The Web Appliance
creates a certificate for its
secure session with the
user.
The returned page goes
through the following
process:
The secure site
sends an HTTPS page
to the Web Appliance.
The Web Appliance
decrypts the page.
The Web Appliance
scans the contents.
The Web Appliance
re-encrypts the page.
The Web Appliance
sends the re-encrypted
page to the user, whose
browser decrypts the
page using the
certificate authority
installed in Step 1.
Note: For more information about obtaining the certificate to install on your users’ browsers, see
Downloading the Certificate Authority
on page 108.
HTTPS Compatibility with Sites
Many financial sites require that clients use a specific certificate authority to establish an HTTPS
session with the financial institution’s site. During HTTPS scanning, the appliance replaces the
client certificate with its own certificate. Therefore, financial institutions that require special client
certificates do not support HTTPS scanning. It is highly recommended that administrators enable
the option to Exempt Financial & Investment sites from HTTPS scanning for maximum
compatibility. This option is enabled by default when HTTPS scanning is enabled.
Sophos Web Appliance | Appliance Behavior and Troubleshooting | 215