Hi,
I searched the forum but I didn't find a satisfying solution what I want to accomplish.
I want that all HTTPS traffic to be scanned for malware & malicious sites without to store the the signing certificate be put in the Trusted CA Store of the clients.
The clients are PC's and mobile devices.
The Web Proxy is running in Transparent Mode and I uploaded my (wildcard) SSL Certificate at "Signing CA" in Filter Options.
When a device (PC/mobile device) is going to https://google.com, I get the warning that the certificate is not trusted. When I look at the certificate, I see at that the issuer is my domain's wildcard. Why is it not trusted? This certificate is from an official CA.
Is it even possible to do HTTPS scanning for all devices without storing the CA locally?
For PC's it's not so difficult but for mobile devices and BYOD's it's hard...
This thread was automatically locked due to age.