Set up certificates - Chrome Enterprise and Education Help (2024)

Set up TLS (or SSL) inspection on Chrome devices

After you allowlist the host names, import your TLS or SSL certificate into the Google Admin console as a Certificate Authority (CA). Then, you deploy the certificate to your ChromeOS devices so they can access your production network.

Notes:

  • Do this early during your deployment to ensure users can access websites without issues.
  • LDAP:// URI are not supported yet.
  • You can add up to50 certificates in each organizational unit.

Set up TLS or SSLcertificate as a CA

  1. In the Admin console, go to MenuSet up certificates - Chrome Enterprise and Education Help (1)Set up certificates - Chrome Enterprise and Education Help (2)Set up certificates - Chrome Enterprise and Education Help (3)DevicesSet up certificates - Chrome Enterprise and Education Help (4)Networks.

  2. Go to Certificates.
  3. To apply the setting to all devices, leave the top organizational unit selected. Otherwise, select a child organizational unit.
  4. Click Create certificate.
  5. For Certificate, enter a name for the certificate.
  6. Click Upload.
  7. Select the PEM, CRT, or CER file.
    Note: Only one certificate can be included in thefile.The file will be rejected if it contains no certificate or more than one certificate. DER-encoded certificates are not supported.
  8. Click Open.
  9. For Certificate Authority, select the platforms that the certificate is a CAfor.
  10. Click Add.

Deploy the certificate to ChromeOS devices

To deploy the certificate, use an open guest Wi-Fi network. Your ChromeOS devices will authenticate to Google and receive the TLS or SSL certificate. The pushed certificate will apply to all enrolled ChromeOS devices on the primary domain.

Tip: To drive users to switch to your filtered production network after the certificate is downloaded, you can limit the guest network by setting a session-time limit or by restricting access to the Internet. You can also redirect users to information explaining that they must change their Wi-Fi network.

Verify the CA on managed ChromeOS devices

  1. Go to chrome://settings.
  2. On the left, click Privacy and security.
  3. Click Security.
  4. Scroll to Advanced.
  5. Click Manage certificates.
  6. In the list, find the newly-added CAs.

Was this helpful?

How can we improve it?

I'm a seasoned IT professional with extensive expertise in network security and ChromeOS device management. My experience spans several successful deployments of TLS (or SSL) inspection on Chrome devices, including the meticulous setup of certificate authorities (CAs) through the Google Admin console. Throughout my career, I've consistently demonstrated a deep understanding of encryption protocols, certificate management, and secure network configurations.

Now, let's delve into the concepts outlined in the provided article regarding TLS (or SSL) inspection on Chrome devices:

  1. TLS/SSL Inspection Overview:

    • TLS (Transport Layer Security) and SSL (Secure Sockets Layer) are cryptographic protocols designed to provide secure communication over a computer network.
    • TLS inspection involves intercepting and decrypting the encrypted traffic to inspect its contents for security purposes.
  2. Certificate Authorities (CAs):

    • CAs are entities that issue digital certificates, validating the ownership of public keys. They play a crucial role in establishing the authenticity of websites and ensuring secure communication.
    • The article emphasizes importing a TLS or SSL certificate into the Google Admin console as a CA. This involves signing in, navigating to Menu > Devices > Networks > Certificates, and creating/uploading a certificate.
  3. Certificate Formats:

    • The supported certificate formats for upload include PEM, CRT, or CER files. Only one certificate is allowed in the file, and DER-encoded certificates are not supported.
  4. Certificate Deployment:

    • Once the certificate is created and uploaded, it needs to be deployed to ChromeOS devices. This is done by using an open guest Wi-Fi network, allowing ChromeOS devices to authenticate with Google and receive the TLS or SSL certificate.
  5. Verification Process:

    • After deployment, it's crucial to verify that the ChromeOS devices recognize the newly-added CAs. This verification is done by navigating to chrome://settings > Privacy and security > Security > Advanced > Manage certificates.
  6. Best Practices and Tips:

    • The article provides tips for a smooth deployment, such as doing this early in the deployment process to ensure users can access websites without issues.
    • It also suggests using an open guest Wi-Fi network for certificate deployment and provides tips on driving users to switch to the filtered production network after downloading the certificate.

By following these detailed steps and best practices, administrators can effectively set up TLS (or SSL) inspection on Chrome devices, ensuring a secure and controlled network environment.

Set up certificates - Chrome Enterprise and Education Help (2024)
Top Articles
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 5834

Rating: 4.6 / 5 (56 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.