Views:

Deploy the Internet Access built-in CA certificate for the Internet Access Cloud or On-Premises Gateway to use on supported browsers to avoid certificate warnings when users visit HTTPS websites.

Procedure

  1. Go to Zero Trust Secure AccessSecure Access ConfigurationInternet Access Configuration and click the HTTPS Inspection tab.
  2. Click the settings icon (gear-icon.png).
    The Manage Default Certificate panel opens.
  3. Click Download built-in certificate (provided by the Internet Access Service) for the type of gateway you are using.
    Default certificate name for each gateway type: cloud_gateway.cer, on-premises_gateway.cer
  4. Deploy the desired CA certificate to the supported browsers on your users' devices.
    Note
    Note
    The following browser setting instructions were valid as of November 2022.
    Browser
    Version
    Setting
    Google Chrome™
    Microsoft Edge™ (Chromium-based)
    Newest and most recent previous version
    Note
    Note
    This task uses Windows 10 as an example.
    1. Open the certificate file.
    2. Click Install Certificate.
      The Certificate Import Wizard opens.
    3. Click Next.
    4. Select Place all certificates in the following store and click Browse.
    5. Select Trusted Root Certification Authorities and click OK.
    6. Click Next, and then click Finish.
    Apple™ Safari™
    Newest and most recent previous version
    1. Locate the certificate file in Finder, and double-click it.
      The Keychain Access window appears.
    2. Locate and open the certificate.
      The Certificate window opens.
    3. Expand Trust, and then set When using this certificate to Always Trust.
    4. Close the window.
      A screen shows and prompts for a password.
    5. Type your password and click Update Settings.
    Mozilla® Firefox®
    Newest and most recent previous version
    1. Click the Open menu icon in the top-right corner of the browser, and then select Settings.
    2. Click the Privacy & Security tab.
    3. Under Certificates, click View Certificates and then select Authorities.
      Note
      Note
      You cannot import the certificate to both the server and authorities. If the certificate is already imported to the server, delete it.
    4. Click Import.
    5. Navigate to the download folder and select the certificate file.
    6. Select Trust this CA to identify websites and then click OK.