be harder for users to identify phishing sites in their browser. Certificate validation ensures
that such sites are not accessed.
■
To add a certificate from a website to the custom certificate list, see "Adding a Certificate from
a Web Site".
■
To add a certificate authority to the custom certificate list, see "Adding a Root Authority
Certificate".
■
To remove a certificate from the custom certificate list, select the check box to the right of the
certificate in the custom certificate list that you want to remove, click Delete, and then click
Apply.
■
To view Sophos root authorities, at the bottom of the custom certificates list, click View Sophos
root authorities, and browse the list of the root certificate authorities supplied by Sophos in
the Root Authorities pop-up dialog box.
Related concepts
on page 213
Appliance Features Not Supported by Endpoint Web Control
on page 54
Related tasks
Adding a Certificate from a Web Site
on page 109
Adding a Root Authority Certificate
on page 109
4.3.6.1 Adding a Certificate from a Web Site
Important: Retrieving certificates from HTTPS sites can be difficult when HTTPS scanning is
enabled, as the Web Appliance will provide its own certificate in place of the remote one. Turn
HTTPS scanning off on the Configuration > Global Policy > HTTPS Scanning page to be able
to download any certificate other than the Sophos-generated certificate. Be sure to turn HTTPS
scanning back on once you are done.
1. Enter the URL to the site from which you want to get the certificate, and click Get Certificate.
You must enter a site URL, not a file or directory-specific URL.
The Add Certificate dialog box is displayed, and it shows the certificate information.
2. Click Add.
The site certificate is added to the certificate list.
Related concepts
on page 213
Related tasks
Configuring Certificate Validation
on page 108
4.3.6.2 Adding a Root Authority Certificate
Important: Retrieving certificates from HTTPS sites can be difficult when HTTPS scanning is
enabled, as the Web Appliance will provide its own certificate in place of the remote one. Turn
HTTPS scanning off on the Configuration > Global Policy > HTTPS Scanning page to be able
Sophos Web Appliance | Configuration | 109