cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1038
Views
0
Helpful
3
Replies

HTTPs Proxy

I have enabled HTTPS proxy in some boxes and generate a local certificate but after this some sites are not accessing, some are because of invalid certificate and some are saying "Bad request". Can i have a valid certificate so this problem can be resolved.

3 Replies 3

jowolfer
Level 1
Level 1

You need to use a Root certificate to create decryption certificates on the fly. You will not be able to obtain a certificate that is already trusted by web browsers.

The only way that your clients will trust the WSA in HTTPS decryption mode, is if you install the Root decryption certificate from the WSA onto all of your clients. Or - if you already have a trusted root certificate in your IT infrastructure, you can import that into the WSA to be used.

One common method of pushing the WSA root certificate to all clients is via Group Policy in Active Directory. This will only affect IE, not other browsers such as FireFox, Opera, or Safari.

But the problem is thhile downloading at some sites like microsoft are giving certificate error while downloading the update saying that 'certificate date and time are invaild'

jowolfer
Level 1
Level 1

Mac,

I'm not sure about Microsoft specifically, but there are many sites / applications that will verify that the certificate being presented is the 'original' certificate that the server was sending.

Decrypting the stream means that the WSA has to generate a new certificate on the fly and spoof the original values.

Intelligent software, such as iTunes, realizes that the certificate is not really from Apple and terminates the connection. In this case, there is nothing you can do except set these servers to "pass through" instead of decrypt.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: