<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WSA &amp; Certificate Query in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-certificate-query/m-p/2602250#M5226</link>
    <description>&lt;P&gt;I will be setting up four WSA for a guest environment and a enterprise environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the guest environment what certificate do I upload to the WSA? A enterprise root certificate or wildcard certificate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any direction you can provide would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jan 2015 14:37:46 GMT</pubDate>
    <dc:creator>peng</dc:creator>
    <dc:date>2015-01-05T14:37:46Z</dc:date>
    <item>
      <title>WSA &amp; Certificate Query</title>
      <link>https://community.cisco.com/t5/web-security/wsa-certificate-query/m-p/2602250#M5226</link>
      <description>&lt;P&gt;I will be setting up four WSA for a guest environment and a enterprise environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the guest environment what certificate do I upload to the WSA? A enterprise root certificate or wildcard certificate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any direction you can provide would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 14:37:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-certificate-query/m-p/2602250#M5226</guid>
      <dc:creator>peng</dc:creator>
      <dc:date>2015-01-05T14:37:46Z</dc:date>
    </item>
    <item>
      <title>What will you be using</title>
      <link>https://community.cisco.com/t5/web-security/wsa-certificate-query/m-p/2602251#M5227</link>
      <description>&lt;P&gt;What will you be using certificate for? For https inspection?&lt;/P&gt;&lt;P&gt;If you'd like to inspect SSL traffic for guest users you'll need to manually deploy CA certificate to client computers (under Truster Root CAs) so I wouldn't recommend you to do https inspection for guests at all. If you won't deploy CA certificate to client computer they'll get invalid certificate warning when establishing secured session.&lt;/P&gt;&lt;P&gt;HTTPS inspection is usually done to inspect corporate traffic where you're able to deploy certificate through GPO for example.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 14:47:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-certificate-query/m-p/2602251#M5227</guid>
      <dc:creator>Jernej Vodopivec</dc:creator>
      <dc:date>2015-01-05T14:47:21Z</dc:date>
    </item>
    <item>
      <title>Jernej, Yes this is for https</title>
      <link>https://community.cisco.com/t5/web-security/wsa-certificate-query/m-p/2602252#M5228</link>
      <description>&lt;P&gt;Jernej,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes this is for https inspection for guest and will then eventually be used in the corporate environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In regards to the client receiving an invalid certificate if &amp;nbsp;I don't deploy a CA certificate, would the same happen for a wildcard certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aim is to have the&amp;nbsp;guest clients&amp;nbsp;to go through the https inspection process, what is the best way of doing this or certificates I can use?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 14:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-certificate-query/m-p/2602252#M5228</guid>
      <dc:creator>peng</dc:creator>
      <dc:date>2015-01-05T14:59:53Z</dc:date>
    </item>
    <item>
      <title>The wildcard certificate</title>
      <link>https://community.cisco.com/t5/web-security/wsa-certificate-query/m-p/2602253#M5229</link>
      <description>&lt;P&gt;The wildcard certificate wouldn't solve the problem. You have to deploy WSA's certificate to clients in some way.&lt;/P&gt;&lt;P&gt;Do it manually - you can put instructions that guest users needs to deploy certificate to their computers (and put link to the certificate along with these instructions) on hotspot portal for wireless users?&lt;/P&gt;&lt;P&gt;Or automatically - through GPO for enterprise clients.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 15:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-certificate-query/m-p/2602253#M5229</guid>
      <dc:creator>Jernej Vodopivec</dc:creator>
      <dc:date>2015-01-05T15:14:44Z</dc:date>
    </item>
  </channel>
</rss>

