This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

decrypt and scan https is checked, and I installed the certificate to trusted root container, but no websites are working

I followed the procedures here:  https://community.sophos.com/kb/en-us/123048

However, I cannot reach any websites anymore, such as google, yahoo, etc, after I have checked the box to "decrypt and scan https" in my firewall rule.  What am I doing wrong?

I have tried restarting the browser, rebooted the computer, removing the certificate and reinstalling, but nothing works.  What can I do to fix it?



This thread was automatically locked due to age.
  • Hi,

    on FF you need to install the CAs in FF.

    Ian

    XGS118 - v21.5.0

    XG115 converted to software licence v21.5.0

    If a post solves your question please use the 'Verify Answer' button.

    • Did you mean Firefox?  I tried that, butI still can't get to Google, Yahoo, etc.  But I can get to Amazon, on Firefox only, nothing on the other browsers.

      • Hi,

        yes, I meant firefox. IE needs the CA installed in its configuration.

        Does your web -> general page look a bit like this?

        Ian

        XGS118 - v21.5.0

        XG115 converted to software licence v21.5.0

        If a post solves your question please use the 'Verify Answer' button.

        • OK.  I did import the CA into IE as well, but it still won't allow me to go to Google, etc.  

          My web - general page does look exactly like that.  I downloaded this CA from the System - Certificates - Certificate Authorities, and its the certificate I have been importing into the browsers.

          • Can you show us a screenshot of your GPO / certificate page? 

            __________________________________________________________________________________________________________________

            • Here is my certificates pages, is this what you were looking for?

              • I meant on the Client. And which did you import where? 

                __________________________________________________________________________________________________________________

                • SecurityAppliance_SSL_CA is the one I downloaded from the XG firewall and saved, then imported that into IE, FF, and Chrome.

                   

                  IE:

                  Chrome:

                  FF:

                   

                  Windows:

                  • Perfect, and if you enable https scanning for this computer, can you show us the error? 

                    __________________________________________________________________________________________________________________

                    • Yes, here is the error that I get:

                      • Any ideas yet?  I'm still trying to figure this out.

                        What about the certificate, when I download it from the XG, it is in the form of a .pem file.  In Chrome for example, on the certificate import wizard, when browsing for the file to import, I have just been selecting the option to show all files, then I select that .pem file.  The default is that it is looking for a .cer or .crt file.  I didn't think it mattered, but do you think maybe it doesn't like the .pem file?

                         

                        • My experience with importing CAs is that if the application doesn't like the CA it will not install it eg want cert but gets pem.

                          Ian

                          XGS118 - v21.5.0

                          XG115 converted to software licence v21.5.0

                          If a post solves your question please use the 'Verify Answer' button.