Changes for page Push Certificate Authority Via Google Chrome Management
Last modified by lmotowski@remc1_org on 2026/08/19 16:33
From version 1.1
edited by Josh Hiner
on 2019/03/06 12:11
on 2019/03/06 12:11
Change comment:
There is no comment for this version
To version 2.1
edited by Josh Hiner
on 2019/03/06 12:13
on 2019/03/06 12:13
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
-
Objects (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -19,3 +19,30 @@ 19 19 1. (Optional) If the certificate will be used as a root CA for an SSL-inspecting web filter or to allow the browser to validate the full digital certificate chain of servers, check the **Use this certificate as an HTTPS certificate authority** box. 20 20 1. Click **Save** and then **Done** to confirm. 21 21 1. You will need a way for chrome devices to get the cert/sync the new policy. Dont enable deep scanning until the cert is pushed (or disable deep scanning until the policy is pushed). 22 + 23 +\\ 24 + 25 += {{id name="Verify-the-certificate-is-pushed"/}}Verify the certificate is pushed = 26 + 27 +(% style="text-align: left;" %) 28 +== {{id name="Before-you-begin"/}}Before you begin == 29 + 30 +(% class="spaced-list" style="text-align: left;" %) 31 +* Users need to sign in with an account in the domain that the device is enrolled in. For example, if the device is enrolled in the [[school.edu>>url:http://school.edu||shape="rect"]] domain, the user needs to sign in with an account that uses the domain, such as [[user@school.edu>>mailto:user@school.edu||shape="rect"]]. 32 +* If you have secondary G Suite domain that is managed under a primary domain and the user account is in the secondary domain, you need to enroll the device in the secondary domain. The device’s enrollment domain and signed-in user’s domain must match for the pushed certificate to work. 33 + 34 +(% style="text-align: left;" %) 35 +== {{id name="Verify-SSL-inspection-is-working"/}}Verify SSL inspection is working == 36 + 37 +==== {{id name="If-Deep-scanning-is-enabled"/}}If Deep scanning is enabled ==== 38 + 39 +(% style="text-align: left;" %) 40 +1. Sign in to a Chrome device with a user account in the domain where the certificate was applied. 41 +1. Go to a site where SSL inspection is applied by your web filter. 42 +1. Verify the building icon is in the address bar. Click it to see details about permissions and the connection. 43 + 44 +==== {{id name="To-simply-look-at-the-cert-in-settings"/}}To simply look at the cert in settings ==== 45 + 46 +1. In the addressbar type chrome:~/~/settings/certificates 47 +1. Click on the Authorities tab 48 +1. You should see the certificate in the list with a building icon next to it (which means the cert is pushed via google console
- Confluence.Code.ConfluencePageClass[0]
-
- id
-
... ... @@ -1,1 +1,1 @@ 1 - 171871511 +711950436