You can configure SSL interception CA certificates by using the Network Security appliance Web UI or CLI:
The SSL Interception feature requires that you import a unique trusted CA certificate and matching private key on the Network Security appliance. This feature also requires that you import a unique untrusted CA certificate and matching private key on the appliance. The CA certificate and private key are used to sign the fake server certificates to intercept HTTPS connections. You also need to export the public key for the trusted certificate.
For details about how to manage HTTPS certificates for SSL interception, see “Managing HTTPS and MTA Certificates” in the “Certificates” chapter of the Trellix System Security Guide.
Important
If HTTP Public Key Pinning (HPKP) is enabled and the header is added on your browser, the header retains the specified public key hashes and associates them with that domain for a specified time period. The browser accepts a certificate only for that domain if any key in the certificate's trust chain matches one of the associated hashes. You cannot access these domains when SSL interception is enabled.
You cannot access any HTTPS-enabled website if your browser has stored HSTS (HTTP Strict Transport Security) settings. The browser uses its own system certificate store instead of the system certificates, and it generates an Invalid Certificate Error Code (“sec_error_unknown_issuer”). Instead of completing the connection, the browser displays a “Secure Connection Failed” page.
Usage Guidelines
Follow these usage guidelines when configuring SSL interception CA certificates:
The certificate and private key must be configured as a Privacy Enhanced Email (PEM) encrypted ASCII string.
The PEM string must be formatted in the following order:
Double quotation marks
A new line
BEGIN delimiter string
ASCII block
END delimiter string
A new line
Double quotation marks
(Optional) A comment
If a comment is added, it must follow the final double quotation marks and be on the same line. Any commentary outside the BEGIN and END delimiter strings is ignored.
Note
You can press Enter in the CLI to add a new line.
You cannot add a new SSL interception CA certificate if one already exists. You must delete or rename the existing certificate first.
Prerequisites
Administrator or Operator access to the Network Security appliance
Verify that you have configured the appliance for inline deployment with a network port pair by using the
show policymgr interfacescommand. For details about how to configure inline operational modes, see Configuring inline operational modes.