SSL interception
-
The CA certificate that is used to sign the server certificate must be preinstalled on all the client devices, so that the regenerated server certificate is trusted by the client.
-
When a front-end client certificate uses MD5 or SHA1 signatures, the copied client certificate is generated with SHA256 signatures. For more information about the copied client certificate signatures for the corresponding front-end client certificates, see Dynamic client certificate generation.
-
SSL profile
-
SSL policy
-
CA certificate store
-
SSL-error autolearning and caching
SSL interception certificate store
Import and apply a CA certificate bundle on the appliance by using the CLI
import ssl certBundle <name> <src>
apply ssl certBundle <name>show ssl certBundle
http://www.example.com/cert_bundle_file.
import ssl certbundle swg-certbundle http://www.example.com/cert_bundle
apply ssl certBundle swg-certbundleshow ssl certbundle
Name : swg-certbundle(Inuse)
URL : http://www.example.com/cert_bundle
Done
Import and apply a CA certificate bundle on the appliance by using the GUI
-
Navigate to Security > SSL Forward Proxy > Getting Started > Certificate Bundles.
-
Do one of the following:
-
Select a certificate bundle from the list.
-
To add a certificate bundle, click "+" and specify a name and source URL. Click OK.
-
-
Click OK.
Remove a CA certificate bundle from the appliance by using the CLI
remove certBundle <cert bundle name>
remove certBundle mytest-cacert
Export a CA certificate bundle from the appliance by using the CLI
export certBundle <cert bundle name> <Path to export>
http://www.example.com/cert_bundle_file.
export certBundle mytest-cacert http://192.0.2.20/
Import, apply, and verify a CA certificate bundle from the Mozilla CA certificate store
> import certbundle mozilla_public_ca https://curl.haxx.se/ca/cacert.pem
Done
> apply certbundle mozilla_public_ca
Done
> sh certbundle | grep mozilla
Name : mozilla_public_ca (Inuse)
Limitations
-
Certificate bundles are not supported in a cluster setup, or on a partitioned appliance.
-
TLSv1.3 protocol is not supported with SSL Forward Proxy.
SSL policy infrastructure for SSL interception
patset), or a URL category derived from the domain.
Create an SSL policy by using the CLI
add ssl policy <name> -rule <expression> -action <string>
detected_domain attribute to check for a domain name.
add ssl policy pol1 -rule client.ssl.detected_domain.contains("XYZBANK") -action BYPASS
add ssl policy pol2 -rule client.ssl.client.ssl.detected_domain.url_categorize(0,0).category.eq ("YouTube") -action RESET
add ssl policy pol3 –rule true –action INTERCEPT
add ssl policy pol4 -rule client.ssl.origin_server_cert.subject.contains("yahoo") –action INTERCEPT
add ssl policy pol_url_category -rule client.ssl.origin_server_cert.subject.URL_CATEGORIZE(0,0).CATEGORY.eq("Shopping/Retail") -action INTERCEPT
add ssl policy pol_url_category -rule client.ssl.origin_server_cert.subject.url_categorize(0,0).category.eq("Uncategorized") -action INTERCEPT
add ssl policy pol_url_set -rule client.ssl.client_hello.SNI.URLSET_MATCHES_ANY("top100") -action INTERCEPT
add ssl policy pol_url_set -rule client.ssl.origin_server_cert.subject.URLSET_MATCHES_ANY("top100") -action INTERCEPT
Create an SSL policy to a proxy server by using the GUI
-
Navigate to Traffic Management > SSL > Policies.
-
On the SSL Policies tab, click Add and specify the following parameters:
-
Policy name
-
Policy action – Select from intercept, bypass, or reset.
-
Expression
-
-
Click Create.
Bind an SSL policy to a proxy server by using the CLI
bind ssl vserver <vServerName> -policyName <string> -priority <positive_integer> -type INTERCEPT_REQ
bind ssl vserver <name> -policyName pol1 -priority 10 -type INTERCEPT_REQ
Bind an SSL policy to a proxy server by using the GUI
-
Navigate to Security > SSL Forward Proxy > Proxy Virtual Servers.
-
Select a virtual server and click Edit.
-
In Advanced Settings, click SSL Policies.
-
Click inside the SSL Policy box.
-
In Select Policy, select a policy to bind.
-
In Type, select INTERCEPT_REQ.
-
Click Bind and then click OK.
Unbind an SSL policy to a proxy server by using the CLI
unbind ssl vserver <vServerName> -policyName <string> -type INTERCEPT_REQ
SSL expressions used in SSL policies
| Expression | Description |
|---|---|
CLIENT.SSL.CLIENT_HELLO.SNI.* |
Returns the SNI extension in a string format. Evaluate the string to see if it contains the specified text. Example: client.ssl.client_hello.sni.contains(“xyz.com”) |
CLIENT.SSL.ORIGIN_SERVER_CERT.* |
Returns a certificate, received from a back-end server, in a string format. Evaluate the string to see if it contains the specified text. Example: client.ssl.origin_server_cert.subject.contains(“xyz.com”) |
CLIENT.SSL.DETECTED_DOMAIN.* |
Returns a domain, either from the SNI extension or from the origin server certificate, in a string format. Evaluate the string to see if it contains the specified text. Example: client.ssl.detected_domain.contains(“xyz.com”) |
SSL error autolearning
-
A request for a client certificate is received from the server.
-
Any one of the following alerts is received as part of the handshake:
-
BAD_CERTIFICATE
-
UNSUPPORTED_CERTIFICATE
-
CERTIFICATE_REVOKED
-
CERTIFICATE_EXPIRED
-
CERTIFICATE_UNKNOWN
-
UNKNOWN_CA (If a client uses pinning, it sends this alert message if it receives a server certificate.)
-
HANDSHAKE_FAILURE
-
Enable learning by using the GUI
-
Navigate to Traffic Management > SSL.
-
In Settings, click Change advanced SSL settings.
-
In SSL Interception, select SSL Interception Error Cache.
-
In SSL Interception Max Error Cache Memory, specify the memory (in bytes) to reserve.

-
Click OK.
Enable learning by using the CLI
set ssl parameter -ssliErrorCache ( ENABLED | DISABLED ) -ssliMaxErrorCacheMem <positive_integer>
SSL profile
-
Check the OCSP status of the origin server certificate.
-
Trigger client renegotiation if the origin server requests renegotiation.
-
Verify the origin server certificate before reusing the front-end SSL session.
Add an SSL profile and enable SSL interception by using the CLI
add ssl profile <name> -sslinterception ENABLED -ssliReneg ( ENABLED | DISABLED ) -ssliOCSPCheck ( ENABLED | DISABLED ) -ssliMaxSessPerServer <positive_integer>
add ssl profile swg_ssl_profile -sslinterception ENABLED
Done
sh ssl profile swg_ssl_profile
1) Name: swg_ssl_profile (Front-End)
SSLv3: DISABLED TLSv1.0: ENABLED TLSv1.1: ENABLED TLSv1.2: ENABLED
Client Auth: DISABLED
Use only bound CA certificates: DISABLED
Strict CA checks: NO
Session Reuse: ENABLED Timeout: 120 seconds
DH: DISABLED
DH Private-Key Exponent Size Limit: DISABLED Ephemeral RSA: ENABLED Refresh Count: 0
Deny SSL Renegotiation ALL
Non FIPS Ciphers: DISABLED
Cipher Redirect: DISABLED
SSL Redirect: DISABLED
Send Close-Notify: YES
Strict Sig-Digest Check: DISABLED
Push Encryption Trigger: Always
PUSH encryption trigger timeout: 1 ms
SNI: DISABLED
OCSP Stapling: DISABLED
Strict Host Header check for SNI enabled SSL sessions: NO
Push flag: 0x0 (Auto)
SSL quantum size: 8 kB
Encryption trigger timeout 100 mS
Encryption trigger packet count: 45
Subject/Issuer Name Insertion Format: Unicode
SSL Interception: ENABLED
SSL Interception OCSP Check: ENABLED
SSL Interception End to End Renegotiation: ENABLED
SSL Interception Server Cert Verification for Client Reuse: ENABLED
SSL Interception Maximum Reuse Sessions per Server: 10
Session Ticket: DISABLED Session Ticket Lifetime: 300 (secs)
HSTS: DISABLED
HSTS IncludeSubDomains: NO
HSTS Max-Age: 0
ECC Curve: P_256, P_384, P_224, P_521
1) Cipher Name: DEFAULT Priority :1
Description: Predefined Cipher Alias
Done
Bind an SSL interception CA certificate to an SSL profile by using the CLI
bind ssl profile <name> -ssliCACertkey <ssli-ca-cert>
bind ssl profile swg_ssl_profile -ssliCACertkey swg_ca_cert
Done
sh ssl profile swg_ssl_profile
1) Name: swg_ssl_profile (Front-End)
SSLv3: DISABLED TLSv1.0: ENABLED TLSv1.1: ENABLED TLSv1.2: ENABLED
Client Auth: DISABLED
Use only bound CA certificates: DISABLED
Strict CA checks: NO
Session Reuse: ENABLED Timeout: 120 seconds
DH: DISABLED
DH Private-Key Exponent Size Limit: DISABLED Ephemeral RSA: ENABLED Refresh Count: 0
Deny SSL Renegotiation ALL
Non FIPS Ciphers: DISABLED
Cipher Redirect: DISABLED
SSL Redirect: DISABLED
Send Close-Notify: YES
Strict Sig-Digest Check: DISABLED
Push Encryption Trigger: Always
PUSH encryption trigger timeout: 1 ms
SNI: DISABLED
OCSP Stapling: DISABLED
Strict Host Header check for SNI enabled SSL sessions: NO
Push flag: 0x0 (Auto)
SSL quantum size: 8 kB
Encryption trigger timeout 100 mS
Encryption trigger packet count: 45
Subject/Issuer Name Insertion Format: Unicode
SSL Interception: ENABLED
SSL Interception OCSP Check: ENABLED
SSL Interception End to End Renegotiation: ENABLED
SSL Interception Server Cert Verification for Client Reuse: ENABLED
SSL Interception Maximum Reuse Sessions per Server: 10
Session Ticket: DISABLED Session Ticket Lifetime: 300 (secs)
HSTS: DISABLED
HSTS IncludeSubDomains: NO
HSTS Max-Age: 0
ECC Curve: P_256, P_384, P_224, P_521
1) Cipher Name: DEFAULT Priority :1
Description: Predefined Cipher Alias
1) SSL Interception CA CertKey Name: swg_ca_cert
Done
Bind an SSL interception CA certificate to an SSL profile by using the GUI
-
Navigate to System > Profiles > SSL Profile.
-
Click Add.
-
Specify a name for the profile.
-
Enable SSL Sessions Interception.
-
Click OK.
-
In Advanced Settings, click Certificate Key.
-
Specify an SSL interception CA certificate key to bind to the profile.
-
Click Select and then click Bind.
-
Optionally, configure ciphers to suit your deployment.
-
Click the edit icon, and then click Add.
-
Select one or more cipher groups, and click the right arrow.
-
Click OK.
-
-
Click Done.
Bind an SSL profile to a proxy server by using the GUI
-
Navigate to Security >SSL Forward Proxy > Proxy Virtual Servers, and add a server or select a server to modify.
-
In SSL Profile, click the edit icon.
-
In the SSL Profile list, select the SSL profile that you created earlier.
-
Click OK.
-
Click Done.
Name: swg_ssl_profile (Front-End)
SSLv3: DISABLED TLSv1.0: ENABLED TLSv1.1: ENABLED TLSv1.2: ENABLED
Client Auth: DISABLED
Use only bound CA certificates: DISABLED
Strict CA checks: NO
Session Reuse: ENABLED Timeout: 120 seconds
DH: DISABLED
DH Private-Key Exponent Size Limit: DISABLED Ephemeral RSA: ENABLED Refresh Count: 0
Deny SSL Renegotiation ALL
Non FIPS Ciphers: DISABLED
Cipher Redirect: DISABLED
SSL Redirect: DISABLED
Send Close-Notify: YES
Strict Sig-Digest Check: DISABLED
Push Encryption Trigger: Always
PUSH encryption trigger timeout: 1 ms
SNI: DISABLED
OCSP Stapling: DISABLED
Strict Host Header check for SNI enabled SSL sessions: NO
Push flag: 0x0 (Auto)
SSL quantum size: 8 kB
Encryption trigger timeout 100 mS
Encryption trigger packet count: 45
Subject/Issuer Name Insertion Format: Unicode
SSL Interception: ENABLED
SSL Interception OCSP Check: ENABLED
SSL Interception End to End Renegotiation: ENABLED
SSL Interception Maximum Reuse Sessions per Server: 10
Session Ticket: DISABLED Session Ticket Lifetime: 300 (secs)
HSTS: DISABLED
HSTS IncludeSubDomains: NO
HSTS Max-Age: 0
ECC Curve: P_256, P_384, P_224, P_521
1) Cipher Name: DEFAULT Priority :1
Description: Predefined Cipher Alias
1) SSL Interception CA CertKey Name: swg_ca_cert