This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

HTTPS traffic

     Can u help me with disabeling CA error



This thread was automatically locked due to age.
Parents
  • Did you distribute the UTM CA certificate to your client devices?

    It is needed for any https decrypt and scan, and it is also needed for block and warn pages on https sites, event without decrypt and scan

  • Hi,

    I want to disable https filter so I don't get that error message and so I won't have to destribute CA to users

    How to do so ?

  • This is like saying that you do not like keys, so you are going to leave your house unlocked all of the time.   Web Filtering is the most valuable part of UTM.   I recommend using both Standard Mode and Transparent Mode.   It has a learning curve, but it is worth the effort.

    Read the articles in the Wiki for some important background information.

    Distributing the certificate is pretty easy if you have Windows devices and Active Directory, it uses Group Policy.   You should be able to hire a consultant to help if thie process seems intimidating.

    However, it is easy enough to turn off web filtering:  Web Filtering... Global... Slide button to the off position.

    If you were asking how to turn decrypt-and-scan off, it is part of the Filter Profile definition, middle tab.   But as I said before, you need to distribute the certificate even if decrypt and scan is not used.

  • thank u,

    just do u know the auto proxy with dhcp in sophos 

    or auto proxy with dhcp in switches

Reply Children
  • Narimane, are you saying that you don't have a Windows server or other and that you would like to use Sophos DHCP?  How does this relate to the first question in your post above?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • hello, it's okay now I'm looking to deploy my certificates in browsers

    I've found how to do it with active directory , but it works on windows systems

    how to deploy my certificate on unix, linux and mac systems 

  • One of the unwritten rules here is "one topic per thread" - that's to make it easier for future members to find an answer to a question that's already been answered without starting a new thread.   Please start a new, appropriately titled, thread with your new question which is unrelated to your original one.

    Merci d'avance.

    Cheers - Bob
    PS moving this thread to the Web Protection forum.

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA