This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Decrypt and Scan HTTPS invalidates HTTPS certificates

Hello , I have been facing this problem for almost two weeks, and Sophos engineer are unable to solve 

hopefully I will get solution from this forum ,

Actually I sold a XG to a client with 3 years licences , I request that we block youtube in in his network so that all devices(laptop, phone, mac device)

will not access it . I do all position policies suggested by Sophos it never work . once it works it will block all the https urls pages . and my client does does not agree on the option of installing CA on each device, although he has an AD.so up to now have no solution and we are risking to loose the order . how can you help 

 

Thanks



This thread was automatically locked due to age.
  • If you want to filter HTTPS there is no other way than decrypt that traffic.
    Otherwise we can forget the "S" and go back to 1994.

    Your client has two options: no HTTPS filter or a certificate rollout.

    A workaround for the youtube problem is to configure a DNS alias for the youtube domain that all traffic is sent into a blackhole.

    MFG
    Dome