Sonic007 Posted July 16, 2021 Posted July 16, 2021 Hi, We've just gone live on our Schools Broadband and I'm just testing things. Just a few questions: - I cant seem to get the SSL certificate to work. I've imported it in to a GPO but sites such as Google just don't work. - Will the SSL certifcate on the server also be picked up by non-domain laptops that just connect to the Internet through the Wifi? Any ideas? THankyou.
snagrat Posted July 16, 2021 Posted July 16, 2021 Although you have imported into GPO is the certificate actually installed on the machine? Non domain laptops will not get the certificate via the server. It will need manually installing or they need to access the internet with SSL disabled.
Sonic007 Posted July 16, 2021 Author Posted July 16, 2021 Are you serious? THe whole point we signed up was to make things simpler. So if someone turns up with their laptop they cant just connect and not have to deal with certificates?
Sonic007 Posted July 16, 2021 Author Posted July 16, 2021 Although you have imported into GPO is the certificate actually installed on the machine? I thought that was the only thing I had to do on the server and then force update GPO settings.
Sonic007 Posted July 16, 2021 Author Posted July 16, 2021 Our filtering is meant to be transparent so thought we wouldnt have to mess with anything.
snagrat Posted July 16, 2021 Posted July 16, 2021 Turn the SSL off then on the transparent side and it’ll work. But if you want the SSL interception then you will need to proxy or use a different VLAN
snagrat Posted July 16, 2021 Posted July 16, 2021 I thought that was the only thing I had to do on the server and then force update GPO settings. It is but you haven’t proved the GPO is actually deploying have you? It the certificate is installed by the GPO and you still have issues then we can troubleshoot that.
Edu-IT Posted July 17, 2021 Posted July 17, 2021 Are you serious? THe whole point we signed up was to make things simpler. So if someone turns up with their laptop they cant just connect and not have to deal with certificates? Yes - if you have SSL inspection enabled.
Sonic007 Posted July 17, 2021 Author Posted July 17, 2021 Thankyou very much for your replies. Much appreciated. Is there any disadvantage of turning SSL inspection/interception or will all my users be fine? Thanks.
SchoolsBroadband Posted July 17, 2021 Posted July 17, 2021 Hi @Sonic007 If you have ssl decryption disabled then you can't decrypt sites such as Google so you can't report on what's inside the packets. The biggest debatable issue this throws up is not being able to run reports on what people have searched for in Google for example as you cNt see inside the encrypted packets when not doing man in the middle ssl decryption. Schools have different policies for devices not controlled by the school. I.e byod some don't decrypt, others do but throw up a splash page where users can download the certificate themselves and install it on their device. Either is possible. Some schools also make fancy captive portal pages showing how to do this. It's entirely up to you and your schools esafety policy ultimately we can achieve either method. I'd suggest having byod on a completely separate vlan / ssid so they can have their own specific filtering policy. If you need any help let me know and I'll get an engineer to give you a call. Thanks Dave
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now