This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Installation of appliance certificate on ipad air (2019) running ipadOS 13.3

I have been trying to get https scanning implemented on my home network.   So far, by using Sophos Network Agent, I have been able to get it functioning on my win10 devices (laptops) and my android devices but am struggling to get it working on my ipad, though have (sort of) been able to get it working on my iphone 6.   Specifically, on my ipad I can’t seem to find a way to install the appliance scanning certificate into Sophos Network Agent (SNA).  

I tried downloading the certificate that http://passthrough.fw-netcacert.pem as mentioned in the final post here https://community.sophos.com/products/unified-threat-management/f/web-protection-web-filtering-application-visibility-control/46800/deploy-https-certificate-to-ios but got notwhere.  

After some digging around I found this post https://community.sophos.com/products/xg-firewall/f/web-protection/108583/import-securityappliance_ssl_ca-into-ios-devices and worked out that I need to use Safari to download the scanning certificate from the user portal to my device, as described here https://community.sophos.com/kb/en-us/123755

So far so good, but having gotten the certificate on my ipad I find I am then unable to open the certificate in SNA.   If I perform a long click on the certificate via there is no option to open it in SNA.   This post https://community.sophos.com/products/xg-firewall/f/web-protection/108583/import-securityappliance_ssl_ca-into-ios-devices talks about downloading the certificate directly from my device, and renaming it to perform the install, but in my install of 17.5 MR9 I have no option to download directly from the device :

Scratch that idea then.

Returning to the knowledge base / community forums I found these posts re appliance certificates in IOS 13

https://community.sophos.com/products/xg-firewall/f/intrusion-prevention/115171/ssl_scanning_certificate-not-accepted-under-ios-13?pi2151=1#pi2151=2

https://community.sophos.com/products/unified-threat-management/f/web-protection-web-filtering-application-visibility-control/115345/issue-with-ios-13-mac-os-10-15-ssl-certificate-requirements-for-transparent-proxy?pi2353=2

If I follow the IOS app link on the KB123755 page from my laptop, I get to the app store preview page which has the following comment on a 1 star review (curiously doing the same from my ipad  / iphone there are no reviews at all so I can’t see if there are any more upto date comments):

so it seems apple (as is their want) made some changes which stopped the installation of certificates; though apparently this was fixed for IOS13 in 17.5 MR9.

 

I think i have gone as far as I can in trying to work out how to install my appliance certificate on my ipad.   My sense of what I have found online and read is that apple made some changes, broke things and whilst a fix has been issued in 17.5 MR9 for IOS 13.x that either doesn’t apply to ipadOS 13.x or didn’t fix it.

Is there currently any way to install the appliance certificate into SNA for my ipad?   Is this a known issue and is there a fix coming ?   What about V18 ?   has this been resolved in EAP3  /will it be resolved before going to GA ?

Seems my current options are to either have my device bypassed from https scanning (and / or maybe find a device level filter I can apply) or to effectively block my ipad from the internet at home.   Neither of which are ideal.

 

Can anyone help ?

Matt

 

Devices: 

Sophos XG 17.5 MR9, Home license, 4GB RAM

2 x win10 laptops (V 1909)

1 x Samsung S3 tablet (Android 8.1)

1x Samsung Note 9 (Android 9)

1 x Apple ipad air (2019), ipadOS13.3

1x iphone 6  (IOS 12.4.4)

1x iphone X (IOS 13.x)

 



This thread was automatically locked due to age.
Parents
  • Hi  

    Due to Apple’s new certificate requirement (https://support.apple.com/en-in/HT210176 ) there are 2 different features where XG need to adopt or enhance changes.

    One is with Appliance web proxy certificate to avoid the cert error after enable "Decry-pt & Scan" on firewall rule to block the HTTPS sites and after importing SSL CA on end device.

    This changes fix taken with latest version MR-9 with reference to "NC-50172 [Web] Conform to Apple's new certificate requirements (awarrenhttp)".

    Release note:  https://community.sophos.com/products/xg-firewall/b/blog/posts/sfos-17-5-mr9-released

    Another changes is with Client authentication agent. IOS 13 doesn't have option to open/ import .scc certificate with Sophos Network Agent APP.

    To take above changes into consideration with CAA ( Client Authentication Agent) certificate - Dev team is working with NC-51432.

    As in work around as of now you may create a clientless user for your IOS 13 device.

    KBA for how to add clientless user:

    https://community.sophos.com/kb/en-us/123039

  • Hi,

    I have the certificate installed on my iPhone and iPad by downloading to my MBP and then emailing it to myself and double clicking on the attachment. Also as suggested I have clientless users.

    The only issue I have is that XG does not recognise the certificate for imaps scanning, so imaps scanning is disabled which is a pain.

    Ian

  • Hi Ian,

     

    I am not clear what you mean by MBP, but you did give me the idea to try downloading the certificate on my win10 machine from my user portal, email it to myself and try installing it that way.   Unfortunately that didn't work either - from within outlook on my ipad i can attempt to open the certificate (inc with double click) but again there is no option to install - it just opens a blank window - which i assume is because of NC-51432 as described by Vishal.

     

    I'll have a look at clientless users when i get a moment - from the KB 123039 it says that there's no network traffic policy - I presume this includes content filtering etc.

     

    I've been keeping an eye on developments within V18 EAP but i'm not sure i'm quite ready to make that jump just yet.   Perhaps when EAP4 is released.

     

    For now though i may look at other options

     

    Matt

Reply
  • Hi Ian,

     

    I am not clear what you mean by MBP, but you did give me the idea to try downloading the certificate on my win10 machine from my user portal, email it to myself and try installing it that way.   Unfortunately that didn't work either - from within outlook on my ipad i can attempt to open the certificate (inc with double click) but again there is no option to install - it just opens a blank window - which i assume is because of NC-51432 as described by Vishal.

     

    I'll have a look at clientless users when i get a moment - from the KB 123039 it says that there's no network traffic policy - I presume this includes content filtering etc.

     

    I've been keeping an eye on developments within V18 EAP but i'm not sure i'm quite ready to make that jump just yet.   Perhaps when EAP4 is released.

     

    For now though i may look at other options

     

    Matt

Children
  • Hi Matt,

    a MBP is a Mac Book Pro. In the iPhone mail I doublecjick on the attached .pem file and it advise to install it from the Control panel - general - profiles.

    Interestingly, I have installed the same certificate on the iPhone and the iPad, the iPhone partially works. Something wrong with the configuration which I have to investigate.

    Ian