Hello,
I am seeking some guidance as to how/where Netskope certificate files are imported onto MacOS. We have had numerous issues with Deloitte practitioners (mainly developers and individuals running code/CLI) where the Netskope cert prevents the application from running due to residing atop the cert chain, and therefore is not trusted by the application service. We have copies of the cert files (ca.deloitte.eu.goskope.com and caadmin.netskope.com) and have set the cert to Always Trust in Keychain; however, SSL errors are still being returned by the system. An example is below, using the brightcove.com service:
2022-09-27 09:10:16.604476-0600 USGA Dev[2698:26211] Task <BB14C893-A867-4C5C-977F-8624C991653B>.<1> finished with error [-1200] Error Domain=NSURLErrorDomain Code=-1200 "An SSL error has occurred and a secure connection to the server cannot be made." UserInfo={NSLocalizedRecoverySuggestion=Would you like to connect to the server anyway?, _kCFStreamErrorDomainKey=3, NSErrorPeerCertificateChainKey=(
"<cert(0x7fde7b11ba00) s: *.brightcove.com i: ca.deloitte.eu.goskope.com>",
"<cert(0x7fde7b069000) s: ca.deloitte.eu.goskope.com i: caadmin.netskope.com>",
"<cert(0x7fde7b069800) s: caadmin.netskope.com i: caadmin.netskope.com>"
I'm looking for any information as to how the above can be resolved without inputting an SSL bypass, as it is clearly related to untrusted agent certificates.
Regards,
Marc-Anthony