Using Certificates

PAGE CONTENTS

There are two types of SSL certificate used by WebTitan Cloud for Service Providers:

  1. UI SSL Certificate. This certificate ensures that all your HTTP communication with the WebTitan Cloud UI is encrypted and secure. See Selecting your WebTitan Cloud UI SSL Certificate.

  2. Customer SSL Certificate. This certificate can be deployed by your customers to their users. It ensures that a user's browser does not return a certificate error page instead of a WebTitan Cloud block page when they visit a blocked HTTPS web page. See Selecting your Customers SSL Certificate.

Note

Default UI SSL and Customer SSL certificates are set up as part of your WebTitan Cloud configuration.

Selecting your WebTitan Cloud UI SSL Certificate

The UI SSL certificate ensures that all HTTP communication with the WebTitan Cloud UI is encrypted.

A default UI SSL certificate is installed as part of your WebTitan Cloud setup. However, if you want to install your own certificate, WebTitan Cloud allows the following types:

  1. Trusted certificates, issued by a trusted certificate signing authority.

  2. Private (self-signed) certificates.

See Generating Certificate Signing Requests for information on creating your own certificates.

Go to Settings > SSL to configure and manage UI SSL certificates.

All loaded certificates are listed in Settings > SSL > Installed Signed Certificates.

Selecting your Customer's SSL Certificate

If your customers visit an HTTPS enabled website that is blocked by their policy, their browser will return a certificate error page instead of the WebTitan Cloud block page. This can be confusing for users.

To avoid this, your customers can deploy an SSL Certificate as a trusted root certificate on all browsers using WebTitan Cloud. See the WebTitan Cloud Customer Admin Guide here for more information on how a customer can do this.

Go to Settings > SSL Certificate to select, view, download and edit the certificate that will be available for your customers to download.

  • CA Certificate shows the root CA certificate which is currently in use by the proxy. To choose a different available certificate, select it from the drop down menu and click Save.

  • The Available Certificates table lists all available certificates.

    • Click the view icon in the Options column to view a certificate.

    • Click the download icon in the Options column to download a certificate.

    • Click the delete icon in the Options column to delete a certificate.

    • Click New to generate a new self-signed certificate.

Generating Certificate Signing Requests

Go to Settings > SSL > Generate Certificate Signing Request (CSR) and follow the steps below to generate a certificate signing request. This CSR can be used either for submission to a certificate authority who will issue a trusted certificate or to create a self-signed certificate.

  1. To create a self-signed certificate:

    • Using the table below as a reference, complete the fields in the Certificate Signing Request (CSR).

    • Click Run opposite Generate Self Signed Certificate.

    • The self-signed certificate will display under Installed Signed Certificates.

  2. If generating the CSR for submission to a certificate authority:

    • Using the table below as a reference, complete the fields in the Certificate Signing Request (CSR).

    • Click Run opposite Generate Certificate Signing Request (CSR). The CSR will generate and display as shown:

    • Copy the CSR text exactly and submit it to a trusted certificate signing authority for signing.

    • Once returned by the certificate authority, import the signed certificate into WebTitan Cloud. See Importing a Signed Certificate

Field

Description

Common Name:

The fully-qualified domain name that is used to access the WebTitan Cloud GUI, e.g. webtitancloud.example.com. This must match the server name exactly or a warning dialog will display every time you visit the site.

Organization:

Company or organization name.

Organization Unit:

Department within the company or organization (optional).

City:

City/town where company or organization is located.

State/Province:

Full name of the state or province where the company or organization is located.

Country:

Two letter country code of country where company or organization is located, e.g. US or IE.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article