Koldov Posted December 15, 2020 Posted December 15, 2020 We are looking at enabling the HTTPS inspection for the LGfL filtering, but I don't seem to be able to get any basic answers on how to deploy to our estate. Like most things LGfL have documentation, but it falls a little short for those of us who haven't done anything like this before. Whilst the support is usually pretty good, I do sometimes get the feeling it's very compartmentalised, which is great for the efficiency of that department - but a pain if you need answers covering multiple areas (ask me about getting Sophos licenses if you have a spare half an hour and I'm still waiting for answers on Gridstore deployment since Dec 1st)... Sometimes the answer is just a link to the help manual section covering that topic! There doesn't seem to be much information on deploying the certificate to iPads other than manually. We have hundreds of iPads and therefore would like some information on deploying the certificate via the LGfL provided Cisco Meraki MDM solution. There is a 'certificate' option in Meraki, but I'm not sure this is the right place as other older information I have found relates to a 'Credential' setting in the Meraki profile which doesn't seem to exist anymore... LGfL have told me it should be in the trusted section, which I can't even find in Meraki... Also the information on deploying to Windows devices seems a little sparse (linking to an MS page) however I have followed that and created a GPO which is fine until step 7.... I presume the certificate is not self-signed, but it says "7). If the certificate is self-signed, and cannot be traced back to a certificate that is in the Trusted Root Certification Authorities certificate store then you must also copy the certificate to that store. In the navigation pane, click Trusted Root Certification Authorities, and then repeat steps 5 and 6 to install a copy of the certificate to that store.". Do I need to do this bit?
round2it Posted December 15, 2020 Posted December 15, 2020 (edited) if it helps this is where i deploy with gpo altough we use exa its the same thing for the certificate as for ipads we deploy with mosyle and is pretty easy this might help https://www.123ict.co.uk/website/wp-content/uploads/2017/11/SurfProtect-Quantum-Certificate-Set-Up.pdf Edited December 15, 2020 by round2it 1
mavhc Posted December 15, 2020 Posted December 15, 2020 You're installing a Root CA, so just make sure it goes to the right place. Computer>policies>windows settings>security>Public Key Policies/Trusted Root Certification Authorities 1
Koldov Posted December 15, 2020 Author Posted December 15, 2020 (edited) Ok, so now this is EXACTLY what I am talking about.... Am I being extremely stupid (it's ok if you say yes).... I probably cannot post links to the actual LGfL/Adept information or copy it verbatim, but here is the jist from the advice page... Installing SSL Certificates: If your school uses Microsoft Active Directory, the network administrator should be able to deploy SSL certificates with Group Policy... Details are available from this Microsoft website: https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc770315(v=ws.10)?redirectedfrom=MSDN In fact I will paste it here.... To deploy a certificate by using Group Policy 1.Open Group Policy Management Console. 2.Find an existing or create a new GPO to contain the certificate settings. Ensure that the GPO is associated with the domain, site, or organizational unit whose users you want affected by the policy. 3.Right-click the GPO, and then select Edit. Group Policy Management Editor opens, and displays the current contents of the policy object. 4.In the navigation pane, open Computer Configuration\Windows Settings\Security Settings\Public Key Policies\Trusted Publishers. 5.Click the Action menu, and then click Import. 6.Follow the instructions in the Certificate Import Wizard to find and import the certificate. 7.If the certificate is self-signed, and cannot be traced back to a certificate that is in the Trusted Root Certification Authorities certificate store, then you must also copy the certificate to that store. In the navigation pane, click Trusted Root Certification Authorities, and then repeat steps 5 and 6 to install a copy of the certificate to that store. My bold... Now if you look at the MS website and follow those instructions (and didn't know better - or ask on EDUGEEK), I think you would put it in: Computer Configuration\Windows Settings\Security Settings\Public Key Policies\Trusted Publishers.... no? So it only says on step 7, that if the certificate is 'self-signed' also put it in the Trusted Root Certification Authorities certificate store... is this certificate self-signed - how the **** would I know? Edited December 15, 2020 by Koldov
round2it Posted December 15, 2020 Posted December 15, 2020 i put mine in the trusted root and it works no problem just create a gpo and apply it to a fresh imaged pc to see if it works
Koldov Posted December 15, 2020 Author Posted December 15, 2020 Thanks, yeah I've changed the GPO now to what you and @mavhc suggested. The Meraki thing is bugging me though, it doesn't look like yours (obviously), but in relation to the Windows style certificate import, it almost seems 'too easy'? It doesn't really inspire confidence that I'm doing the right thing or this is the right place to put it (maybe that's just a Meraki/iOS thing)...
Koldov Posted December 15, 2020 Author Posted December 15, 2020 (edited) Plus when I select it, it doesn't give me any info on what it does... Edit: I typed in the 'NAME' part - but it doesn't come up with any details in the Issuer: Subject/CN: Expiration: parts! Edited December 15, 2020 by Koldov
round2it Posted December 15, 2020 Posted December 15, 2020 it just works and is that easy ipads suck but you can gointo certificates on the ipad and see what its doing and also check to see if it is set to trusted goto settings and type certificate
pete Posted December 15, 2020 Posted December 15, 2020 So it only says on step 7, that if the certificate is 'self-signed' also put it in the Trusted Root Certification Authorities certificate store... is this certificate self-signed - how the **** would I know? HTTPS interception certs are always self-signed (OK, unless you're a nation state who can compromise or strong-arm a CA), trying to use a publicly-valid cert for HTTPS interception is a great way to get banned by public CAs. Symantec (for example) got into a lot of trouble when it transpired they were creating certs for third-party domains without authorization: https://arstechnica.com/information-technology/2017/01/already-on-probation-symantec-issues-more-illegit-https-certificates/
PaddyNewman Posted December 15, 2020 Posted December 15, 2020 (edited) @Koldov I've found your case, I'll assist you in there. Is there anything from the call you'd like us to improve / assist with and I'll see if its something we can do. Feel free to say it here, all ears! (aside from your first paragraph that is, I'll feed that back to the support manager for you) Edited December 15, 2020 by PaddyNewman
Koldov Posted December 15, 2020 Author Posted December 15, 2020 Ah ok, I see.... Once I pressed save on that page in Meraki it was a bit more forthcoming and filled in those parts! On the iPad I can see it appears to have installed (and in 'Certificate Trust Settings' is OK)... The GPO has also installed the cert in the correct place on the Windows test machine! Thanks again! Now onto the Macs...
Koldov Posted December 15, 2020 Author Posted December 15, 2020 (edited) Thanks @PaddyNewman - I think I'm just about there! I know it's difficult to be all things to all people - some need hand holding through an entire process and things explained in minute detail (like me), who aren't confident in making changes to live/production environments, some need complete freedom to do whatever they want (install it and see what breaks). It's a delicate balance for sure, but that's the thing with EDU IT, some are professionals with years of experience, some are teachers who do a 'bit of IT', one man bands to full departments... and everyone has a lot going on at the moment, things that we haven't had a lot of time to plan for and have suddenly become very urgent! Feel free to jump in on the Gridstore and Sophos cases while you're there though... Also if you have the ear of anyone dealing with the HomeProtect filtering, I'm waiting on some answers for that too! Edited December 15, 2020 by Koldov
PaddyNewman Posted December 15, 2020 Posted December 15, 2020 @Koldov Whilst I know what HomeProtect is, I am not the guy that looks after it sadly. If you have emailed them and have got stuck feel free to try again/forward to me and I can pass to them no worries. I understand the balance, I deal with people well above me skill wise and also people that just want a fix and don't know what a patch lead is so we try to cater for the majority and in between. I'm fortunately able to poke various/most bits of our system, I'll probably be doing your HTTPS migration also, so all good. Support team are the first line you see so its key that you get what you intended to get by raising the case. It has been a bit troublesome to get people up to scratch when its pretty much isolated and everyone is at home, but still, we try to give 100%. I get how it is in your position though! If you IM me your case refs I can go take a look. 1
DavidYoung Posted December 16, 2020 Posted December 16, 2020 Also if you have the ear of anyone dealing with the HomeProtect filtering, I'm waiting on some answers for that too! Hi @Koldov. Can you please send me a PM with your details and I will see what's happened to your request. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now