When you activate HTTPS Inspection, SSL-encrypted web traffic is routed through the Web Security infrastructure. Before you turn on HTTPS Inspection for your Web Security service, you must do the following:
Download the Symantec Web Security.cloud Root CA from the portal.
Install the certificate on all of the web browsers that are connected to the Web Security service.
Take this step to ensure that the Symantec Web Security.cloud Root CA is correctly authenticated by your users' browsers. If you do not install the certificate on each browser, users receive a certificate error when they access a website using HTTPS.
In the portal, click Tools > Downloads
Click the link for the Symantec Web Security.cloud Root CA and save the certificate to a suitable location.
You must install the certificate on all browsers that connect to the Web Security service infrastructure. You can install the certificate by using a number of different methods, as listed here.
Run MMC.exe.
Choose File > Add/Remove snap-in.
Select Certificates and click Add.
Choose Computer Account and click Next.
Select Local computer and click Finish.
Click OK to add the Certificates snap-in to MMC.
Expand Trusted Root Certification Authorities, right-click Certificates, and choose Import.
At the welcome page click Next.
Browse to locate the certificate file, select the file name, and click Next.
Ensure that the certificate is placed in the Trusted Root Certification Authorities store, and click Next.
Click Finish to import the certificate.
Edit the appropriate group policy. For example, Default domain policy.
Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies > Trusted Root Certification Authorities.
Right-click Trusted Root Certification Authorities and choose Import.
Browse to the copy of the Symantec.cloud root certificate and click Next.
Confirm that the certificate is placed in the correct certificate store, and click Next.
Click Finish to import the certificate into the Group Policy.
The Group Policy setting takes effect after the affected computers have been restarted.
The Google Chrome web browser uses the local certificate store on each users' computer. Google Chrome is compatible with either method of manually importing a certificate or automatically importing a certificate with Group Policy.
The Mozilla Firefox web browser does not use the computer's certificate store, but instead has its own store for root certificates.
Open an instance of your Mozilla Firefox browser.
On the Firefox home page, click on Settings and then click the Advanced tab.
Click on View Certificates.
The Certificate Manager window opens.
Select the Authorities tab, click Import, and browse to the certificate file and click OK.
The Downloading Certificate window opens.
Check the Trust this CA to identify websites check box and click OK.
Click OK to close the Certificate Manager window.
Click OK to close the Options window.