Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jberg712
Collaborator
Jump to solution

Inbound HTTPS inspection and Qualys SSL Labs results

Hi,

I wanted to find out from others if this behavior is normal or not.  Whenver I run an SSL labs qualys check on our systems just to ensure there isn't a broken chain, the systems that I have inbound HTTPS inspection enabled for show up in the results of the chain indicating 'contains anchor'.  What I found out is that is inferring that the whole chain including the root certificate is being presented to the client.  What I learned is that my systems really only need the internmediate certificate in the chain as the root is normally trusted by the client.  When I bypass HTTPS inspection and run the ssl labs test again, It doesn't present any issues with the chain including the 'contains anchor' warning (assuming it's just a warning).

Anyway, I'm curious if anyone else sees this type of behavior when testing their SSL certificates to ensure there isn't a broken chain or any issues when inbound HTTPS inspection is enabled.

And I do have the updated P12 certificate imported and applied to the rule.  

But is this normal to see 'contains anchor' when HTTPS inspection is turned on?

JB

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

To prevent issues with validating the certificate chain, we recommend including the entire certificate chain as part of the import of any CA certificate (including for HTTPS Inspection).
This is likely why you see this result and it would, therefore, be expected.

View solution in original post

1 Reply
PhoneBoy
Admin
Admin

To prevent issues with validating the certificate chain, we recommend including the entire certificate chain as part of the import of any CA certificate (including for HTTPS Inspection).
This is likely why you see this result and it would, therefore, be expected.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events