The Re-Signing Certificate is used by the Sensor to substitute the server's certificate when establishing a session with the client. The Sensor uses this certificate when responding to the client's request. After the client sends a request, the Sensor receives the public key and the certificate from the web server. The Sensor then validates the certificate by comparing it with the list of trusted certificates available in the trusted CA list. After the Sensor validates the server certificate, it re-signs the certificate using its own certificate before sending it back to the client. This allows the Sensor to decrypt the traffic between the client and server. You can configure your own certificate on the Re-Signing Certificate tab. It can be a customized certificate issued by the CA.
Note
Re-Signing Certificate can be managed only at the domain level. From the 11.1 Update 8 release, certificates up to 4096-bit are supported.
The re-signing CA certificate must be created for server authentication and added to the browser as a trusted authority without purpose limitations.
Note
You must re-import the Re-Signing Certificate after adding a new Sensor.
Note
For a stack of NS9500 Sensors, you must re-import the Re-Signing Certificate after a capacity upgrade from 40 Gbps or 60 Gbps to 100 Gbps.
When you enable outbound SSL decryption for the first time, the default re-signing certificate provided with the Manager is displayed. You cannot enable the outbound SSL decryption feature with a customized re-signing certificate when you enable the feature for the first time. You can import the customized certificate later.