Friday, May 28, 2021

Cisco switches and ssl decryption

I am working for a fairly large organization and all our internet traffic is ssl inspected. Essentially each endpoint needs to have a root certificate in each endpoint, and that will enable the device to get to HTTPS sites.

The management of our switch infrastructure is outsourced, and our outsourcer says that the Cisco switches need to communicate to Cisco over HTTPS to manage licensing. However they have said that they cannot install the cert in the switch, and so all of it has to be made an exception. I find that hard to believe and was wondering if any of you had any experience with this. Or any experience in setting up certs in Cisco switches. The alternative is to create exceptions for a whole host (thousands) of switches which is not the way I want to go down.

Thanks.



No comments:

Post a Comment