
Just as there is a slight performance impact on the processing of encrypted traffic with any SSL
transaction, so there will be if you enable HTTPS scanning. Consider this impact on the traffic
throughput and capacity for your network and the appliance when deciding whether to use this
feature.
The Configuration > Global Policy > HTTPS Scanning page allows you to enable or disable
HTTPS (SSL) scanning and set logging options for HTTPS transactions.
■
To enable or disable HTTPS scanning, either click On beside HTTPS scanning to enable it,
or click Off to disable it, and then click Apply.
Important: When you enable HTTPS scanning, certificate validation is automatically enabled.
Certificate validation ensures that sites with invalid certificates (often phishing sites) are not
accessed. If you do want certificate validation disabled while HTTPS scanning is enabled, you
must disable it on the Configuration > Global Policy > Certificate Validation page after
enabling HTTPS scanning.
■
To set the HTTPS logging options, select either Log hostname only for HTTPS transactions
or Log complete URLs for HTTPS transactions to enable that logging option for HTTPS
transactions, and then click Apply.
■
To create and manage a list of sites exempted from scanning, see the "Managing HTTPS
Scanning Exemptions" page.
■
To download a copy of the Sophos certificate authority, see the "Downloading the Certificate
Authority" page.
Related concepts
on page 213
Appliance Features Not Supported by Endpoint Web Control
on page 54
4.3.5.1 Managing HTTPS Scanning Exemptions
The Configuration > Global Policy > HTTPS Scanning page allows appliance administrators
to create and manage a list of sites that are exempted from scanning. Certain sites do not function
properly if HTTPS scanning is enabled. To ensure that these sites work properly, add these
problematic sites to this list of sites exempt from HTTPS scanning.
■
To exempt sites from HTTPS scanning:
a) In the text box to the left of the Add button, enter the domain or site (for example,
example.
com
or
host.example.com
) that you want exempted from scanning.
The entry must be in one of the following forms:
— a top-level domain, such as
example.com
— a fully qualified domain name, such as
host.example.com
— a fully qualified domain name including a subdomain, such as
host.subdomain.
example.com
The entry must not be in either of the following forms:
— a domain name including a sub-domain, but without the hostname, such as
subdomain.
example.com
106 | Configuration | Sophos Web Appliance