Configuring SSIM GIN Behind the Websense Proxy
search cancel

Configuring SSIM GIN Behind the Websense Proxy

book

Article ID: 152945

calendar_today

Updated On:

Products

Security Information Manager

Issue/Introduction

You are trying to configure the Global Inelegance Network in SSIM through a websense proxy and you get the error as described below.

Error communicating with GIN through Proxy please verify proxy/network configuration

GIN Config: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

Cause

The WebSense proxy is configured to authenticate all outgoing connections using an internal CA and certificate mechanism. Each connection coming to the Websense need to decrypt and encrypt form inside to outside and vice versa. There are no logs reported as blocked attempts on the Websense proxy, because https:// deepsightinfo.symantec.com is permitted through WebSense.

Resolution

There is a configuration in WebSense to ‘specify the individual hostnames or IP addresses for which SSL decryption is not performed’.
 configure deepsightinfo.symantec.com to bypass the SSL decryption and it will connect successfully.


Applies To

(SSIIM -GIN)-------------------|[WebSense proxy]--------------(Internet)

                              SSL