To resolve the issue, it is recommended that you import the internal CA certificate which is trusted by all clients into IWSVA.
To import a CA certificate:
- From the main menu, click HTTP > HTTPS Decryption > Settings | Certificate Authority.
- Click Browse next to Certificate to select a certificate file. IWSVA supports certificates using Base64-encoded certificate and RSA-based encrypted private key in PEM file format.
- Click Browse next to Private Key to select the private key associated with the CA certificate.
- Type the passphrase.
- Click Import CA.
If you do not have a PKI (nointernal CA certificate), you may choose to trust the default IWSVA certificate.
To trust a certificate:
- From the main menu, click HTTP > HTTPS Decryption > Settings | Certificate Authority.
- Click Export Public CA Key.
- Follow the on-screen prompt to save the certificate file on your computer.
- If all clients are in the AD domain, modify the group policy to add the saved certificate into Trusted Root Certificate Authorities.
- If there is no AD, you have to copy the certficate to clients.
- On clients, go to IE > Settings > Internet Options > Content | Certificates.
- On the Trusted Root Certification Authorities tab, click Import.
- Follow the wizard to import the certificate.