Views:

To resolve the issue, it is recommended that you import the internal CA certificate which is trusted by all clients into IWSVA.

To import a CA certificate:

  1. From the main menu, click HTTP > HTTPS Decryption > Settings | Certificate Authority.
  2. Click Browse next to Certificate to select a certificate file. IWSVA supports certificates using Base64-encoded certificate and RSA-based encrypted private key in PEM file format.
  3. Click Browse next to Private Key to select the private key associated with the CA certificate.
  4. Type the passphrase.
  5. Click Import CA.

If you do not have a PKI (nointernal CA certificate), you may choose to trust the default IWSVA certificate.

To trust a certificate:

  1. From the main menu, click HTTP > HTTPS Decryption > Settings | Certificate Authority.
  2. Click Export Public CA Key.
  3. Follow the on-screen prompt to save the certificate file on your computer.
  4. If all clients are in the AD domain, modify the group policy to add the saved certificate into Trusted Root Certificate Authorities.
  5. If there is no AD, you have to copy the certficate to clients.
  6. On clients, go to IE > Settings > Internet Options > Content | Certificates.
  7. On the Trusted Root Certification Authorities tab, click Import.
  8. Follow the wizard to import the certificate.