This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Certificate issue for macos 10.15 for DPI

Dear community,

I'm happy that I upgraded my small business hardware with a XG 135w.

As deep packet inspection for HTTPS streams with macos did not work since two years ago I give it a chance and it looks that I oversee something obvious.

Please give me advice.

I have downloaded the SecurityAppliance_SSL_CA certificate onto my macbookpro. The ending of the file is .pem that does not have a meaning for my other Windows 10 computers. But I would like first to get my macbookpro into this.

By double-klicking on the downloaded file I can see that the file is imported in the key registry as it should be.

When I switch the firewall rule to do DPI than I can not open goole, neither yahoo neither all the other stuff searches. It is very, very limited.

I can switch in the firewall the rule to DPI https inspection on or off. With OFF everything works pretty good. All things in macos catalina work properly (applestore, music downloads, ... all cloud functions). But with ON a lot of things do not work like safary searches, as mentioned. First I want to understand how to enable Safary and DPI at HTTPS streams.

Only Apple's website and Sopho's websites and of course some others are available.

For bing or goole searches the pages are just blocked without any notification.

For yahoo it's telling me that the site is not private.

I'm running also sophos endpoint that changed the accessibility to my firewall. But that's not a problem to me anymore.

What am I doing wrong as I do not see any special recommendations or problems out in the world? Please help.

Please see some pictures attached.

Cheers,

Frank



This thread was automatically locked due to age.
Parents
  • I know this should be an easy and basic thing and no inspiring question but I guess that I'm doing something easily wrong.

    I forgot to send to other pictures that are also important to my request.

    Of course I'm using SFOS 17.5.8 MR8 on the device.

    Here are screenshots from the WEB rule and the general settings:

    Cheers,

    Frank

  • Frank,

    I am using decrypt and scan on my MAC almost from 3 years and I never had any issue.

    Did you try with Firefox?  Do you have the same issue?

    Thanks

  • How long does your XG run? 

    https://www.reddit.com/r/sophos/comments/cts9mm/sophos_xg_web_filter_ca_issued_certificates_no/

    Apple changed the requirements of the Certificate. So to speak, you should regenerate and re deploy the certificate, if your HTTPs Certificate does not match the needed requirements. 

    But be careful, if you press regenerate on XG, the old certificate should not be enabled anymore (as far as i know). So this could lead to a downtime, until you redeploy all stations. 

    __________________________________________________________________________________________________________________

  • Hi Iferrara,

    I've installed now firefox 69.0.3 and all sites work.

    It's a pitty that Safari is useless with HTTPS scans.

    I had a clean install of my mac to start from 0.

    I've changed another thing as well as I was seeing those messages to disable "Block unrecognized SSL protocols" option from "Web -> Protection -> HTTPS Decryption and Scanning".

    So, my issue is now solved with your workaround.

    Thanks.

    Cheers, Frank

Reply
  • Hi Iferrara,

    I've installed now firefox 69.0.3 and all sites work.

    It's a pitty that Safari is useless with HTTPS scans.

    I had a clean install of my mac to start from 0.

    I've changed another thing as well as I was seeing those messages to disable "Block unrecognized SSL protocols" option from "Web -> Protection -> HTTPS Decryption and Scanning".

    So, my issue is now solved with your workaround.

    Thanks.

    Cheers, Frank

Children