cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2459
Views
0
Helpful
5
Replies

WSA HTTPS Proxy Certificate update problem

Hello, everyone. I am in my first month at new job and trying to fix some problems. One of them is that we have 2 WSAs those working in Forward mode. Browsers get WPAD.dat file from Citrix load balancer so that part of workers access internet through first WSA and another part from the second. The problem is that the previous worker uploaded https proxy certificate to secon WSA not correctly. The common name is wrong and this cause some users to get error when accessing the internet. I Security Services -> HTTPS Proxy -> Edit Settings -> and  generated new CSR with correct name. Then I signed it with our internal CA server and uploaded into WSA. The ironport accepted it. I submitted and committed changes. The problem is the users still get the old certificate and error. How I can apply my changes?

 

Thanks in advance.

 

 

1 Accepted Solution

Accepted Solutions

Hello and thank you for your reply. Actually, I have already solved the problem. The problem was because we are doing AD authentication the certificate on authentication box also required to be changed.

 

Thanks you again

View solution in original post

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

If the Pre-build Windows then your certificate might have already packaged  with packages.

 

To test, download the correct certificate and load to PC and test it. 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Handy Putra
Cisco Employee
Cisco Employee

Make sure that you clear the browser history/cache, in case the browser still remembering the old connection.

 

Regards

Handy Putra

sadik.sener1
Level 1
Level 1

Hi Orkhan, I suspect the thing is, your clients do not trust SubCA.

 

Please check if this certificate is installed on their trusted intermediate certification authorities folder.

You can do that by : typing mmc in run or cmd, when the dialog box opens up, file-> add or remove snap in-> certificates -> computer account -> ok ->  (do the same for user account also ) and check for both of the stores if the problemmatic pc trusts the subordinate CA

Regards

Hello and thank you for your reply. Actually, I have already solved the problem. The problem was because we are doing AD authentication the certificate on authentication box also required to be changed.

 

Thanks you again

I have the same question with you. After reading your answer, I don't quite understand how to operate it. Could you tell me the specific way to do it,thank you!