I'm in the process of "rebuilding" a system, and one element that I need to re-enable is HTTPS inspection. This was working previously, but has been bypassed for the last several months (by a rule in the policy)
The existing certificate is 5 years old with a 10 year life, and at present is NOT installed on the users machines due to them being rebuilt (and group policy being reset too!), its also created on the management server using the company's name as the issuing authority (www.mycompany,co,uk), but this is a local certificate and nothing to do with the actual real domain by that name. So the cert shows issued by and issued to, both as www.mycompany.co.uk, which is a little confusing for people.
So my thought is to generate a new certificate on the management server, using a more generic or obvious name with a full 10 years on it, then deploy this with via a GPO, however I can't see a way to do this.
I'm assuming that there is a way to do this but so far I've not found anything helpful (everything seems to discuss creating it when you turn on HTTPS inspection, but as it's already on this isn't an option), so I was wondering if anyone could advise me?