Sheridan Posted October 27, 2015 Posted October 27, 2015 I've finally managed to get a test chromebook and some time to tinker. I've now got an enrolled chromebook which seems to be pulling policies down nicely. The only (albeit a biggy) problem is that ssl inspection isn't working. We use smoothwall and have the certificate installed on all devices (Windows/mac/ios) and the chromebook appears to have pulled this certificate down (when you check in the settings/certificates) But any ssl traffic is blocked with the 'Your connection is not private' and the error NET: ERR_CERT_AUTHORITY_INVALID I feel like I'm very close but is there something else I'm supposed to do? I followed the google instructions and it all seems to have configured correctly.
CyberNerd Posted October 27, 2015 Posted October 27, 2015 You can deploy the SSL cert via the admin console. It's in devices > network >certificates I see that you say it has these settings, but that is all we did. Check whether it is FQDN 1
Sheridan Posted October 27, 2015 Author Posted October 27, 2015 Its the certificate exported from smoothwall that we deploy to windows machines and IOS devices which seems to work ok I can see it has installed on the chromebooks so I guess its something else wrong with that certificate.
CyberNerd Posted October 27, 2015 Posted October 27, 2015 Ours just says: Issued on: Dec 10, 2013 Expires on: Dec 6, 2028 Restricted to: Chromebooks This certificate is not being used by any networks. Multiple sign-in will be disabled for users where SSL-inspecting certs are in effect (tick) Use this certificate as an HTTPS certificate authority. I would double check that it's the FQDN certificate.One interesting thing (and I double checked our "user settings", and no cert is deployed there) is that when students bring in their own BYOD chromebook that isn't in the domain management console, the certificate also gets deployed to their user profile, thus if they loginto their own chromebook with a school account they also get the certificates, but don't if they login with a home account. My understanding was that "network settings" should only apply to devices, but we deploy to users too, so it might be worth checking that.
Sheridan Posted October 27, 2015 Author Posted October 27, 2015 Hmm, our smoothwall still uses the smoothwall.local name, which is on the certificate. It works fine deployed to any other device apart from the chromebooks. I wonder if it won't work unless it uses our domain name. I've got it setup exactly the same as you by the look of it.
Sheridan Posted October 27, 2015 Author Posted October 27, 2015 Ha! Deleted the certificate, re-exported it, and then imported it back into the admin console and its working perfectly now!
timbo343 Posted October 27, 2015 Posted October 27, 2015 @Sheridan how did you get round the problem with the smoothwall.local certs? Our county has got new boxes and 2 of us have got certs with smoothwall.local rather than name.domain.local. Is there a way to recreate the cert?
Sheridan Posted October 27, 2015 Author Posted October 27, 2015 Ours still has the smoothwall.local name and it now works. I removed any old certificates from the Google domain and then exported the certificate from the smoothwall box, then reimported it back into the Google domain. It showed the same details as previously but now works fine, so I'm not sure what the problem was?
timbo343 Posted October 27, 2015 Posted October 27, 2015 Hmmm.. I thought the cert had to have the same name as the system with the domain name for things to work.
Sheridan Posted October 27, 2015 Author Posted October 27, 2015 So did I, and I thought that's what my problem must have been. You do have to check the option to mark it as a CA certificate as @CyberNerd describes above which presumably gets around this.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now