cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2540
Views
0
Helpful
2
Replies

WSA HTTPS Proxy

ermionline
Level 1
Level 1

Hi Guys,

 

I have two WSA S170 and i want to enable HTTPS proxy, but i don't have root certificate. My question is how can i get a root certificate and how can i uses the certificate to enable HTTPS proxy

 

Thanks

Ermias

2 Replies 2

David Niemann
Level 3
Level 3
You can either generate a self-signed certificate and have it pushed to your workstations as a trusted CA cert via Windows GPOs or if you have a PKI generate a cert for the WSA that will be trusted by your domain.

Assuming you're a Microsoft shop, you can spin up a VM and install the Certificate Authority role as an Enterprise CA.  That will put the ROOT of the CA in your AD, and replicate it to your workstations. Then from the CA issue a subordinate CA cert and use that on your WSAs.

 

OR

 

Use the demo certs that came with one of the WSAs.  Download them, and then add the to a group policy as a "Trusted Root" cert and make sure all of your machines get it. 

 

Some resources:

Steps to configure HTTPS Proxy and CSR Option on Web Security Appliance: https://www.youtube.com/watch?v=1g_96XYnkz4&feature=youtu.be

 

Steps to enable HTTPS proxy on (WSA) & Uploading Root/Intermediate certificate option.

https://supportforums.cisco.com/video/11932521/steps-enable-https-proxy-wsa-uploading-rootintermediate-certificate-option

 

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: