Internal certificate authority

An internal certificate authority resigns the traffic after it has been decrypted.

This topic discusses how to add an internal certificate authority (CA) to an outbound section of a standard decryption policy. The internal CA must be trusted by users on your network to avoid seeing untrusted certificate errors in their web browser.

For more information, see Add an internal CA for outbound protection.