Importing the Unified Assurance Global CA Certificate
This guide will show you how to import the Unified Assurance Global CA certificate into the browser store, which is needed for UIs to load faster and improve overall performance.
Note:
After Unified Assurance generated certificates are rotated, the Unified Assurance Global CA certificate may change. If your browser no longer trusts the Unified Assurance UI after certificate rotation, connect to a Unified Assurance instance, navigate to $A1BASEDIR/etc/ssl/, then download and import the new Unified Assurance Global CA certificate. After that, follow the steps given in Import the Certificate into the Store.
Download the Certificate
-
In the browser, go to the login screen of a Unified Assurance installation.
-
A notification bar will be shown with a link to download the CA Certificate. Click on the link to download the file, then proceed with the Import the Certificate into the Store steps below.
Note:
If the notification bar is not displayed, there are a few possible reasons for that:
-
If the notification bar was previously manually closed, it will not be displayed again. A workaround for this is to clear any cookies for the installation, then refreshing the login page, or go to the login screen using a private/incognito browser window.
-
The notification bar may have been disabled by a local administrator. While this is usually done when using a externally signed certificate, it could have been done by mistake as well. Please contact a local administrator for additional assistance.
-
Import the Certificate into the Store
Windows
Chrome and Edge
-
Press the Windows button + R to bring up the Run window.
-
Enter mmc and press enter to launch the Microsoft Management Console.
-
Click on the File drop-down, then click Add/Remove Snap-in.
-
In the Available snap-ins list, select Certificates and then click Add.
-
In the pop-up, select Computer account and click Next.
-
Leave Local computer... selected and click Finish.
-
Click OK.
-
Expand the following path: Certificates (Local Computer) -> Trusted Root Certification Authorities -> Certificates.
-
In the right panel, click More Actions, then All Tasks, then Import.
-
In the Certificate Import Wizard, click Next.
-
Use the Browse button to select the certificate file that was saved in the previous section, then click Next.
-
Leave the Place all certificates... option selected, then click Next.
-
Click Finish.
-
Click OK on the successful import message.
-
Restart the browser.
-
Go to a Unified Assurance installation. The browser should now report the site is secure.
Firefox
-
Follow the steps in the Windows -> Chrome and Edge section to import the certificate into the local store.
-
Open Firefox, and in a new tab, enter the following in the address bar:
about:config
-
Click I accept the risk!.
-
In the Search bar, enter the following:
security.enterprise_roots.enabled
-
The default value of the option is false. Do one of the following to change it to true:
-
Double-click on the "security.enterprise..." line.
-
Right-click on the line and select Toggle from the drop-down.
-
Close the tab.
-
Restart Firefox.
-
Go to a Unified Assurance installation. The browser should now report the site is secure.
Mac
Chrome and Safari
-
Launch Finder, then select Applications, open the Utilities folder, and start the Keychain Access application.
-
On the left side of the window, Keychains should be set to System and Category should be set to Certificates.
-
Drag-and-drop the certificate that was exported earlier from the desktop into the list of certificates.
-
Double-click the recently added Unified Assurance Global CA certificate to show additional options.
-
Expand the Trust section.
-
Set the When using this certificate field to Always Trust.
-
Close the Unified Assurance Global CA window.
-
Close the Keychain Access window.
-
Restart the browser.
-
Go to a Unified Assurance installation. The browser should now report the site is secure.
Firefox
-
Follow the steps in the Mac -> Chrome and Safari section to import the certificate into the local store.
-
Open Firefox, and in a new tab, enter the following in the address bar:
about:config
-
Click I accept the risk!.
-
In the Search bar, enter the following:
security.enterprise_roots.enabled
-
The default value of the option is false. Do one of the following to change it to true:
-
Double-click on the "security.enterprise..." line.
-
Right-click on the line and select Toggle from the drop-down.
-
Close the tab.
-
Restart Firefox.
-
Go to a Unified Assurance installation. The browser should now report the site is secure.