Hi,
I wanted to find out from others if this behavior is normal or not. Whenver I run an SSL labs qualys check on our systems just to ensure there isn't a broken chain, the systems that I have inbound HTTPS inspection enabled for show up in the results of the chain indicating 'contains anchor'. What I found out is that is inferring that the whole chain including the root certificate is being presented to the client. What I learned is that my systems really only need the internmediate certificate in the chain as the root is normally trusted by the client. When I bypass HTTPS inspection and run the ssl labs test again, It doesn't present any issues with the chain including the 'contains anchor' warning (assuming it's just a warning).
Anyway, I'm curious if anyone else sees this type of behavior when testing their SSL certificates to ensure there isn't a broken chain or any issues when inbound HTTPS inspection is enabled.
And I do have the updated P12 certificate imported and applied to the rule.
But is this normal to see 'contains anchor' when HTTPS inspection is turned on?
JB