Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

HTTPS Decrypt and Scan Encountering Warning Pages

Hey Sophos,

We've recently been testing Packet Inspection / HTTPS Decryption and was mostly a success, but some sites were presenting the below, even when we had the appliance cert installed. Can someone shed some light as to what was causing this? Note that it wasn't all sites, just a handful:

Many Thanks



This thread was automatically locked due to age.
Parents
  • The message means: The Firewall can#t check the Server-identity.
    This is not a problem from SSL-decryption certificate at the client.
    Check the webserver, there must be an issue with the SSL-Server certificate.
    I use https://testtls.com or www.ssllabs.com/.../ for this.

    You may post the server-url here.

  • Hi Dirk,

    We pushed the appliance certificate (SecurityAppliance_SSL_CA) located under Certificates > Certificate Authorities. This same certificate is set under Web > General Settings > HTTPS scanning certificate authority (CA) to be used as the designated CA.

    Devices with the certificate above worked mostly, and those without the certificate got blocks on every page. Those with the certificate only got blocks on certain pages, or using certain services.

    As soon as we turned Packet Inspection off, the site was accessible as before Packet Inspection was enabled. There aren't any other firewall rules in use that would supersede this one with Decrypt HTTPS during web proxy filtering checked, so I'm at a loss as to what would cause this.

Reply
  • Hi Dirk,

    We pushed the appliance certificate (SecurityAppliance_SSL_CA) located under Certificates > Certificate Authorities. This same certificate is set under Web > General Settings > HTTPS scanning certificate authority (CA) to be used as the designated CA.

    Devices with the certificate above worked mostly, and those without the certificate got blocks on every page. Those with the certificate only got blocks on certain pages, or using certain services.

    As soon as we turned Packet Inspection off, the site was accessible as before Packet Inspection was enabled. There aren't any other firewall rules in use that would supersede this one with Decrypt HTTPS during web proxy filtering checked, so I'm at a loss as to what would cause this.

Children