Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

* Certs and Web Appliance

Does the web appliance work with * certs?  It seems that every time I see an organization with a cert issued to *.company.com, the web appliance does not allow access to the page until I add that site to the bypass list for SSL.  It says that the site certificate is not valid although I cannot find any problems with it.  Am I doing something wrong?

Here's an example site:

https://www.ctspurchasing.com/

Jason

:3428


This thread was automatically locked due to age.
Parents
  • www.ctspurchasing.com uses a certficate signed by Network Solutions Certificate Authority.  When Certificate Validation is turned on, we validate the issuer of the certificates used by the secured sites.  Unfortunately, Network Solutions Certificate Authority is not in our system yet.  Therefore, the certificate used by www.ctspurchasing.com fails the Certificate Validation.

    We expect customers may run into this situation, so we provide two ways to workaround it.  The first method is what you said.  You can add the certificate used by the secured site.

    The second method is to upload the certificate(s) required to validate the certificate used by the secured site.  For www.ctspurchasing.com, here are the steps:

    1) Start Google Chrome on a linux computer
    2) Set Google Chrome to connect directly to the Internet
    3) Browse to https://www.ctspurchasing.com
    4) Once loaded, click on the yellow lock icon at the end of the address bar
    5) In the Security Information window, click Certificate Information
    6) In the Certificate Viewer window, select the Details tab
    7) In the Certificate Hierachy area, select Network Solutions Certificate Authority and click Export
    8) In the Save File window, select Base64-encoded ASCII, single certificate, enter a file name and save the file.
    9) Go to our Administration Web Interface > Configuration > Global Policy > Certificate Validation page.
    10) Under the Add root authority certificate area, click Browse, select the file exported in step 8, and click Add.

    Now, https://www.ctspurchasing.com will not fail the Certificate Validation check.

    I have created item to include Network Solutions Certificate Authority in our system.  The reference number is SUG60980.  When this issue is addressed, it will be documented in Help > Release Notes.

    :3442
Reply
  • www.ctspurchasing.com uses a certficate signed by Network Solutions Certificate Authority.  When Certificate Validation is turned on, we validate the issuer of the certificates used by the secured sites.  Unfortunately, Network Solutions Certificate Authority is not in our system yet.  Therefore, the certificate used by www.ctspurchasing.com fails the Certificate Validation.

    We expect customers may run into this situation, so we provide two ways to workaround it.  The first method is what you said.  You can add the certificate used by the secured site.

    The second method is to upload the certificate(s) required to validate the certificate used by the secured site.  For www.ctspurchasing.com, here are the steps:

    1) Start Google Chrome on a linux computer
    2) Set Google Chrome to connect directly to the Internet
    3) Browse to https://www.ctspurchasing.com
    4) Once loaded, click on the yellow lock icon at the end of the address bar
    5) In the Security Information window, click Certificate Information
    6) In the Certificate Viewer window, select the Details tab
    7) In the Certificate Hierachy area, select Network Solutions Certificate Authority and click Export
    8) In the Save File window, select Base64-encoded ASCII, single certificate, enter a file name and save the file.
    9) Go to our Administration Web Interface > Configuration > Global Policy > Certificate Validation page.
    10) Under the Add root authority certificate area, click Browse, select the file exported in step 8, and click Add.

    Now, https://www.ctspurchasing.com will not fail the Certificate Validation check.

    I have created item to include Network Solutions Certificate Authority in our system.  The reference number is SUG60980.  When this issue is addressed, it will be documented in Help > Release Notes.

    :3442
Children
No Data