This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Certificate issue for macos 10.15 for DPI

Dear community,

I'm happy that I upgraded my small business hardware with a XG 135w.

As deep packet inspection for HTTPS streams with macos did not work since two years ago I give it a chance and it looks that I oversee something obvious.

Please give me advice.

I have downloaded the SecurityAppliance_SSL_CA certificate onto my macbookpro. The ending of the file is .pem that does not have a meaning for my other Windows 10 computers. But I would like first to get my macbookpro into this.

By double-klicking on the downloaded file I can see that the file is imported in the key registry as it should be.

When I switch the firewall rule to do DPI than I can not open goole, neither yahoo neither all the other stuff searches. It is very, very limited.

I can switch in the firewall the rule to DPI https inspection on or off. With OFF everything works pretty good. All things in macos catalina work properly (applestore, music downloads, ... all cloud functions). But with ON a lot of things do not work like safary searches, as mentioned. First I want to understand how to enable Safary and DPI at HTTPS streams.

Only Apple's website and Sopho's websites and of course some others are available.

For bing or goole searches the pages are just blocked without any notification.

For yahoo it's telling me that the site is not private.

I'm running also sophos endpoint that changed the accessibility to my firewall. But that's not a problem to me anymore.

What am I doing wrong as I do not see any special recommendations or problems out in the world? Please help.

Please see some pictures attached.

Cheers,

Frank



This thread was automatically locked due to age.
Parents
  • I know this should be an easy and basic thing and no inspiring question but I guess that I'm doing something easily wrong.

    I forgot to send to other pictures that are also important to my request.

    Of course I'm using SFOS 17.5.8 MR8 on the device.

    Here are screenshots from the WEB rule and the general settings:

    Cheers,

    Frank

  • Frank,

    I am using decrypt and scan on my MAC almost from 3 years and I never had any issue.

    Did you try with Firefox?  Do you have the same issue?

    Thanks

  • How long does your XG run? 

    https://www.reddit.com/r/sophos/comments/cts9mm/sophos_xg_web_filter_ca_issued_certificates_no/

    Apple changed the requirements of the Certificate. So to speak, you should regenerate and re deploy the certificate, if your HTTPs Certificate does not match the needed requirements. 

    But be careful, if you press regenerate on XG, the old certificate should not be enabled anymore (as far as i know). So this could lead to a downtime, until you redeploy all stations. 

  • Hi Iferrara,

    I've installed now firefox 69.0.3 and all sites work.

    It's a pitty that Safari is useless with HTTPS scans.

    I had a clean install of my mac to start from 0.

    I've changed another thing as well as I was seeing those messages to disable "Block unrecognized SSL protocols" option from "Web -> Protection -> HTTPS Decryption and Scanning".

    So, my issue is now solved with your workaround.

    Thanks.

    Cheers, Frank

  • Toni thanks for your reply.

    My XG is nearly hot. 2 weeks ago I got my.

    I have now redeployed the certificate. (deleted the old ones before)

    Safari asks for each of my bookmarked sites 'site is not private'.

    Per site and following the non private stuff I see that the web site certificates are installed.

    But that is not practical. Site per site.

    Bing, Google and Yahoo still not wanting to be opened.

    Cannot establish a secure connection.

    Will stick to the workaround with firefox.

    Now I will try to import certificate to my iOS (later next week). I hope that I can use the builtin browser?

    Cheers,

    Frank

Reply
  • Toni thanks for your reply.

    My XG is nearly hot. 2 weeks ago I got my.

    I have now redeployed the certificate. (deleted the old ones before)

    Safari asks for each of my bookmarked sites 'site is not private'.

    Per site and following the non private stuff I see that the web site certificates are installed.

    But that is not practical. Site per site.

    Bing, Google and Yahoo still not wanting to be opened.

    Cannot establish a secure connection.

    Will stick to the workaround with firefox.

    Now I will try to import certificate to my iOS (later next week). I hope that I can use the builtin browser?

    Cheers,

    Frank

Children
No Data