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Import SecurityAppliance_SSL_CA into iOS Devices

 Hi, has anyone had much success implementing Decrypt & Scan HTTPS specifically for iOS and Androis devices. I have exported the SecurityAppliance_SSL_CA but unable to install it on an iPhone.



This thread was automatically locked due to age.
Parents
  • Hi,

     

    Where you able to import the sophos XG SSL cert into IOS device? I am having same issue with IPAD IOS Version 12.4.1, It seems that "trust the root certificate" setting is no longer available in new IOS versions. So far only way to import is if you have Apple Configurator 2 app (which runs on imac only) or MDM. For home, I got neither. 

    I was able to important the SSL cert into WIndows computers and ANdroid phone, took me 5 minutes.

  • Hi,

    I have imported the XG CA into iPad and iPhone, all running the latest versions of IOS 12.4.1.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hi, thanks for the reply. Could you please share how you did it?

Reply Children
  • Hi,

    I sent the p12 to myself and double clicked on it in the mail message.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Well I am able to send the .pem file to myself as well and import it using the Network Agent but that is as far as I can get. There is second step where you need to go into General > About > Certificate Trust Settings > to enable the CA. This option is no longer there. 

  • Ok. It seems there is now a 3 step process.

    Open the SSL CA file > It will show you message "review the profile in settings app..." then go back to settings and under your name, you will see the "downloaded profile" click that, you then install the cert, then go back to General > About > Certificate Trust Settings > to enable the SSL cert. 

  • Hi,

    one thing is you will more than likely need to delete your email accounts and recreate them otherwise you will get continual connection failures on sending.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.