03-03-2018 12:17 AM - edited 02-21-2020 07:28 AM
Dears,
I m little confused from the below guides of ssl decryption , I don't have any Internal CA in my corporate nor I m going to get it signed by third party CA ( verisign,godaddy) so according to the below link I have to follow only step 1 (OPTION 1) and then straight jump to SSL policy configuration (Navigate to Policies > SSL then click New Policy.)
Thanks
03-03-2018 02:41 AM
Yes, that's right. But you still have to import the self-signed certificate from Option1 to all your client-devices as trusted root-certificate.
03-03-2018 03:55 AM - edited 03-03-2018 03:57 AM
Dear Karsten,
if I am not wrong I have to export from the box instead of the import, where I can find the option to download the self signed certificate from the box ??? so that once download ,, by windows group policy I can push to all PC in the domain.
thanks
03-06-2018 06:55 AM
Hi
You can download the certificate from objects>PKI >CA
If you have created the CA on FMC itself.
Hope it helps,
Yogesh
03-06-2018 12:43 PM
these certificates has to be install in client machine in which location ???
03-07-2018 04:56 AM
After exporting the certificate (and converting from p12 to pem) you have to install it into the trusted root store on all client machines. If the clients are using Firefox, there is a separate store where it has to be installed.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide