Jump to content

Recommended Posts

Posted

I've finally managed to get a test chromebook and some time to tinker. I've now got an enrolled chromebook which seems to be pulling policies down nicely.

 

The only (albeit a biggy) problem is that ssl inspection isn't working. We use smoothwall and have the certificate installed on all devices (Windows/mac/ios) and the chromebook appears to have pulled this certificate down (when you check in the settings/certificates)

 

But any ssl traffic is blocked with the 'Your connection is not private' and the error NET: ERR_CERT_AUTHORITY_INVALID

 

I feel like I'm very close but is there something else I'm supposed to do? I followed the google instructions and it all seems to have configured correctly.

Posted

You can deploy the SSL cert via the admin console.

It's in devices > network >certificates

I see that you say it has these settings, but that is all we did.

Check whether it is FQDN

  • Thanks 1
Posted

Its the certificate exported from smoothwall that we deploy to windows machines and IOS devices which seems to work ok

 

I can see it has installed on the chromebooks so I guess its something else wrong with that certificate.

Posted

Ours just says:

Issued on: Dec 10, 2013 Expires on: Dec 6, 2028

Restricted to: Chromebooks

This certificate is not being used by any networks.

 

Multiple sign-in will be disabled for users where SSL-inspecting certs are in effect

 

(tick) Use this certificate as an HTTPS certificate authority.

 

I would double check that it's the FQDN certificate.One interesting thing (and I double checked our "user settings", and no cert is deployed there) is that when students bring in their own BYOD chromebook that isn't in the domain management console, the certificate also gets deployed to their user profile, thus if they loginto their own chromebook with a school account they also get the certificates, but don't if they login with a home account. My understanding was that "network settings" should only apply to devices, but we deploy to users too, so it might be worth checking that.

Posted

Hmm, our smoothwall still uses the smoothwall.local name, which is on the certificate. It works fine deployed to any other device apart from the chromebooks.

 

I wonder if it won't work unless it uses our domain name. I've got it setup exactly the same as you by the look of it.

Posted

@Sheridan how did you get round the problem with the smoothwall.local certs? Our county has got new boxes and 2 of us have got certs with smoothwall.local rather than name.domain.local.

 

Is there a way to recreate the cert?

Posted
Ours still has the smoothwall.local name and it now works. I removed any old certificates from the Google domain and then exported the certificate from the smoothwall box, then reimported it back into the Google domain. It showed the same details as previously but now works fine, so I'm not sure what the problem was?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...