IWSVA cannot block some URLs that failed on server certificate checking. The URLs that failed the checking will be categorized as “Generic”.
Based on IWSVA scanning flow, it will first do an HTTPS handshake and check the server certificate, then it will try to get URL category from TMUFE server.
If there is a certificate check error, IWSVA will send a certificate check failed page to the client and will not query the category information. As a result, the URL will be categorized as “Generic” and will not be blocked by pre-defined categories under the URL filtering policy.
In order to have the original category of those Generic URLs, add the root CA on active certificates under HTTP > Configuration > Digital Certificates.
For example:
https://sls.update.microsoft.com, there is a certificate warning for root CA "Microsoft Root Certificate Authority 2011" which is not trusted by Chrome and IWSVA. To block this, add the Root CA in Active Certificates.