Use Sophos Mobile to enable mobile devices to trust CA for HTTPS decryption
Mobile devices show a warning message or block traffic if the Certificate Authority (CA) for the certificate used in HTTPS traffic decryption by Sophos Firewall is not known to them.
Introduction
You must import the CA into mobile devices to make sure they trust Sophos Firewall during HTTPS decryption. This applies to decryption using the web proxy and the DPI engine.
Sophos Firewall is shipped with a CA certificate used in HTTPS inspection. You can install the CA in groups of mobile devices using a Mobile Device Management (MDM) solution, such as Sophos Mobile.
Apple recommends using an MDM solution or Apple Configurator to install the CA. If you do this, the CA is automatically trusted.
If you use Apple Configurator, you must create a configuration profile on a Mac. You can then connect one or more iOS devices and install the CA on them.
In this example, we show how to install the CA in iOS mobile devices enrolled with Sophos Mobile, our MDM solution. Using Sophos Mobile, you can install certificates and CAs on groups of Android and iOS mobile devices.
The configuration steps are as follows:
- Download the CA.
- Specify the CA for SSL/TLS inspection and decryption when using the DPI engine.
- Specify the CA for HTTPS decryption and scanning when using Sophos Firewall as a web proxy.
- Go to Sophos Mobile, and add the CA to your device policy. For details, see root certificate configuration for Android or iOS device policies in Sophos Mobile administrator help.
- Confirm that the root CA is added to a registered mobile device.
Apply root CA for HTTPS decryption and download CA
Use the CA shipped with Sophos Firewall for HTTPS decryption.
You must select the CA for SSL/TLS inspection, which uses the DPI engine. You must select the CA for HTTPS decryption, which uses web proxy filtering. You must download the CA.
-
Go to Certificates > Certificate authorities and click Download
next to
SecurityAppliance_SSL_CA
.Alternatively, you can specify the settings of the Default CA, which is the locally-signed CA shipped with Sophos Firewall, and download it. You can also import an external CA.
Here's an example:
-
If you want users to add the CA manually, email the CA certificate to them.
Alternatively, upload the CA to a server from which users can download the certificate to their mobile devices.
-
To configure the CA for SSL/TLS inspection, which uses the DPI engine, do as follows:
- Go to Rules and policies > SSL/TLS inspection rules and select SSL/TLS inspection settings.
-
Under Re-signing certificate authorities, select
SecurityAppliance_SSL_CA (RSA)
for Re-sign RSA with.Here's an example:
-
Click Apply.
- To configure the CA for HTTPS decryption, which uses web proxy, go to Web > General settings. Under HTTPS decryption and scanning, select
SecurityAppliance_SSL_CA
for HTTPS scanning certificate authority (CA).
Here's an example:
Install the root CA in mobile devices using Sophos Mobile
In Sophos Mobile, add the root CA to the policy that you've assigned to your mobile devices.
In this example, we add the root CA to an iOS and iPadOS device policy. Similarly, you can add the root certificate to an Android policy.
-
In Sophos Mobile, go to Policies > iOS & iPadOS.
-
Click the policy that you've assigned to the devices on which you want to install the root CA.
-
On the Edit policy page, click Add > Root certificate.
-
On the Root certificate page, click Upload a file and select the certificate file.
-
Click Apply to save the configuration.
-
Click Save to save the policy.
-
In the policy list, click the Down arrow next to the policy and click Update devices.
If the policy has no Update devices option, devices update automatically the next time they sync with Sophos Mobile.