<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem about certificate on Cisco WSA in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/problem-about-certificate-on-cisco-wsa/m-p/3386804#M7809</link>
    <description>&lt;DIV id="noteView" class="NoteView lia-note-view-display lia-note-source-outbox lia-note-unread lia-unread lia-component-notes-widget-note-view lia-component-note"&gt;
&lt;DIV class="lia-quilt lia-quilt-private-notes-item lia-quilt-layout-single-row-full"&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV class="lia-note-content"&gt;
&lt;DIV class="lia-note-subject lia-component-subject"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-note-body lia-component-body"&gt;
&lt;P&gt;Problem about certificate on Cisco WSA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I implement transparency proxy and enable https proxy&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When I browse to the device in Internet Explorer (https://%FQDN%), I get a 'Problem with this website's security certificate' error because the appliance is using the Demo Appliance cert for the web interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;use to test by sign certificate by local CA Server and install on WSA (Trust cert with cert domain) , It’s work&lt;/P&gt;
&lt;P&gt;But Guest devices which not join domain not work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;will use public cert solution for fix issue? or you have solution to fix this Issue?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PS.How solution solve this problem by not install cert at client, Because i can't install certificate to all client and guest.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Sat, 09 Mar 2019 03:44:59 GMT</pubDate>
    <dc:creator>NUTNICHA PIYANIJDUMRONG</dc:creator>
    <dc:date>2019-03-09T03:44:59Z</dc:date>
    <item>
      <title>Problem about certificate on Cisco WSA</title>
      <link>https://community.cisco.com/t5/web-security/problem-about-certificate-on-cisco-wsa/m-p/3386804#M7809</link>
      <description>&lt;DIV id="noteView" class="NoteView lia-note-view-display lia-note-source-outbox lia-note-unread lia-unread lia-component-notes-widget-note-view lia-component-note"&gt;
&lt;DIV class="lia-quilt lia-quilt-private-notes-item lia-quilt-layout-single-row-full"&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV class="lia-note-content"&gt;
&lt;DIV class="lia-note-subject lia-component-subject"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-note-body lia-component-body"&gt;
&lt;P&gt;Problem about certificate on Cisco WSA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I implement transparency proxy and enable https proxy&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When I browse to the device in Internet Explorer (https://%FQDN%), I get a 'Problem with this website's security certificate' error because the appliance is using the Demo Appliance cert for the web interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;use to test by sign certificate by local CA Server and install on WSA (Trust cert with cert domain) , It’s work&lt;/P&gt;
&lt;P&gt;But Guest devices which not join domain not work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;will use public cert solution for fix issue? or you have solution to fix this Issue?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PS.How solution solve this problem by not install cert at client, Because i can't install certificate to all client and guest.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sat, 09 Mar 2019 03:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/problem-about-certificate-on-cisco-wsa/m-p/3386804#M7809</guid>
      <dc:creator>NUTNICHA PIYANIJDUMRONG</dc:creator>
      <dc:date>2019-03-09T03:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Problem about certificate on Cisco WSA</title>
      <link>https://community.cisco.com/t5/web-security/problem-about-certificate-on-cisco-wsa/m-p/3387855#M7810</link>
      <description>When you say "Browse to device" do you mean when you browse to the WSA's management interface?&lt;BR /&gt;&lt;BR /&gt;That cert could be a cert from a public vendor.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;If you mean you're going to other servers on the internet, you don't have a choice, you MUST install the root or the signing cert itself on the clients.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;OR&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Build a policy that doesn't decrypt for those stations that aren't domain joined.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 23 May 2018 17:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/problem-about-certificate-on-cisco-wsa/m-p/3387855#M7810</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2018-05-23T17:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Problem about certificate on Cisco WSA</title>
      <link>https://community.cisco.com/t5/web-security/problem-about-certificate-on-cisco-wsa/m-p/3388109#M7811</link>
      <description>&lt;P&gt;Thank you. I understood.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 02:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/problem-about-certificate-on-cisco-wsa/m-p/3388109#M7811</guid>
      <dc:creator>NUTNICHA PIYANIJDUMRONG</dc:creator>
      <dc:date>2018-05-24T02:43:12Z</dc:date>
    </item>
  </channel>
</rss>

