The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring SSL interception CA certificates

Prev Next

You can configure SSL interception CA certificates by using the Network Security appliance Web UI or CLI:

The SSL Interception feature requires that you import a unique trusted CA certificate and matching private key on the Network Security appliance. This feature also requires that you import a unique untrusted CA certificate and matching private key on the appliance. The CA certificate and private key are used to sign the fake server certificates to intercept HTTPS connections. You also need to export the public key for the trusted certificate.

For details about how to manage HTTPS certificates for SSL interception, see “Managing HTTPS and MTA Certificates” in the “Certificates” chapter of the Trellix System Security Guide.

Important

If HTTP Public Key Pinning (HPKP) is enabled and the header is added on your browser, the header retains the specified public key hashes and associates them with that domain for a specified time period. The browser accepts a certificate only for that domain if any key in the certificate's trust chain matches one of the associated hashes. You cannot access these domains when SSL interception is enabled.

You cannot access any HTTPS-enabled website if your browser has stored HSTS (HTTP Strict Transport Security) settings. The browser uses its own system certificate store instead of the system certificates, and it generates an Invalid Certificate Error Code (“sec_error_unknown_issuer”). Instead of completing the connection, the browser displays a “Secure Connection Failed” page.

Usage Guidelines

Follow these usage guidelines when configuring SSL interception CA certificates:

  • The certificate and private key must be configured as a Privacy Enhanced Email (PEM) encrypted ASCII string.

    The PEM string must be formatted in the following order:

    1. Double quotation marks

    2. A new line

    3. BEGIN delimiter string

    4. ASCII block

    5. END delimiter string

    6. A new line

    7. Double quotation marks

    8. (Optional) A comment

      If a comment is added, it must follow the final double quotation marks and be on the same line. Any commentary outside the BEGIN and END delimiter strings is ignored.

    Note

    You can press Enter in the CLI to add a new line.

  • You cannot add a new SSL interception CA certificate if one already exists. You must delete or rename the existing certificate first.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • Verify that you have configured the appliance for inline deployment with a network port pair by using the show policymgr interfaces command. For details about how to configure inline operational modes, see Configuring inline operational modes.