Hi all,
I read about certificate inspection feature and I don't quite understand its logic. According to this KB article, for instance, all it does is checking CN field of the server-sent certificates to the web filter policies. Is it all it can do?
[ul]
What about SAN field, is it checked?What about checking CN or SAN hostnames against the SNI value sent by the client? Is it done?What about setting constraints on the certificate chain? For instance, I know that all Google sites are equipped with certificates issued by GlobalSign. Can I set "certificate inspection" profile to verify that certificate received from https://mail.google.com is indeed signed by GlobalSign CA cert? Can it be done for all sites under the google.com domain? Is it possible with regular firewall policies or with proxy policies?[/ul]Does anybody know answers to these?
Thanks,
Vladimir.