Last modified by lmotowski@remc1_org on 2026/08/19 16:33

From version 1.1
edited by Josh Hiner
on 2019/03/06 12:11
Change comment: There is no comment for this version
To version 2.1
edited by Josh Hiner
on 2019/03/06 12:13
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -19,3 +19,30 @@
19 19  1. (Optional) If the certificate will be used as a root CA for an SSL-inspecting web filter or to allow the browser to validate the full digital certificate chain of servers, check the **Use this certificate as an HTTPS certificate authority** box.
20 20  1. Click **Save** and then **Done** to confirm.
21 21  1. You will need a way for chrome devices to get the cert/sync the new policy. Dont enable deep scanning until the cert is pushed (or disable deep scanning until the policy is pushed).
22 +
23 +\\
24 +
25 += {{id name="Verify-the-certificate-is-pushed"/}}Verify the certificate is pushed =
26 +
27 +(% style="text-align: left;" %)
28 +== {{id name="Before-you-begin"/}}Before you begin ==
29 +
30 +(% class="spaced-list" style="text-align: left;" %)
31 +* Users need to sign in with an account in the domain that the device is enrolled in. For example, if the device is enrolled in the [[school.edu>>url:http://school.edu||shape="rect"]] domain, the user needs to sign in with an account that uses the domain, such as [[user@school.edu>>mailto:user@school.edu||shape="rect"]].
32 +* If you have secondary G Suite domain that is managed under a primary domain and the user account is in the secondary domain, you need to enroll the device in the secondary domain. The device’s enrollment domain and signed-in user’s domain must match for the pushed certificate to work.
33 +
34 +(% style="text-align: left;" %)
35 +== {{id name="Verify-SSL-inspection-is-working"/}}Verify SSL inspection is working ==
36 +
37 +==== {{id name="If-Deep-scanning-is-enabled"/}}If Deep scanning is enabled ====
38 +
39 +(% style="text-align: left;" %)
40 +1. Sign in to a Chrome device with a user account in the domain where the certificate was applied.
41 +1. Go to a site where SSL inspection is applied by your web filter.
42 +1. Verify the building icon is in the address bar. Click it to see details about permissions and the connection.
43 +
44 +==== {{id name="To-simply-look-at-the-cert-in-settings"/}}To simply look at the cert in settings ====
45 +
46 +1. In the addressbar type chrome:~/~/settings/certificates
47 +1. Click on the Authorities tab
48 +1. You should see the certificate in the list with a building icon next to it (which means the cert is pushed via google console
Confluence.Code.ConfluencePageClass[0]
id
... ... @@ -1,1 +1,1 @@
1 -17187151
1 +711950436