Hi All,
Current Environment Setup:
URL Filtering Enabled
HTTPS Inspection Enabled: Domain A (Signed by Third-Party CA)
There's scenario when customer is migrating to new active directory domains, so there would some existing users still in Domain A however some users is migrated to Domain B. Previously all the user's PC is already installed the certificate under domain A that export from the gateway for HTTPs Inspection. However, when migrating the users to new domain, those new users' domain is facing certificate authority invalid issue which cause them unable to browse internet. After checked found that the browser certificate is still using old domain A, that's why the connection is not trusted as different domain.
Customer concern if renew the HTTPs Inspection certificate to new Domain B, all the existing users that still in Domain A might have impact where's the gateway will not recognize for these users. However, if without renew the cert to new domain, those migrated users is impacted, and they couldn't browser internet.
Hence would like to know whether is that possible to import 2 different domain CA cert to the HTTPs Inspection as so the HTTPs Inspection can be applicable to two different Activity Directory domain users. Or is there any workaround for this situation? Kindly please advised. Thank you.
Best Regards,
Keon